
IT Engineer
The role in a nutshell:
At Chainguard, identity is everything, and as our IT Engineer (Identity/IAM), you’ll be the gatekeeper of how Chainguardians log in, get to work, and keep things secure. You’ll be the engineer behind the curtain making sure access feels effortless for our team while staying airtight against threats. From automating how new teammates get the right access on day one, to building the guardrails that keep our systems compliant and safe, this role is at the center of how we work every day. If you love solving puzzles, making security seamless, and keeping doors locked for the bad guys (and wide open for the good ones), you’ll fit right in.
What you’ll do:
Identity & Access Management (IAM):
- Design, implement, and manage enterprise IAM solutions, including SSO, MFA, and directory services to deliver amazing identity UX and outstanding security to a rapidly growing company.
- Drive adoption of Zero Trust and modern cloud IAM architectures across Okta as well as AWS, GCP, Azure, and SaaS ecosystems.
Lifecycle Automation:
- Build and maintain joiner/mover/leaver workflows using Okta Identity Lifecycle Management, Okta Workflows, and HRIS integrations to meet regulatory requirements and business objectives.
Governance & Trust:
- Lead quarterly access reviews, segregation-of-duties assessments, and role-attestation processes using automation to cut down on repetitive manual work.
- Assist the Governance and Trust team in preparing evidence for SOC 2, ISO27001, and other regulatory audits.
- Define and enforce IAM governance, RBAC, and policy frameworks.
Systems & Support:
- Oversee IAM platform operations and system administration to ensure high availability, reliability, and performance.
- Provide escalation support for complex IT issues and document processes to strengthen IT operations.
Collaboration & Leadership:
- Lead IAM-related projects end to end, from planning to execution.
- Mentor junior IT staff fostering a culture of security and operational excellence.
- Partner with IT, HR, compliance, and business stakeholders to balance security and user experience.
Monitoring & Reporting:
- Conduct IAM risk assessments, audits, and incident response activities.
- Deliver reporting on IAM performance, maturity, and risk posture through KPIs, dashboards, and regular updates.
What we're looking for:
- 8+ years of experience in the Identity and Access Management field
- Proven experience in managing complex IAM deployments, including design, development, testing, deployment, and maintenance
- Hands-on experience designing, deploying, and managing enterprise Okta platforms.
- Strong background with identity lifecycle automation (joiner/mover/leaver) using tools such as Okta Workflows and HRIS integrations.
- Familiarity with IAM governance, RBAC, and regulatory frameworks (SOC 2, ISO,NIST, GDPR, etc.), with experience preparing audit evidence.
- Proven track record of effective communication and collaboration, with the ability to build relationships and work seamlessly with cross-functional teams
- Ability to balance day-to-day execution with long-term strategy, delivering executive-level reporting on IAM maturity and risk posture
- Ability to work effectively in a fast-paced environment with multiple priorities and deadlines.
- Proactive in streamlining workflows, improving user experience, and evolving IAM practices to align with business and security goals.
Base Salary Range
$128,000 - $150,000 USD
About Us
Chainguard is the secure foundation for software development and deployment. By providing guarded open source software, built from source and updated continuously, Chainguard helps organizations eliminate threats in their software supply chains.
Founded by the industry's leading experts on open source software, security and cloud native development, Chainguard has built the largest library of open source software that is secure by default.
Chainguard’s mission is to be the safe source for open source.
We live and breathe our company values:
We are customer obsessed - We focus on delivering solutions to our customers that create value and make their lives better.
We have a bias for intentional action - We prioritize, plan, try things, and fail fast.
We don’t take ourselves too seriously (but we do serious work) - We are solving an important problem which takes focus, but we also like to enjoy the journey.
We trust each other and assume good intentions - We’re transparent with decisions to empower team members to make well informed decisions.
A few of the benefits we offer:
- Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
- Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
- 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
- ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
- 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.
- For a full list of our benefits and rewards, click here.
If your experience is close but doesn’t fulfill all requirements, please apply. We’re building the best team in technology and are focused on hiring “Chainguardians'' with unique backgrounds, perspectives, and experiences.
Chainguard is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law.
By submitting your application, you acknowledge that Chainguard will process your personal data in accordance with Chainguard’s Privacy Policy.
©2025 Chainguard. All Rights Reserved.
Apply for this job
*
indicates a required field