Staff Security Engineer IAM
Austin, TX - USA
Job Summary
Lead the development implementation and ongoing maintenance of comprehensive security strategies and solutions.
Design and deploy advanced identity security controls to safeguards networks systems and applications.
Work across disciplines to shape our security services strategy and execution
Set and uphold the standard for security processes to support high-quality engineering
Mentor and galvanize new engineers to do their best work
BS/BTech (or higher) in Computer Science Information Technology Cybersecurity or a related field
8 years of experience in software or security engineering within Cloud Native environments
Domain Specific Minimum Requirements
Cloud IAM Architecture: Deep knowledge of cloud security architectures (AWS IAM Azure Entra ID or GCP IAM) including designing/enforcing least-privilege roles RBAC/ABAC and permission policies.
Identity Protocols & Governance: Proficiency in identity standards and federation protocols (SAML OIDC OAuth LDAP/Directory Services) user lifecycle automation SSO MFA and Just-In-Time (JIT) access.
Automation & IaC: Strong hands-on proficiency with Infrastructure as Code (Terraform or CloudFormation) and scripting (Python or PowerShell) to automate identity provisioning drift detection and access workflows.
Non-Human Identity (NHI) Fundamentals: Practical experience managing service accounts API keys bots and automated workload identities across cloud infrastructure.
Experience architecting developing and deploying large-scale distributed systems at scale
Experience with cloud technologies e.g. AWS Azure GCP
Experience building continuous integration and continuous development (CI/CD) pipelines
Familiarity with server-side web technologies (eg: Java Python Scala C# C Go)
4 years of experience acting as a trusted technical decision-maker in a team setting solving for short-term and long-term business value
Experience with health-tech systems like Electronic Health Records Clinical data etc.
Domain Specific Experience
AI Identity & Access Management
NHI Architecture: Design secure scalable and automated solutions for managing service accounts machine identities secrets certificates APIs and cloud-native workloads.
AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g. Gemini Claude AWS Bedrock) conducting threat modeling for AI systems or managing automated permission guardrails for AI agents.
AI/ML Security & Threat Modeling: Hands-on experience with AI/ML tools (e.g. Gemini Claude AWS Bedrock) conducting threat modeling for AI systems or managing automated permission guardrails for AI agents.
Advanced Protocols & Microservice Security: Familiarity with SPIFFE/SPIRE zero-trust network architectures or complex containerized identity frameworks.
SIEM & Security Observability Tools: Experience orchestrating VPC flow logs and audit feeds into security analytics tools (e.g. Crowdstrike Sumo Logic Wiz Zscaler).
Industry & Regulatory Context: Experience with health-tech systems clinical data environments (EHRs) and regulatory standards (HIPAA SOC 2 ISO 27001).
Certifications: CISSP OSCP CEH Certified AI Security Specialist (CAISS) or GIAC Machine Learning Security Engineer (GMSE).
Required Experience:
Staff IC
About Company
#LI-KC1 Who We Are: Aledade PBC, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country ... View more