Staff Iam Engineer

SoFi SoFi · Fintech · San Francisco, CA · Information Security

Staff IAM Engineer responsible for securing and managing non-human identities (service accounts, API tokens, machine credentials) across on-prem, cloud, and crypto infrastructure. Focuses on designing systems for secure authentication, secrets management, and access provisioning for automated services, APIs, and DevOps pipelines, ensuring governance, lifecycle, and least-privilege principles are followed. Role involves architecture, engineering, lifecycle management, automation, security, risk management, and compliance with financial regulations.

What you'd actually do

  1. Design, implement, and maintain a Non-Human Identity (NHI) framework governing all service accounts, API tokens, certificates, and machine credentials.
  2. Implement centralized secrets management using tools such as HashiCorp Vault or AWS Secrets Manager,
  3. Build integrations with CI/CD pipelines and cloud services (AWS, GCP, Azure) to enforce automated credential rotation and JIT provisioning.
  4. Develop automated workflows for creation, rotation, deactivation, and certification of service accounts and API keys.
  5. Produce compliance reports for SOX, SOC 2, PCI DSS, FFIEC, and crypto-custody audits.

Skills

Required

  • IAM
  • DevSecOps
  • Security Engineering
  • Non-human identity management
  • Secrets management tools
  • Cloud IAM concepts (AWS IAM Roles, Azure Managed Identities, GCP Service Accounts)
  • CI/CD pipeline integration
  • DevOps tools
  • Automation and scripting (Python, PowerShell, or Bash)
  • Authentication standards (OIDC, OAuth 2.0, SAML, JWT)
  • API security
  • Key rotation policies
  • Service-to-service authentication
  • Container and workload identities (Kubernetes, ECS, Lambda)
  • Zero Trust principles
  • Machine identity management
  • Certificate lifecycle management

Nice to have

  • HashiCorp Vault
  • AWS Secrets Manager
  • Okta
  • HashiCorp Certified Vault Associate
  • AWS Certified Security – Specialty
  • Okta Certified Professional or Administrator
  • Certified Identity and Access Manager (CIAM)
  • CISSP

What the JD emphasized

  • non-human identities
  • service accounts
  • API tokens
  • machine credentials
  • secrets management
  • SOX
  • SOC 2
  • PCI DSS
  • FFIEC
  • crypto-custody audits