Senior Security Engineer I, IAM
Oscar Health · New York, NY · 1 wk ago
Information Technology$164k/yrFull-time
About the role
The Senior Identity and Access Manager will build Oscar's identity and access management disciplines across various systems, including internally built applications, cloud environments, and data platforms.
Responsibilities
- Design and implement least privilege access models and enterprise identity architectures.
- Create and maintain identity threat detection and response capabilities.
- Partner with software engineering teams to review and improve access controls in custom applications.
- Reason about identity telemetry, detection logic, and incident response workflows.
- Communicate identity risk and architecture tradeoffs effectively to technical and non-technical audiences.
Requirements
- 4+ years of relevant experience in Identity engineering.
- Experience designing or implementing identity and access management controls for enterprise systems, cloud environments, SaaS platforms, or internally built applications.
- Strong understanding of least privilege, role-based, and attribute-based access control, privileged access patterns, identity lifecycle management, and access review processes.
- Hands-on experience with identity platforms such as Okta, Google Workspace Identity, and Google Cloud permission models.
- Working knowledge of authentication and authorization protocols such as SAML, OAuth, OIDC, SCIM, LDAP, and related session, token, and federation patterns.
- Experience partnering with software engineering teams to review permission models, design secure authorization patterns, and improve access controls in custom applications.
- Ability to reason about identity telemetry, detection logic, high-risk configuration states, and incident response workflows.
- Strong written and verbal communication skills, including the ability to explain identity risk and architecture tradeoffs to technical and non-technical audiences.
Qualifications
- Bachelor's degree in Computer Science, Information Systems, or a related field.
- CISSP, CISM, or GIAC certifications preferred.
Skills
- Experience building identity controls in AWS environments and data platforms such as BigQuery.
- Experience building or operating ITDR, UEBA, SIEM, SOAR, or other security detection and response capabilities.
- Experience in healthcare, insurance, fintech, or another regulated technology environment.
- Experience writing automation, queries, or production-quality code to support identity workflows, detections, or platform integrations.
Benefits
- Medical, dental, and vision benefits.
- 11 paid holidays.
- Paid sick time.
- Paid parental leave.
- 401(k) plan participation.
- Life and disability insurance.
- Paid wellness time and reimbursements.
Pay
$163,944 per year - $215,176 per year.
Schedule
This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule.