The role involves architecting enterprise identity and access solutions while enforcing security policies across cloud-native environments. You will lead audit readiness and compliance initiatives while collaborating with engineering teams to embed security controls throughout the development lifecycle.
This is a remote position.
We are seeking a Mid-Senior Infosec / Compliance Specialist to lead and strengthen security, identity, governance, and compliance initiatives across cloud-native and enterprise environments. The role focuses on identity federation, access governance, DevSecOps security controls, cloud security, and audit readiness while ensuring adherence to industry-recognized compliance frameworks and best practices.
The Key Responsibilities are:
Architect enterprise Single Sign-On (SSO) solutions using Keycloak, SAML 2.0, and OpenID Connect (OIDC).
Configure Microsoft Entra ID (Azure AD) and Google Cloud Identity as identity brokers.
Establish centralized Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), and Zero Trust security policies across all platform boundaries.
Manage GitHub Advanced Security (GHAS) initiatives, including enforcement of Dependabot alerts, secret scanning, static code analysis (CodeQL/SAST), and branch protection rules.
Implement portable secrets management and monitor service-to-service security mechanisms such as mutual TLS (mTLS) across Kubernetes cluster boundaries.
Lead audit readiness activities, vulnerability scanning programs, and compliance enforcement initiatives for frameworks such as SOC 2 and ISO 27001.
Collaborate with engineering, platform, and operations teams to ensure security controls are embedded throughout the software development lifecycle.
Support continuous improvement of organizational security posture through governance, risk management, and compliance best practices.
Requirements
Bachelor’s degree in Computer Science, Software Engineering, or a related field.
Minimum 5 years of experience in Information Security, Identity and Access Management (IAM), Compliance, DevSecOps, or a related field.
Deep experience with Keycloak administration, realm configuration, user federation, and Identity Provider (IdP) mapping.
Strong knowledge of Microsoft Entra ID enterprise applications and Google Identity Platform.
Experience enforcing security policies across multi-tenant Kubernetes clusters and cloud boundaries.
Familiarity with GitHub Advanced Security and DevSecOps automated tooling.
Strong understanding of SAML 2.0, OpenID Connect (OIDC), identity federation, and authentication protocols.
Experience implementing RBAC, MFA, Zero Trust architectures, and cloud security best practices.
Knowledge of vulnerability management, audit readiness processes, and compliance frameworks such as SOC 2 and ISO 27001.
Excellent analytical, problem-solving, and risk assessment skills.
Excellent English communication skills.
Ability to work effectively with cross-functional and globally distributed teams.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”