Advanced Security Engineer (IAM)
Quick Summary
Posting Type Remote Job OverviewThe Advanced IAM Engineer is a technically deep, hands-on practitioner who forms the operational backbone of the enterprise IAM function.
Posting Type
Remote
Job Overview
The Advanced IAM Engineer is a technically deep, hands-on practitioner who forms the operational backbone of the enterprise IAM function. Treating identity as the primary control plane in a defense-in-depth program, this engineer designs, deploys, and optimizes AI-enabled identity technologies across the workforce, customer, and non-human (machine and agent) identity domains. Partnering with the Manager of Enterprise Security and cross-functional teams, the role reduces Relativity's identity attack surface and improves detection and response times for identity-based threats.Job Description and Requirements
Responsibilities
~1 min read- →
Implement and operate identity controls spanning workforce, machine, and workload identity as part of a layered defense-in-depth model.
- →
Operate continuous adaptive trust mechanisms, including continuous access evaluation (CAE), risk-based step-up authentication, and session revocation, that re-verify identity against real-time posture and behavioral signals rather than at the access gate alone.
- →
Configure ZTNA, least-privilege access, phishing-resistant MFA/FIDO2, and JIT access across access paths.
- →
Implement SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environments.
- →
Apply hardening standards to identity infrastructure using CIS Benchmarks/DISA STIGs with automated compliance validation.
Build and maintain identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applications.
Operate identity governance and administration (IGA) workflows: access reviews, certification campaigns, and segregation-of-duties checks.
Administer privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoring.
Maintain governance of non-human identities (service accounts, workloads, secrets) using drift detection and policy-as-code.
Feed identity telemetry into the detection stack (SIEM/SOAR, UEBA) to support detection of credential abuse, privilege escalation, and lateral movement.
Execute identity-focused IR playbook steps for account takeover, credential compromise, and session hijacking.
Implement identity checks in CI/CD pipelines (secret scanning, IaC identity analysis), acting on AI-generated fix recommendations in PR workflows.
Track identity hygiene metrics and support audits, certifications, and e-discovery requirements alongside GRC.
Requirements
~1 min readThis position is eligible for total compensation which includes a competitive base salary, an annual performance bonus, and long-term incentives.
The expected salary range for this role is between following values:
$104 000 and $156 000The final offered salary will be based on several factors, including but not limited to the candidate's depth of experience, skill set, qualifications, and internal pay equity. Hiring at the top end of the range would not be typical, to allow for future meaningful salary growth in this position.
Location & Eligibility
Listing Details
- Posted
- August 31, 2026
- First seen
- September 30, 2026
- Last seen
- September 30, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 11%
- Scored at
- October 1, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.