
cybersecurity engineer senior, Identity Lifecycle and Authentication Services
- Seattle, WA
- Permanent
- Full-time
- Deploy and maintain identity services that support authentication, authorization, and lifecycle management across cloud and on-prem environments.
- Contribute to the design and enforcement of Zero Trust principles across identity workflows.
- Conduct technical evaluations, proof-of-concepts, and vendor assessments for identity-related tools and services.
- Support the integration of technologies such as IGA, adaptive access controls and risk-based authentication mechanisms into Starbucks' identity ecosystem.
- Configure and implement identity solutions using protocols and standards such as SAML, OAuth, OpenID Connect, and SCIM.
- Develop and maintain documentation, runbooks, and knowledge articles for identity services.
- Participate in incident response and troubleshooting related to identity and access issues.
- Collaborate with engineering, security, and business teams to integrate identity solutions into enterprise platforms and applications.
- Partner with the Security Architecture team to ensure platform goals and security solutions align with business strategy and objectives.
- Monitor threat intelligence feeds and reports, and develop remediation strategies based on findings.
- Design and implement security controls that meet compliance requirements, including SOX, PCI, and internal controls.
- Provide mentorship and technical guidance to junior engineers and cross-functional partners.
- 5+ years of experience in information technology, with a strong emphasis on cybersecurity
- 5+ years of hands-on experience in Identity and Access Management (IAM), including workforce and B2B identity lifecycle management, and authentication processes
- Demonstrated experience deploying and managing cloud identity platforms like Microsoft Entra ID in complex-hybrid environments
- Solid understanding of identity standards and technologies such as SAML, OAuth, OpenID Connect, SCIM, and MFA
- Solid understanding of IAM principles, including user lifecycle management, provisioning with SCIM, and compliance frameworks
- Expertise in developing and executing enterprise-wide identity strategies and governance frameworks. Experience with IAM automation, including workflows, API integrations, and scripting (e.g. PowerShell)
- Deep knowledge on Role-Based Access Control (RBAC) and fine-grained authorization including lifecycle management of non-human identities (NHIs)
- Proven ability to assess, mitigate, and respond to cybersecurity risks and vulnerabilities
- Excellent written and verbal communication skills, with the ability to convey complex technical concepts to diverse audiences
- Certifications such as CISSP, CISM, CIPM, or others focused on cybersecurity, IAM, data privacy or information risk management.