Senior Security Engineer - IAM
Define hardened identity standards for Entra ID, Active Directory, Okta, and cloud IAM
As a Senior Security Engineer for IAM at TENEX.AI, you will define what hardened identity looks like across Entra ID, Active Directory, Okta, and cloud IAM platforms. You will build and maintain configuration and hardening standards grounded in real-world attack patterns, not generic checklists. Your work involves analyzing customer environments to identify attacker paths and supporting SOC and incident responders when identity is involved in ...
Why This Role?
Play a meaningful role in defining and building company culture as an early employee
Key Responsibilities
- Define hardened identity standards for Entra ID and Active Directory
- Build and maintain configuration standards for Okta and cloud IAM
- Analyze customer environments to identify attacker paths in identity systems
- Support SOC and incident responders during identity-related security incidents
- Keep identity hardening standards current based on actual attack techniques
Requirements
- Deep knowledge of identity systems down to the protocol level
- Experience thinking in attack paths for identity infrastructure
- Ability to assess customer IAM architectures and identify missed risks
- Background in cybersecurity with focus on identity and access management
- Experience with Entra ID, Active Directory, Okta, and cloud IAM platforms
Required Skills
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
COMPANY OVERVIEW: TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape. We’re a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you’ll play a meaningful role in defining and building our culture. Get in on the ground floor. We’re a small but well-funded team that just raised a substantial round – joining now comes with limited risk and unlimited upside. Culture is one of the most important things at TENEX.AI http://TENEX.AI—explore our culture deck at culture.tenex.ai http://culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in-person work. ABOUT THE OPPORTUNITY: Almost every serious intrusion runs through identity at some point: a stolen token, an over-permissioned service principal, a trust relationship nobody remembered was there. It is also where defenders have the least margin for error, and where compliant and hard to attack are rarely the same thing. As Senior Security Engineer for IAM, you own that problem for TENEX and our customers. You will define what hardened identity actually looks like across Entra ID and Active Directory, Okta, and cloud IAM, take customer environments apart to find the paths an attacker would take, and back our SOC and incident responders when identity is in play. This is for someone who knows identity down to the protocol level, thinks in attack paths, and can sit across from a customer’s IAM architect and be the one who spots the risk they missed. WHAT YOU’LL DO: - Define what hardened identity looks like. Build and maintain the configuration and hardening standards for Entra ID and Active Directory, Okta, and cloud IAM, grounded in how these platforms actually get attacked rather than a generic checklist. Keep them current as the vendors ship changes and attackers find new paths. - Reduce IAM risk for customers. Work through customer identity environments and map the attack paths: excessive privilege and shadow admin, weak or bypassable authentication, loose federation and trust, stale access, and the tier-0 exposure that turns one foothold into full tenant or domain compromise. Then drive the remediation that actually closes them. - Work alongside customer identity teams. Sit across from client IAM engineers and architects as a peer, review their designs, and push back where the risk warrants it. Give clear, prioritized recommendations they can put into production. - Advise the SOC and IR. Be the identity expert our analysts and responders reach for when something looks off: anomalous token use, a suspicious OAuth consent grant, a golden SAML, lateral movement across trust relationships. Help them scope identity-driven incidents fast and know what to pull and what to contain. - Mature how the SOC handles identity. Assess how well the SOC can respond to and contain identity attacks today, then close the gaps: the detections that need to fire, the containment actions that should be fast and repeatable (revoking sessions and tokens, disabling accounts, killing malicious app grants, cutting an abused trust), and the playbooks that hold up under pressure. WHAT YOU BRING: - 7+ years deep in identity, hands-on across Entra ID and Active Directory, Okta, and cloud IAM (AWS, GCP, Azure), with real command of authentication, authorization, federation and trust, and privileged access. - The attacker’s view of identity: how Kerberos, SAML, OAuth, and OIDC break in practice, and how a single foothold becomes privilege and then persistence. - A track record of hardening real identity environments and getting the fixes shipped, not just writing up the gaps. - The depth and credibility to be the authority on identity risk in any room, including across the table from a customer’s own IAM architects. BONUS POINTS: - You can code, and you use AI to move faster: automating assessments, parsing sign-in and audit logs, and building tooling instead of doing it by hand. - Time in an MDR, MSSP, security consulting, or a high-growth startup. - Identity attack experience from the offensive side, or detection and IR work where identity was the story. EDUCATION & CERTIFICATIONS: - Bachelor’s degree in Computer Science, Cybersecurity, or Engineering, or a related field (or equivalent experience). - Relevant certifications such as Microsoft SC-300, Okta certifications, a cloud identity or security specialty, CISSP, or an offensive cert like CRTP or OSCP are a plus. WHY JOIN US? - Own identity hardening across an MDR customer base and be the person who closes the attack paths before an intruder walks them. - Collaborate with a talented and innovative team focused on continuously improving security operations. - Competitive salary and benefits package. - A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.
Salary Context
Similar Engineering roles on LokerDollar pay around $195k/yr (range $36k–395k/yr, n=251 active listings).
Hiring at TENEX.AI
TENEX.AI has 22 other active roles on LokerDollar and has been hiring here since May 3, 2026 — across Engineering, Data & Analytics.
View all TENEX.AI openings →Openness not stated by employer — check the listing
Frequently asked questions
- Is Senior Security Engineer - IAM at TENEX.AI a remote job?
- This role is based in Remote. See the listing for remote/onsite details.
- What type of employment is Senior Security Engineer - IAM at TENEX.AI?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at TENEX.AI.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Remote ≠ Remote: The Skills That Open Global Work to Indonesians (2026)12,891 remote listings: the highest-paid coding skills are the most geo-locked for Indonesia-based applicants. CC BY 4.0 aggregate dataset.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- Interview Radiologist Remote: What You NeedBreaking down the remote radiology interview process for USD-paying jobs, from screening to offer letter.
- Remote Radiology Jobs: August 2026 UpdateDiscover the latest remote radiology jobs and salary trends for August 2026. Learn about the opportunities and challenges of remote work in radiology.
- Unlocking Remote USD Jobs: A GuideDiscover the best remote USD-paying jobs and learn how to succeed in the global job market.