Description
As a Staff Systems Engineer, Identity, you will serve as the primary technical owner of CoreWeave's enterprise identity ecosystem, with a focus on Okta and Opal. You will design, build, and operate identity lifecycle systems that are secure, automated, and scalable.
This is a highly visible, high-impact role where identity sits at the center of security. You will define how access is granted, changed, and removed across the organization, enabling business velocity while enforcing least privilege and strong governance.
Key responsibilities include:
Design and scale enterprise identity architecture that minimizes access sprawl and enforces least privilege
Own and improve Joiner, Mover, and Leaver (JML) lifecycle processes across all critical systems
Build and operate identity governance and administration (IGA) capabilities including birthright access models, role-based access control (RBAC), approval workflows and policy enforcement, access reviews and certification processes
Administer and enhance Okta capabilities (SSO, MFA, adaptive policies, lifecycle management, SCIM, integrations)
Build and scale access request workflows in Opal and integrated systems
Integrate new applications into the identity ecosystem (SAML, OIDC, SCIM, role mapping)
Develop automation and infrastructure-as-code to improve reliability and reduce manual effort
Partner with Security to strengthen identity as a core control plane (Zero Trust, authentication, authorization)
Align identity systems with PeopleOps and organizational changes
Monitor and improve identity system health, observability, and performance
Troubleshoot complex authentication, provisioning, and authorization issues
Maintain documentation, runbooks, and architectural standards
Serve as an escalation point for identity-related incidents
Drive continuous improvement in identity architecture, governance, and user experience
Requirements include:
7–10+ years of experience in IT systems engineering, identity engineering, or systems architecture
Deep hands-on experience with Okta in a complex enterprise environment
Strong expertise in identity and access concepts (SSO, MFA, SAML, OAuth, OIDC, SCIM, RBAC, Zero Trust)
Proven experience designing lifecycle automation (JML) and access governance frameworks
Experience with IGA or access request platforms such as Opal
Strong automation and infrastructure-as-code experience (Terraform, APIs, Python/PowerShell/Golang)
Ability to integrate enterprise applications into centralized identity platforms
Strong troubleshooting skills across identity, federation, and provisioning systems
Excellent communication skills with the ability to influence cross-functional stakeholders
Preferred qualifications include familiarity with Active Directory, Entra ID, HRIS systems, and SaaS ecosystems, experience building identity observability and reporting, and relevant certifications (Okta, cloud, or security).
Why CoreWeave?
At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:
Be Curious at Your Core
Act Like an Owner
Empower Employees
Deliver Best-in-Class Client Experiences
Achieve More Together
Why This Role Matters
Identity is one of the most critical control planes in a modern enterprise. In this role, you will define how secure access is managed across CoreWeave, ensuring identity remains a foundational pillar of security, compliance, and scale.
The base salary range for this role is $188,000 to $275,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).
What We Offer
The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs, including medical, dental, and vision insurance, company-paid life insurance, voluntary supplemental life insurance, short and long-term disability insurance, flexible spending account, health savings account, tuition reimbursement, ability to participate in employee stock purchase program (ESPP), mental wellness benefits through Spring Health, family-forming support provided by Carrot, paid parental leave, flexible, full-service childcare support with Kinside, 401(k) with a generous employer match, flexible PTO, catered lunch each day in our office and data center locations, a casual work environment, and a work culture focused on innovative disruption.