Technical Lead, Identity & Access Management
$60k - $300k • Sunnyvale • FullTime
Posted 5mo ago
About the job
Applied Intuition is seeking a hands-on Technical Lead to take ownership of identity and access management (IAM) across the organization. This senior individual contributor role involves defining the long-term IAM strategy, assessing and maturing the Identity Provider (IDP) architecture, and driving all identity systems towards Zero Trust principles. You will be responsible for automating identity lifecycle processes, implementing Role-Based Access Control (RBAC), defining least-privilege policies, centralizing secrets management, and designing Privileged Access Management (PAM) solutions. The role also includes implementing scalable access management for AI agents and bots, enforcing Single Sign-On (SSO), and owning the implementation and governance of authentication protocols and modern identity standards. You will collaborate with various teams to deliver access management capabilities that support business needs and satisfy audit requirements, translating complex identity requirements into actionable technical plans.
Responsibilities
- Define the long-term IAM strategy, roadmap, and operating model.
- Assess and mature the current-state Identity Provider (IDP) architecture.
- Drive identity systems toward Zero Trust principles.
- Automate the full identity lifecycle beyond traditional IGA joiner-mover-leaver (JML) processes.
- Implement and enforce RBAC for human and non-human identities at scale.
- Define and operationalize least-privilege policies.
- Centralize secrets management across cloud and enterprise environments.
- Design and deliver Privileged Access Management (PAM) for admin accounts.
- Implement a scalable access management model for AI agents and bots.
- Collaborate with IT Apps and infrastructure teams to enforce and enable SSO.
- Own the implementation and governance of authentication protocols (SAML, OIDC, OAuth 2.0) and modern identity standards.
- Partner with engineering, security, IT, compliance, and product teams to deliver access management capabilities.
- Translate complex identity requirements into clear, executable technical plans.
Requirements
- 8 - 12+ years in identity engineering, security engineering, or a closely related discipline.
- Hands-on architecture or engineering experience in cloud environments (AWS, GCP, or Azure).
- Demonstrated track record of leading complex, cross-functional IAM programs.
- Deep expertise in modern IAM technologies: directories (LDAP/AD), IDPs, federation, and authentication protocols (SAML, OIDC, OAuth 2.0).
- Practical experience implementing Zero Trust identity models and PAM frameworks.
- Strong understanding of identity governance, IGA tooling, and role lifecycle management.
- Hands-on experience with secrets management platforms (e.g., HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager).
- Experience with non-human identity and machine identity management in large-scale environments.
- Experience building access controls for AI workloads, agents, or service accounts at scale.
- Familiarity with SCIM provisioning and automated IGA workflows.
- Excellent communication and influencing skills.
Benefits
- Base salary
- Equity in the form of options and/or restricted stock units
- Comprehensive health, dental, vision, life and disability insurance coverage
- 401k retirement benefits with employer match
- Learning and wellness stipends
- Paid time off