Iam Security Engineer 3

MongoDB MongoDB · Enterprise · New York, NY · Enterprise Security

IAM Security Engineer 3 at MongoDB responsible for designing, implementing, and operating identity, access, and endpoint security solutions. Focuses on IAM platforms like Okta, AWS IAM, GCP IAM, and Azure AD, automation using Terraform/Python, and supporting compliance initiatives like FedRAMP High.

What you'd actually do

  1. Operate and enhance IAM platforms, including Okta, AWS IAM, GCP IAM, and Azure AD, helping to ensure secure, least-privilege, and scalable access models for employees and service accounts.
  2. Implement and support SSO integrations (SAML, OIDC, OAuth2) and MFA enforcement for internal and third-party applications.
  3. Help maintain and improve RBAC models, groups, and policies, ensuring access is consistent with business needs and audit requirements.
  4. Contribute to the identity lifecycle (provisioning, deprovisioning, access changes, and just-in-time access) using automation (Terraform/OpenTofu, Python, Tines) to reduce manual effort and errors.
  5. Assist with hardening non-human identities (service accounts, workloads, automation identities, agentic AI systems), focusing on least-privilege and proper key/secret management.

Skills

Required

  • Identity & Access Management
  • Security Engineering
  • Cloud Security
  • Okta administration
  • AWS IAM
  • GCP IAM
  • Azure AD
  • OAuth2
  • OIDC
  • SAML
  • MFA
  • RBAC
  • Python
  • Bash
  • Terraform
  • OpenTofu
  • Datadog
  • SIEM tools

Nice to have

  • Phishing-resistant authentication
  • WebAuthn
  • FIDO2
  • YubiKey
  • IGA platforms
  • Zero Trust
  • MDM platforms
  • Jamf
  • Workspace ONE
  • Kolide
  • Tines
  • Okta Certified Administrator
  • AWS Associate/Professional certifications
  • Security+ certification

What the JD emphasized

  • FedRAMP High
  • US Citizen