# Senior IAM Engineer

**Company**: xAI
**Location**: Austin, TX; Palo Alto, CA; Washington, D.C.
**Experience**: senior
**Job type**: full-time
**Salary**: $100,000 - $258,000 USD
**Category**: IT
**Industry**: Technology
**Wikidata**: https://www.wikidata.org/wiki/Q120599684

**Apply**: https://job-boards.greenhouse.io/xai/jobs/5180827007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_11fa492b-d98

## Description

## About the Role

We are looking for a Senior Identity and Access Management (IAM) Engineer to play a critical role in designing, implementing, and maturing our enterprise IAM ecosystem. As a Senior IAM Engineer, you will serve as a key subject matter expert (SME) within the broader Information Security organization, driving secure, scalable, and user-friendly identity solutions in a fast-paced, high-growth environment.

## Responsibilities

- Design and implement enterprise-grade IAM solutions across on-prem, cloud, and SaaS environments.

- Architect and deliver end-to-end federation strategies using modern protocols (SAML, OIDC, OAuth 2.0, SCIM).

- Lead integration and optimization of key IAM platforms including SailPoint, Okta, PingOne, Microsoft Entra ID, and other tools.

- Drive Identity Lifecycle Management (LCM), Role-Based Access Control (RBAC), Privileged Access Management (PAM), and Just-In-Time access initiatives.

- Develop automation scripts and Infrastructure as Code (Terraform) to improve provisioning, governance, and operational efficiency.

- Serve as the primary IAM SME, providing technical guidance, troubleshooting complex issues, and mentoring other team members.

- Work closely with InfoSec, Compliance, and Engineering teams to meet audit, regulatory, and security requirements.

- Continuously improve IAM architecture, processes, and capabilities in a dynamic, fast-moving organization.

- Support cloud IAM strategies across AWS, GCP, and other platforms.

- Participate in on-call rotation and incident response related to identity systems.

## Basic Qualifications

- 6+ years of hands-on experience in Identity and Access Management.

- Thorough understanding of IAM principles and modern security concepts, including Zero Trust, Least Privilege, Adaptive/Risk-Based Authentication, Attribute-Based Access Control (ABAC), Continuous Access Evaluation, and Identity Threat Detection and Response (ITDR).

- Strong expertise in IAM protocols and standards: SAML, OIDC, OAuth 2.0, SCIM, and other federation protocols.

- Strong expertise in IAM and federation protocols, with proven experience in architecting and implementing end-to-end federation solutions.

- Hands-on experience with major IAM platforms, particularly SailPoint, Okta, PingOne, and Microsoft identity solutions.

- Strong working knowledge of cloud platforms (AWS and GCP), Cloud IAM services, Terraform, and CI/CD practices.

- Strong scripting and programming skills in Python and JavaScript/TypeScript, with extensive experience developing IAM workflows, automation, and integrations.

- Demonstrated ability to lead technical initiatives and drive projects from design through implementation.

## Compensation and Benefits

$100,000 - $258,000 USD Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

## Skills

### Required
- Identity and Access Management
- IAM principles
- Zero Trust
- Least Privilege
- Adaptive/Risk-Based Authentication
- Attribute-Based Access Control (ABAC)
- Continuous Access Evaluation
- Identity Threat Detection and Response (ITDR)
- SAML
- OIDC
- OAuth 2.0
- SCIM
- SailPoint
- Okta
- PingOne
- Microsoft Entra ID
- Terraform
- Python
- JavaScript/TypeScript
- Cloud IAM services
- CI/CD practices

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/xai/jobs/5180827007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
