Security Software Engineer, IAM

Remote $208k–$312k middle 1 month ago full-time quality 8.5/10

Role in brief

Vercel is seeking a Security Software Engineer to define and implement their Identity and Access Management (IAM) strategy for both corporate and production systems. This role involves migrating IAM configurations to Terraform, enforcing least-privilege access, and automating workflows. Candidates with extensive experience in Okta, Terraform, and cloud IAM in fast-moving environments should apply.

OktaTerraformAWSGCPMDMMAM

About the role

This role focuses on owning the full Identity and Access Management (IAM) strategy for Vercel, covering both internal corporate systems and external production environments. The work involves defining the roadmap, setting standards, and architecting solutions to ensure secure access. A key responsibility will be migrating existing Okta configurations to Terraform, promoting an infrastructure-as-code approach, and educating engineering teams on its use. This position is central to enhancing Vercel's internal systems to meet the same high standards offered to customers.

The Security Software Engineer will design and implement strict least-privilege access controls across various platforms, including cloud services, SaaS applications, and production infrastructure. This involves close collaboration with platform and engineering teams to integrate IAM best practices early in the development cycle. Additionally, the role includes building and managing Mobile Device Management (MDM) and Mobile Application Management (MAM) tools to secure access from endpoints and mobile devices throughout the organization.

Success in this position means driving significant automation in provisioning, deprovisioning, and access review processes, streamlining operations and improving security posture. The individual will serve as the primary subject matter expert for IAM, providing guidance and support to Security, IT, and Engineering teams. This requires a strong ability to align diverse teams and operate independently to make critical decisions within a dynamic work environment.

The base salary for this role in San Francisco, CA ranges from $208,000 to $312,000, with actual compensation adjusted based on skills, experience, location, and potentially including equity and bonus programs.

Skills that matter here

  • Okta: This role requires deep expertise in Okta, including single sign-on, multi-factor authentication, lifecycle management, and API-driven automation for identity solutions.
  • Terraform: Proficiency in Terraform is essential for migrating Okta configurations and managing IAM infrastructure as code.
  • AWS: Experience with AWS IAM is necessary for managing service accounts, roles, and workload identity federation within cloud environments.
  • GCP: Experience with GCP IAM is necessary for managing service accounts, roles, and workload identity federation within cloud environments.
  • MDM: This role involves building and managing MDM solutions to secure endpoint and mobile device access across the organization.
  • MAM: This role involves building and managing MAM solutions to secure endpoint and mobile device access across the organization.

Who this role suits

  • Someone with over 7 years of experience in identity, access management, or platform security engineering.
  • An individual who is comfortable operating with autonomy and making decisions in a fast-paced setting.
  • A strong collaborator capable of aligning various teams, including Engineering, IT, Compliance, and Security.
  • A professional committed to managing infrastructure as code and driving its adoption among engineering teams.

From the employer

What You Will Do:

  • Own the full IAM strategy for both corporate and production environments - defining the roadmap, standards, and architecture end to end.
  • Migrate Okta and all related IAM configuration to Terraform, driving infrastructure-as-code adoption and leveling up engineering teams in its use.
  • Lead Vercel-on-Vercel and Vercel infrastructure cleanup initiatives, ensuring our internal systems reflect the same standards we sell to customers.
  • Design and enforce least-privilege access controls across cloud, SaaS, and production infrastructure.
  • Partner with platform and engineering teams to embed IAM best practices early in the design process.
  • Build and manage MDM/MAM tooling to secure endpoint and mobile device access across the organization.
  • Drive automation across provisioning, deprovisioning, and access review workflows.
  • Serve as the IAM subject matter expert across Security, IT, and Engineering.

About You:

  • 7+ years of experience in identity, access management, or platform security engineering.
  • Deep expertise with Okta - including SSO, MFA, lifecycle management, and API-driven automation.
  • Proficient in Terraform and committed to managing IAM infrastructure as code.
  • Experience designing IAM strategy at scale - across both corporate (IT/SaaS) and production (cloud infrastructure) environments.
  • Hands-on experience with AWS or GCP IAM - service accounts, roles, workload identity federation.
  • Background in MDM/MAM solutions (Jamf, Intune, or equivalent).
  • Strong collaborator who can drive alignment across Engineering, IT, Compliance, and Security teams.
  • Comfortable operating with autonomy and owning decisions in a fast-moving environment.

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
  • The San Francisco, CA base pay range for this role is $208,000 - $312,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role.

Questions about this role

What is the remote work policy for this role?

This is a fully remote position.

What level of seniority is expected for this role?

This is a middle-seniority position, requiring significant experience in identity, access management, or platform security engineering.

How do I apply for this position?

The job posting does not specify an application process, but it is for Vercel, an agentic infrastructure company.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Vercel.