Quick Summary
MFA, phishing-resistant methods, passwordless rollout, and legacy auth retirement. Partner with our Endpoint Engineer so access policy and device posture stay in sync.
scripting or API work against identity and SaaS platforms rather than console-only administration. Ability to write clear documentation and turn written policy into enforceable technical controls.
We are a renewable energy and ocean technology company committed to rapidly developing and deploying technologies that will ensure a sustainable future for Earth by unlocking the vast energy potential of its oceans. Our focus is on capturing civilizational levels of ultra-low-cost renewable energy for applications including computing and affordable renewable fuels delivered to shore.
The company is a public benefit corporation headquartered in Portland, Oregon, and backed by leading venture capitalists, philanthropic investors, university endowments, and private investment offices. We operate as an idea meritocracy in which the best ideas change the company’s direction on a regular basis.
Our staff have worked at organizations such as SpaceX, Blue Origin, Boeing, Tesla, Apple, Virgin Orbit, Astra, Google, Amazon, Microsoft, New Relic, Bridgewater, Raytheon, Disney Imagineering, and the US Army and Air Force, as well as research universities, startups, and small companies across a range of industries.
About the Role
~1 min readOur core technology is the node, a device that produces energy in the ocean’s harshest conditions for years at a time without human maintenance or intervention.
We're looking for an IAM Engineer to own the identity plane at Panthalassa. Identity is the control point for everything we do: who gets access to what, on which device, from where, and for how long. You'll build that system and the automation behind it.
This is a high-ownership individual contributor role. You'll administer Microsoft Entra ID and Google Workspace identity, design Conditional Access and context-aware policy, automate joiner/mover/leaver, and bring every SaaS application in our stack under SSO and automated provisioning. You'll also help govern the identities that aren't people: service accounts, OAuth grants, and workload credentials. We have an established zero trust roadmap and a security framework to comply with, and your job is to turn both into enforceable technical controls and explain the reasoning well enough that the rest of the company comes along with you.
Candidates should have strong interpersonal skills and be able to thrive in a creative, scrappy, and collaborative environment in which the best ideas change the company’s direction on a regular basis.
Responsibilities
~1 min read- Administer Microsoft Entra ID, including user lifecycle, group management, dynamic membership rules, and role assignment.
- Design and maintain Conditional Access policy, tying device compliance posture, identity signals, risk, and location to resource access.
- Own authentication standards: MFA, phishing-resistant methods, passwordless rollout, and legacy auth retirement.
- Partner with our Endpoint Engineer so access policy and device posture stay in sync.
- Automate joiner, mover, and leaver so access is granted and revoked from a source of truth rather than a ticket.
- Manage SSO integrations and application provisioning via SAML and SCIM across our SaaS stack.
- Build and run access review and recertification cycles that produce evidence auditors accept.
- Implement least privilege for privileged roles, including just-in-time elevation and break-glass procedures.
- Govern service accounts, OAuth grants, and API credentials: naming conventions, ownership, scope review, and rotation.
- Establish where secrets live and how they are issued, stored, and retired.
- Maintain a defensible inventory of who and what can reach our systems.
- Advance our zero trust roadmap and translate policy into enforceable technical controls.
- Own the access control domain of our compliance framework (NIST or equivalent), including documentation and evidence.
- Partner with information security leadership on access control policy, identity threat detection, and incident response involving compromised accounts.
Requirements
~2 min read- Experience administering identity and access in a modern IdP, including user lifecycle, groups, and conditional or context-aware access.
- Experience implementing SSO and provisioning integrations (SAML, SCIM) across a SaaS stack.
- Automation experience: scripting or API work against identity and SaaS platforms rather than console-only administration.
- Ability to write clear documentation and turn written policy into enforceable technical controls.
- Ability to explain the reasoning behind an access decision to a non-technical audience and get buy-in.
- Experience owning an IdP at a growing technology company.
- Familiarity with zero trust architecture and how it translates into identity controls.
- Experience with identity governance and administration: access reviews, entitlement management, and privileged access.
- Experience governing non-human identities, service accounts, and OAuth scopes.
- Experience supporting or implementing a security or compliance framework (NIST, ISO 27001, SOC 2, or equivalent).
- Experience with identity threat detection and response, or investigating account compromise.
The above qualifications are desired, not required. We encourage you to apply if you are a strong candidate with only some of the desired skills and experience listed.
- Available for occasional off-hours work to support identity migrations, tenant changes, and access cutovers that have to land outside business hours.
- Participate in incident response when accounts or credentials are involved, including outside business hours.
- Travel to the Portland office quarterly if working remotely.
- Intermittently able to work longer hours to support critical needs. While we expect a lot of each other, we also offer a high degree of autonomy and work-life balance, including flexible PTO and flexible working hours.
What We Offer
~1 min readIf hired for this full-time role, you will receive:
This is an on-site position. Our offices, lab, and shop are located in Portland, Oregon.
Location & Eligibility
Listing Details
- Posted
- October 6, 2026
- First seen
- October 6, 2026
- Last seen
- October 6, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 67%
- Scored at
- October 6, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.