Jobs · Engineering · California

Senior Identity & Auth Engineer

Cubit Capital · Laguna Beach, CA · 5 days ago
On-siteEngineering$150k–$225k/yrFull-time

Responsibilities

  • Architect and deploy Kubernetes-native identity and authorization infrastructure for IL6 (SECRET) multi-tenant environments
  • Serve as a technical authority for identity/auth controls during ATO processes, documenting and evidencing compliance for IdP components
  • Design and implement multi-tenant isolation strategies ensuring zero lateral movement between customer/program boundaries
  • Evaluate, deploy, and harden self-hosted IdPs (Keycloak, Dex, Authentik, etc.) for classified Kubernetes clusters
  • Implement workload identity frameworks (SPIFFE/SPIRE, K8s projected tokens) and service mesh authentication (Istio, Linkerd, Cilium)
  • Build policy-as-code systems (OPA/Gatekeeper, Kyverno, Cedar) for automated compliance enforcement at runtime
  • Integrate with government identity systems (CAC/PIV, LDAP, Active Directory) and legacy SAML 2.0 applications
  • Collaborate with security team on secret management strategy (HashiCorp Vault, Azure Key Vault) with encryption key lifecycle for IL6 environments
  • Work with application teams to define authentication/authorization contracts for microservices
  • Partner with customers and government auditors during ATO processes to demonstrate compliance and address findings
  • Stay current on emerging identity/auth technologies and evaluate applicability to classified environments

Qualifications

  • Clearance: Eligible for TS/SCI clearance (U.S. citizen or lawful permanent resident), active clearance strongly preferred
  • Experience: 10+ years in platform/security engineering with 5+ years focused on identity, authentication, or authorization systems
  • Multi-Tenant Architecture: Designed and implemented proper tenant isolation (zero lateral movement, strong security boundaries) for SaaS, defense, or high-assurance systems
  • Kubernetes Production Experience: Deployed and operated production Kubernetes clusters with 3+ years experience
  • Identity Infrastructure: Production experience deploying/operating at least one K8s-native IdP (Keycloak, Dex, etc.) or enterprise IAM system
  • Authorization Design: Implemented RBAC, ABAC, or ReBAC authorization models in production systems
  • Zero Trust Principles: Deep understanding of NIST SP 800-207 and practical zero trust architecture patterns
  • Compliance Frameworks: Working knowledge of NIST 800-53, CMMC Level 3+, or FedRAMP High requirements
  • Scripting/Automation: Proficiency in Python, Go, or Bash for automation and tooling
  • Preferred Skills And Experience: Active TS/SCI clearance (or ability to start immediately upon clearance grant), IL4/IL5 deployment and operations experience (IL6 is nice-to-have but not required), ATO Experience, Participation in at least one ATO process for NIST 800-53, CMMC, FedRAMP, or IL4/IL5 systems, Experience with modern authorization frameworks (SpiceDB, Authzed, OpenFGA, Ory Keto), SPIFFE/SPIRE workload identity implementation experience, Service mesh authentication (Istio, Linkerd, Cilium) in production, HashiCorp Vault or enterprise secret management in classified or high-assurance environments, CAC/PIV card integration and PKI certificate management, Policy-as-code (OPA/Rego, Kyverno, Cedar) for runtime enforcement, Experience in aerospace, defense, intelligence community, or national security space, Startup or fast-paced environment experience (balance velocity with compliance rigor), Active TS/SCI clearance (or ability to start immediately upon clearance grant), IL4/IL5 deployment and operations experience (IL6 is nice-to-have but not required), ATO Experience, Participation in at least one ATO process for NIST 800-53, CMMC, FedRAMP, or IL4/IL5 systems, Experience with modern authorization frameworks (SpiceDB, Authzed, OpenFGA, Ory Keto), SPIFFE/SPIRE workload identity implementation experience, Service mesh authentication (Istio, Linkerd, Cilium) in production, HashiCorp Vault or enterprise secret management in classified or high-assurance environments, CAC/PIV card integration and PKI certificate management, Policy-as-code (OPA/Rego, Kyverno, Cedar) for runtime enforcement, Experience in aerospace, defense, intelligence community, or national security space, Startup or fast-paced environment experience (balance velocity with compliance rigor)

Similar jobs