The RoleAs our Senior Identity Engineer, you will own workforce and workload identity end-to-end - SSO, MFA, the joiner-mover-leaver lifecycle, privileged access, secrets, and service/machine identity - across corporate, cloud, and factory systems that handle export-controlled technical data. You will build an automation-first, least-privilege identity program that shrinks our largest attack surface while keeping engineers fast. This is a hands-on individual-contributor role on a small, high-leverage security team in Los Angeles.
What You'll Do- Design, implement, and operate our IdP stack (e.g., Okta, Entra, Google Workspace, Auth0, or Zitadel) - SSO, SCIM provisioning, and phishing-resistant MFA - and build the systems around it.
- Build identity systems at scale that put OAuth 2.0 / OIDC / SAML and modern authorization models (RBAC and relationship-based access control) to work in production.
- Own cloud identity end-to-end - Azure service principals, AWS IAM, and workload/service identity - and tie those identities cleanly to the underlying infrastructure.
- Work cross-functionally to help other teams meet their identity needs, and automate the access lifecycle (joiner-mover-leaver) and reviews.
- Partner with Detection & Response and Compliance/FSO so identity telemetry is detectable, actionable, and audit-ready.
What We're Looking For- You can build. Strong software engineering fundamentals and a track record of shipping identity systems at scale - not just configuring a vendor tool or leaning on AI-assisted coding.
- Real command of core identity concepts - OAuth 2.0 flows, OIDC, SAML, RBAC, and relationship-based access control (ReBAC) - and the ability to design systems that exploit these protocols well.
- Hands-on depth with one or more IdPs (Okta / Entra / Google Workspace / Auth0 / Zitadel), since day-to-day is implementing, designing, and integrating these platforms.
- Cloud identity depth - Azure service principals, AWS IAM - and a clear grasp of how those identities map to real infrastructure.
- The autonomy and urgency to own the identity domain end-to-end on a small, high-leverage team with minimal direction.
What Will Set You Apart- Fine-grained authorization at scale (ReBAC with OpenFGA / Zanzibar-style systems) built and run in production.
- Identity engineering for OT/manufacturing or other regulated, controlled environments.
- Large-scale passkey/FIDO2 or PAM (CyberArk/Teleport) rollouts, and secrets management with HashiCorp Vault.
- Experience building on a small, high-automation team where output-per-engineer is the measure; detection-engineering and ITAR-aware access design.
Benefits for Full-time Employees- Medical, dental, vision, and life insurance plans for employees
401k - Relocation support may be provided for certain situations, based on business need.
- Flexible vacation policy
- Equity
ITAR RequirementsTo conform to U.S. Government export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen or national, lawful permanent resident, protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.