Talent Systems

Security Engineer, IAM

Talent Systems United States

Software Development · 201-500 employees

11 h ago
security Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer will design, implement, and manage global Identity and Access Management systems including SSO, MFA, and PAM. They will also collaborate with cross-functional teams to ensure compliance, monitor for anomalous activity, and automate access workflows.

What they look for

IAM SSO MFA RBAC PAM SAML OAuth 2.0 OpenID Connect LDAP SCIM Okta Azure AD Zero-trust Python PowerShell Bash

Requirements

Candidates must have 4+ years of hands-on experience in IAM engineering or identity security. Proficiency in IAM protocols like SAML and OAuth 2.0, along with experience administering enterprise identity providers, is required.

Full description

Security Engineer, IAMTitle: Security Engineer, IAM Level: IC-2 Location: Los Angeles, CA Work setup: In-office (4 days a week) Department: IT Company Talent Systems, LLC is the leading technology solution provider for casting and auditioning to the entertainment industry. Casting directors and agents worldwide use Talent Systems’ portfolio of products to source and manage talent across film, television, commercials, theater and digital projects, powering an unparalleled, global casting software ecosystem. We are headquartered in Los Angeles and operate in the US, Canada, UK, Australia and India. Our portfolio brands include Casting Networks, Spotlight, Cast It Systems, Cast It Talent, Casting Frontier, Staff Me Up, Cast It Reach & Tagmin. Job Description The Security Engineer, IAM will design, implement, and manage Identity and Access Management systems across Talent Systems' global technology stack. This role sits within the Corporate IT team and is critical to ensuring that the right people have the right access to the right resources and that unauthorized access is proactively detected and prevented. You will work cross-functionally with Engineering, Product, Security, and HR teams to build scalable, secure, and compliance-aligned identity infrastructure that supports our global platforms and workforce. IAM Architecture & Engineering• Design, deploy, and maintain IAM solutions including SSO, MFA, RBAC, and PAM across cloud and on-premise environments

  • Architect and manage identity federation using protocols such as SAML, OAuth 2.0, and OpenID Connect
  • Build and maintain lifecycle management processes for user provisioning, de-provisioning, and access reviews
  • Integrate IAM systems with SaaS platforms (Google Workspace, Slack, GitHub, Zendesk, and others) and internal applications
  • Develop and maintain automation for access request workflows and entitlement management

Security Operations & Compliance

  • Conduct periodic access reviews and certification campaigns to ensure least-privilege principles are enforced
  • Monitor IAM systems for anomalous activity, access violations, and policy drift; respond to and remediate incidents
  • Support audit and compliance activities related to SOC 2, PCI-DSS, GDPR, and other applicable frameworks
  • Define and enforce IAM policies, standards, and procedures in alignment with industry best practices
  • Collaborate with the Information Security Office to evaluate and close identity-related vulnerabilities

Cross-Functional Collaboration

  • Partner with Engineering and DevOps teams to embed IAM controls into CI/CD pipelines and cloud infrastructure
  • Work with IT Team to align identity processes with endpoint and network security policies
  • Support onboarding, offboarding, and role-change workflows in coordination with People Operations
  • Participate in cross-functional planning to surface IAM-related risks, roadmap items, and quarterly priorities
  • 4+ years of hands-on experience in IAM engineering, identity security, or a closely related field
  • Proficiency with IAM protocols: SAML, OAuth 2.0, OpenID Connect, LDAP, SCIM
  • Experience administering an enterprise identity provider (e.g., Okta, Azure AD / Entra ID, Google Workspace Identity, or equivalent)
  • Solid understanding of RBAC, least-privilege, and zero-trust principles
  • Familiarity with compliance frameworks including SOC 2 Type II, GDPR, and ISO 27001
  • Excellent written and verbal communication skills; able to explain complex identity concepts to non-technical stakeholders
  • Preferred: Experience with Privileged Access Management (PAM) tools (e.g., CyberArk, BeyondTrust, HashiCorp Vault)
  • Preferred: Demonstrated ability to script and automate IAM workflows using Python, PowerShell, Bash, or similar
  • Preferred: Hands-on experience with cloud IAM (AWS IAM, GCP IAM, or Azure RBAC)
  • Preferred: Background in SaaS or multi-tenant platform environments with complex user hierarchy management
  • Preferred: Exposure to entertainment, media, or marketplace platform security
  • Preferred: Experience working in a globally distributed team across multiple time zones

Similar roles