← Voltar aos resultados[Remote] Advanced Security Engineer (IAM)
Relativity
- Localização
- Anywhere
- Publicado
- 8 de out. de 2026
Antes de se candidatar, confirme no site da empresa se a vaga continua aberta e confira as condições completas.
Descrição da vaga
A interface está em português. Os títulos e as descrições publicados pelas empresas permanecem no idioma original, que pode ser inglês.
Note: The job is a remote job and is open to candidates in USA. Relativity is seeking an Advanced IAM Engineer to serve as a hands-on operational backbone for its enterprise identity and access management function. The role designs, deploys, and optimizes identity technologies across workforce, customer, machine, and AI-agent domains while improving identity threat detection and response.
Responsibilities
Implement and operate identity controls spanning workforce, machine, and workload identity as part of a layered defense-in-depth modelOperate continuous adaptive trust mechanisms, including continuous access evaluation (CAE), risk-based step-up authentication, and session revocation, that re-verify identity against real-time posture and behavioral signals rather than at the access gate aloneConfigure ZTNA, least-privilege access, phishing-resistant MFA/FIDO2, and JIT access across access pathsImplement SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environmentsApply hardening standards to identity infrastructure using CIS Benchmarks/DISA STIGs with automated compliance validationBuild and maintain identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applicationsOperate identity governance and administration (IGA) workflows: access reviews, certification campaigns, and segregation-of-duties checksAdminister privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoringMaintain governance of non-human identities (service accounts, workloads, secrets) using drift detection and policy-as-codeFeed identity telemetry into the detection stack (SIEM/SOAR, UEBA) to support detection of credential abuse, privilege escalation, and lateral movementExecute identity-focused IR playbook steps for account takeover, credential compromise, and session hijackingImplement identity checks in CI/CD pipelines (secret scanning, IaC identity analysis), acting on AI-generated fix recommendations in PR workflowsTrack identity hygiene metrics and support audits, certifications, and e-discovery requirements alongside GRC
Skills
Must be able to obtain and maintain the required Public Trust clearance for this roleBachelor's in Computer Science, Information Security, or equivalent experience5+ years of hands-on experience in enterprise IAM or security engineering, with a focus on identity, authentication, and access domains, or a Master's degree in Cybersecurity or a relevant fieldHands-on experience with common identity tools such as IdP/SSO (Okta, Entra ID/Azure AD, Ping), IGA (SailPoint, Saviynt), PAM (CyberArk, BeyondTrust), and directory services, plus intermediate knowledge of authentication and federation protocols (SAML, OIDC, OAuth 2.0, SCIM, LDAP, Kerberos)Basic knowledge of industry-standard security benchmarks and frameworks (MITRE, NIST 800-63, Zero Trust)Proficiency in at least one scripting/automation language (Python, Bash, or PowerShell) applied to modern containerized services, CLI-based commands, and/or identity-specific use cases (API-driven provisioning, policy-as-code)Ability to communicate technical findings clearly to both engineering peers and non-technical stakeholdersFamiliarity with AI-enabled identity operations (UEBA, ML-based access-risk scoring, or AI-assisted access-review and threat-hunting workflows)Basic knowledge of common cloud environments (AWS, Azure, or GCP) and their native identity services (IAM, RBAC, workload identity)Working knowledge of the software development lifecycle, software engineering practices, or infrastructure-as-code environments: contributing identity and access controls (secrets management, workload identity, policy-as-code) to CI/CD pipelinesExperience with non-human, workload, and AI-agent identity, secrets management, and machine-to-machine authenticationExperience supporting compliance and audit requirements (SOC 2, ISO 27001, FedRAMP, HIPAA) from an identity and access control perspectiveRelevant certifications such as SC-300 (Microsoft Identity and Access Administrator), AZ-500 (Azure Security Engineer), Okta Certified Professional/Administrator, SailPoint IdentityIQ, SEC+, CISSP, CISA, or equivalent
Benefits
An annual performance bonusLong-term incentivesRemote work
Company Overview
Relativity provides legal data intelligence and AI technology for litigation and investigations. It was founded in 2001, and is headquartered in Chicago, Illinois, USA, with a workforce of 1001-5000 employees. Its website is http://www.relativity.com.
Company H1B Sponsorship
Relativity has a track record of offering H1B sponsorships, with 21 in 2026, 23 in 2025, 12 in 2024, 21 in 2023, 25 in 2022, 20 in 2021, 30 in 2020. Please note that this does not guarantee sponsorship for this specific role.