Haystack
← Back to Jobs
Technology

Senior Security Engineer, Identity and Access Management

NimbusAITech LLCDenver, CO🇺🇸United StatesPosted 4 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

 

Title: Senior Security Engineer, Identity and Access Management 

Location: Denver, CO

 

### Role Overview

We are seeking a senior security engineer to design and build scalable identity, access, and authorization systems that support secure enterprise operations. This role is highly hands-on and requires production-grade engineering, deep IAM expertise, and the ability to translate security architecture into reliable systems.

 

### Key Responsibilities

- Architect and implement identity federation solutions across enterprise identity providers using OIDC, SAML, and standards-based provisioning.

- Design secure authorization flows that map federated identities into downstream systems’ native authorization models.

- Build and maintain OAuth2/OIDC integrations, including scope design, audience restriction, token exchange, and failure-mode mitigation.

- Implement policy-based authorization using an externalized policy engine with RBAC and at least one of ABAC or ReBAC.

- Develop cloud IAM and centralized secrets management solutions, including automated secret rotation.

- Build production-quality security features for containerized and orchestrated environments.

- Deliver least-privilege, just-in-time, and fully auditable access systems.

- Partner with engineering teams to embed secure-by-design patterns into platform and application development.

 

### Required Qualifications

- 8+ years of experience in security engineering.

- 3+ years architecting identity and access management at scale.

- Deep hands-on experience with enterprise identity providers, OIDC, SAML, federation, and provisioning standards.

- Strong understanding of OAuth2/OIDC internals, including scopes, audiences, token exchange, audience restriction, confused-deputy risks, and token passthrough issues.

- Proven experience implementing authorization policy models using an externalized policy engine.

- Strong cloud IAM experience and centralized secrets management expertise, including automated rotation.

- Container orchestration and container security fundamentals.

- Ability to write and ship production-quality code, not just provide advisory support.

- Demonstrated experience delivering least-privilege and auditable access systems.

 

### Preferred Qualifications

- Experience securing AI agents, LLM-based systems, and automated tool-invocation interfaces.

- Familiarity with prompt-injection and tool-boundary threat modeling.

- Experience with workload identity frameworks and machine-to-machine credentialing.

- Experience building security telemetry pipelines and integrating with SIEM platforms at scale.

- Experience delivering vulnerability-management programs, including continuous scanning, SBOM tooling, CVE correlation, and risk-based prioritization.

- Experience securing edge, IoT, or intermittently connected devices.

- Experience with zero-trust infrastructure access, PKI, certificate lifecycle management, mutual TLS, and device attestation.

- Experience securing event-driven platforms and CI/CD pipelines, including artifact signing, IaC scanning, and automated security gates.

- Relevant security architecture certifications are a plus.

 

### Why This Role

This is a builder role for a security engineer who wants to design and ship identity and access systems that are both scalable and auditable. You will work on high-impact security infrastructure that helps protect users, services, and production environments.

 

 

Skills

SAML
IoT
LLM
PKI

Similar jobs