The Role
Do you care deeply about secure access at scale Making sure the right people have the right access exactly when they need it without slowing teams down Join Moveworks and help shape the future of our identity and access strategy.
At Moveworks we believe great security is an enabler not a blocker. As a Senior Identity & Access Management Engineer youll be a hands-on technical developer coding designing building and scaling IAM solutions across cloud infrastructure SaaS applications and internal systems. Youll own the development of IAM initiatives end-to-end from untangling ambiguous access challenges to architecting secure automated solutions and driving them into production.
In this role youll develop robust access models across AWS Azure Kubernetes and beyond; reduce privilege sprawl through thoughtful role design; and build strong observability through logging metrics and reporting in our SIEM. Youll modernize access reviews to deliver real security impact with minimal friction continuously de-risk IAM threats and partner closely with teams to drive adoption of secure-by-default patterns.
Your work will directly protect Moveworks most critical systems while enabling our engineers to move fast safely and confidently.
What you get to do in this role:
Be the technical developer to drive IAM application development: Code design and implement solutions with extensive knowledge in AWS Azure Teleport and Terraform. Enabling robust and reliable solutions to keep our engineering teams active.
Drive IAM projects end-to-end: Take ambiguous access problems understand and have the ability to define requirements architect solutions and own the rollout/operationalization (not just the design).
Develop with secure access models in mind: Continuously develop role design improvements and access assignment patterns across AWS Kubernetes SaaS apps and internal systems to reduce unnecessary privileges minimize manual grants and create scalable safe baseline access that covers routine work without daily elevation.
Develop on operationalizing logging and metrics: Ensure access changes are observable in our Security Information and Event Management (SIEM) tool; build repeatable reporting that surfaces risky access and drift.
Run and improve user access reviews (UAR): Develop execute and design a UAR process & solution that meets compliance requirements while improving real security signalminimizing approver burden through scoping automation and clear decision support.
Develop technology to continuously de-risk: Identify high-risk permissions and misuse paths propose appropriate controls and mitigations drive adoption with partner teams and develop solutions to continuously de-risk.
Operate with strong security judgment and high signal: Reliably distinguish meaningful IAM risk from noise gather context efficiently and escalate with crisp rationale and actionable mitigations.
Qualifications :
To be successful in this role you have:
US Citizenship preferred
Willingness to work onsite at our Mountain View or New York offices
Experience: 5 years of experience working in IAM security engineering or platform engineering with substantial IAM responsibilities in production environments.
IAM Expertise: Strong grasp of IAM best practices and common failure modes (e.g. least privilege privilege escalation paths separation of duties breakglass auditability).
Cloud Infrastructure IAM: Practical experience implementing and designing access control in AWS Azure GCP environments and partnering with teams who manage infrastructure at scale. Experience configuring IAM in Teleport Terraform and Kubernetes environments is a plus.
SSO Experience: Experience with Okta administration and patterns (e.g. groups app assignments lifecycle/provisioning) or equivalent experience with a similar SSO product.
Threat-aware thinking: Ability to spot dangerous permissions and misuse paths (including insider-threat scenarios) assess risk and identify suitable mitigations and controls.
Automation-first mindset: Comfortable using scripting languages and AI coding tools to build reliable automation and able to read/validate what the code is doing.
Protocol fluency: Working understanding of OAuth OIDC SAML and SCIM including when to use which failure modes and common pitfalls.
Collaboration: Proven ability to build long-lasting relationships with various technical teams such as Engineering Information Technology Infrastructure and DevOps teams.
Educational Background: BS in computer science or a related field or equivalent relevant experience.
Additional Information :
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible remote or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color creed religion sex sexual orientation national origin or nationality ancestry age disability gender identity or expression marital status veteran status or any other category protected by addition all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process or are unable to use this online application and need an alternative method to apply please contact for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations including the U.S. Export Administration Regulations (EAR) ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. 2025 Fortune Media IP Limited. All rights reserved. Used under license.
Remote Work :
No
Employment Type :
Full-time
Learn here. Grow here. Make a difference here. At ServiceNow, our cloud?based platform and solutions deliver digital workflows that create great experiences and unlock productivity for employees and enterprises. Were growing fast, innovating even faster, and making an impact on our c ... View more