MTS Lead Identity and Access Management
Summary
Reflection is hiring a lead identity and access management engineer to architect, build, and operate cloud-native IAM: phishing-resistant authentication, just-in-time credentials for GPU clusters, workload identity, and authorization-as-code across AWS, GCP, and Kubernetes. Requires 15+ years in identity/security or infrastructure engineering and coding in Go, Python, or Rust.
You will architect, build, and operate cloud-native identity infrastructure. You will enforce phishing-resistant authentication, develop just-in-time access systems, secure workload identities, automate identity lifecycles, and integrate authorization policies into developer and infrastructure workflows.
Responsibilities
- Design and implement cloud-native identity architecture using modern identity providers, federations, and zero-trust access networks
- Own identity lifecycle architecture across corporate, production, and research environments
- Enforce hardware-backed phishing-resistant authentication across corporate, production, and research endpoints
- Design dynamic least-privilege zero-trust access controls
- Build short-lived just-in-time credentialing for GPU cluster access across cloud environments
- Replace long-lived credentials with ephemeral certificate-based access
- Architect workload identity frameworks for service-to-service communication
- Ensure machine accounts, training jobs, and CI/CD pipelines use dynamic short-lived tokens
- Manage authorization policies as code with version control, testing, and deployment pipelines
- Integrate authorization into developer workflows and infrastructure deployment pipelines
- Automate provisioning and deprovisioning through SCIM and API-first tooling
- Instrument identity telemetry and build detection logic for identity-layer attacks
Requirements
- 15+ years of experience in identity security, security architecture, or infrastructure engineering
- Experience architecting and operating modern zero-trust identity infrastructure at scale
- Experience securing IAM boundaries across AWS, GCP, Kubernetes, and containerized environments
- Experience building privileged access management systems for large-scale compute environments
- Understanding of OAuth 2.0, OIDC, SAML, WebAuthn, FIDO2, and PKI
- Software engineering capability with Go, Python, or Rust
- Infrastructure as Code experience with Terraform or Pulumi
- Knowledge of identity-focused adversary techniques
Benefits
- Stock options
- Comprehensive medical, dental, vision, and life insurance
- Annual wellness allowance
- Daily office lunch and dinner
- 22 weeks of paid parental leave
- Unlimited paid time off in the U.S.
- 30 days of paid time off in the U.K.
- Visa sponsorship support
- Regular off-sites, happy hours, and team celebrations