Infosec / Compliance Specialist
Summary
Remote mid-senior Infosec/Compliance Specialist leading identity federation and SSO (Keycloak, SAML 2.0, OIDC, Entra ID, Google Cloud Identity), access governance (RBAC, MFA, Zero Trust), and DevSecOps controls like GHAS and secrets management across Kubernetes and cloud, plus audit readiness for SOC 2 and ISO 27001.
This is a remote position.
- Architect enterprise Single Sign-On (SSO) solutions using Keycloak, SAML 2.0, and OpenID Connect (OIDC).
- Configure Microsoft Entra ID (Azure AD) and Google Cloud Identity as identity brokers.
- Establish centralized Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), and Zero Trust security policies across all platform boundaries.
- Manage GitHub Advanced Security (GHAS) initiatives, including enforcement of Dependabot alerts, secret scanning, static code analysis (CodeQL/SAST), and branch protection rules.
- Implement portable secrets management and monitor service-to-service security mechanisms such as mutual TLS (mTLS) across Kubernetes cluster boundaries.
- Lead audit readiness activities, vulnerability scanning programs, and compliance enforcement initiatives for frameworks such as SOC 2 and ISO 27001.
- Collaborate with engineering, platform, and operations teams to ensure security controls are embedded throughout the software development lifecycle.
- Support continuous improvement of organizational security posture through governance, risk management, and compliance best practices.
Requirements
- Bachelor’s degree in Computer Science, Software Engineering, or a related field.
- Minimum 5 years of experience in Information Security, Identity and Access Management (IAM), Compliance, DevSecOps, or a related field.
- Deep experience with Keycloak administration, realm configuration, user federation, and Identity Provider (IdP) mapping.
- Strong knowledge of Microsoft Entra ID enterprise applications and Google Identity Platform.
- Experience enforcing security policies across multi-tenant Kubernetes clusters and cloud boundaries.
- Familiarity with GitHub Advanced Security and DevSecOps automated tooling.
- Strong understanding of SAML 2.0, OpenID Connect (OIDC), identity federation, and authentication protocols.
- Experience implementing RBAC, MFA, Zero Trust architectures, and cloud security best practices.
- Knowledge of vulnerability management, audit readiness processes, and compliance frameworks such as SOC 2 and ISO 27001.
- Excellent analytical, problem-solving, and risk assessment skills.
- Excellent English communication skills.
- Ability to work effectively with cross-functional and globally distributed teams.
- Availability to work from 11:00 AM to 8:00 PM.
