Staff Security Risk & Compliance Program Manager - Access Management
Own Confluent's access management strategy and roadmap for machine identity
Own the strategic direction and roadmap for Confluent's internal access management program with machine and workload identity as the center of gravity. Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes. Lead enforcement of service-to-service authentication and formalize non-human identity programs from pilot to funded governance.
Why This Role?
Own the horizontal governance of access across Confluent's distributed functions
Key Responsibilities
- Own the strategic direction and roadmap for the internal access management program
- Lead enforcement of service-to-service authentication across Trust & Security-owned surfaces
- Formalize non-human identity program from pilot to funded, governed state
- Stand up access controls for AI agents as agentic workloads acquire production access
- Own the Access Management Standard and policies for least privilege and separation of duties
- Ensure the standard remains audit-ready and keeps pace with evolving access surfaces
Requirements
- Experience owning internal access management programs
- Experience with machine and workload identity, service-to-service authentication
- Experience formalizing non-human identity programs
- Experience establishing access controls for AI agents
- Experience owning and evolving access management standards and policies
- Experience driving program maturity models toward governance and least-privilege outcomes
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
Keywords
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them. It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together. One Confluent. One Team. One Data Streaming Platform. ABOUT THE ROLE: We are seeking a highly motivated and experienced Staff Security Risk & Compliance Program Manager - Access Management to join our Trust & Security team. This senior role owns Confluent's internal access management program and leads its evolution toward machine and workload identity — service-to-service (S2S) authentication, non-human identity (NHI), and access controls for AI agents — as the next frontier of least-privilege security for the Confluent Cloud platform. You will be the horizontal owner of how Confluent governs access: the Access Management Standard, access metrics, and the executive reporting cadence. As access operations are distributed across partner functions, you will hold the policy, risk, and measurement line so Confluent maintains one coherent access posture rather than fragmented silos. WHAT YOU WILL DO: - Strategy and Leadership: Own the strategic direction and roadmap for Confluent's internal access management program, with machine and workload identity as the durable center of gravity. Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes. - Machine & Workload Identity: Lead the program to enforce service-to-service (S2S) authentication across Trust & Security-owned surfaces, taking ownership of the enforcement hand-off from the identity engineering team. Formalize non-human identity (NHI) — service accounts, keys, and workload credentials — from pilot into a funded, governed program. Stand up access controls for AI agents as agentic workloads acquire production access. - Access Governance & Standards: Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access. Ensure the standard keeps pace with the evolving access surface and remains audit-ready. - Metrics, Reporting & Governance Cadence: Own access metrics and reporting (e.g., JIT/unilateral-access volume, broad-privilege usage, prod-access reduction). Define and track program OKRs and run the monthly execution and executive-review cadence, articulating risk posture and progress to senior leadership. - Cross-Functional Execution & Transitions: Drive cross-functional delivery with engineering, platform, and identity teams without direct authority. - Integration with GRC and Partner Functions: Ensure the access management program is tightly integrated with adjacent GRC domains and partner teams (Insider Threat, IT/Identity, Detection & Response, and engineering owners), with clear RACI across governance and operations. WHAT YOU WILL BRING: - Experience: 8+ years in security program management, identity & access management, or a closely related security discipline, with at least 3 years running an enterprise- or platform-scale access program in a technology company. - Technical Skills: - Deep expertise in identity and access management concepts: least privilege, separation of duties, RBAC/ABAC, just-in-time (JIT) and privileged access management (PAM), and access review/certification. - Working knowledge of machine and workload identity — service-to-service authentication, non-human identity, service accounts, secrets/key management, and emerging AI-agent access patterns. - Strong security engineering fundamentals across cloud infrastructure security controls in GCP, AWS, and/or Azure, including Kubernetes and cloud control-plane access models. - Familiarity with identity platforms and access tooling (e.g., Okta, JIT/access-orchestration tooling) and how access controls are enforced in production. - Tooling and Automation: Experience integrating access processes, controls, or findings into GRC and access-orchestration platforms, and a bias toward automating access decisions over manual operations. - Program Management Skills: - Strong project management and organizational skills. - Exceptional analytical and problem-solving skills, with a data-driven approach to decision-making. - Experience running long-term, complex security programs that deliver iterative, measurable risk reduction. - Communication and Collaboration Skills: - Excellent written and verbal communication, with the ability to influence and lead without direct authority across engineering and security teams. - Ability to articulate complex technical concepts and program status to executive-level audiences and technical teams alike. READY TO BUILD WHAT'S NEXT? LET’S GET IN MOTION. COME AS YOU ARE Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible. We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law. PRIVACY STATEMENT Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization. By proceeding with this application, you understand that Confluent will share your personal information with other IBM affiliates involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross-border data transfer, are available here http://ibm.com/careers/us-en/privacy-policy/.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
Frequently asked questions
- Is Staff Security Risk & Compliance Program Manager - Access Management at Confluent a remote job?
- Yes. Staff Security Risk & Compliance Program Manager - Access Management at Confluent is a fully remote role open to candidates worldwide.
- What is the salary for Staff Security Risk & Compliance Program Manager - Access Management at Confluent?
- The listed pay range for this role is $222.1k–261k/yr.
- What type of employment is Staff Security Risk & Compliance Program Manager - Access Management at Confluent?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at Confluent.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- Senior Tech Roles Remote Salaries June 2026In-depth analysis of 7 senior tech role remote salaries from Vercel, Airbnb, Stripe, to Notion. Compare with local market and negotiation strategies.
- Sourcing Specialist: The Complete GlobalCurious about becoming a remote Sourcing Specialist? Learn the essential skills, tools, and how to land a USD-paying job—no matter where you live.
- Remote Mobile Developer Jobs July 2026A roundup of USD-paying remote mobile developer jobs from Loker Dollar. Analyze trends and get application tips.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume