Engineering Manager, Identity & Access Management (IAM)
$297,000–$440,000 year
HybridSan Francisco, California, United States or San Jose, California, United States
Job Summary
Build and lead the IAM engineering team, defining long-term architectural strategy for identity, authentication, authorization, and key-management services across Lambda's APIs, Console, and Kubernetes products. Evolve the authorization platform with RBAC, policy enforcement, and audit integration while owning the Key Management Service, including customer-managed keys and HSM-backed protection. Drive alignment with Security, Product, and Compliance teams to ensure secure, scalable capabilities are adopted consistently. Manage reliability, security, and operations for mission-critical services, translating enterprise requirements into durable platform capabilities. Requires 9+ years of engineering experience with 3+ years leading teams, with presence in San Francisco or San Jose four days per week.
Required Qualifications
- 9+ years of professional software engineering experience
- 3+ years leading and developing engineering teams in a fast-paced environment
- Built and operated large-scale distributed systems with high availability, security, and reliability requirements
- Strong technical judgment across cloud infrastructure and IAM — authentication, authorization, workload identity, privileged access, and policy enforcement
- Ability to engage deeply in architecture, pressure-test designs, and guide tradeoffs across security, correctness, scale, performance, and operability
- Strong track record of building high-performing teams and developing engineers and technical leaders through periods of growth and change
- Experience driving cross-functional platform or security initiatives and influencing teams and leaders without direct authority
- Ability to turn ambiguous infrastructure problems into clear strategy, pragmatic execution, and broadly adopted platform capabilities
- Clear communication with technical and non-technical stakeholders
- BS, MS, or PhD in Computer Science or a related technical field, or equivalent practical experience
- Presence in San Francisco or San Jose office location 4 days per week
Desired Qualifications
- Experience with public-cloud or multi-tenant IAM, authorization/policy engines, or security token services
- Experience with KMS, HSMs, customer-managed keys, secrets management, or encryption platforms
- Experience supporting enterprise or regulated customers, or building foundational platforms in a high-growth environment
- Experience supporting compliance programs such as SOC 2 or translating compliance requirements into platform capabilities
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.