L
LambdaSan Francisco, California, United States {{REMOTE}}
Engineering Manager (Identity & Access Management (IAM))
On-siteFull Time$297k - $440k per yearPosted 25 days ago
About the role
- We are looking for an Engineering Manager to lead the Identity and Access Management team and define how identity, authentication, authorization, and key-management services are built and scaled across Lambda Cloud
- His team owns the foundational identity and authorization services on the critical path for every Lambda product – spanning APIs, Console, Kubernetes products, and cloud services – including identity federation, SSO, SCIM, users and groups, service and workload identities, RBAC, resource hierarchy, policy enforcement, and audit integration
- This is a technically engaged leadership role. You will own execution, team health, and organizational direction working with technical leadership on architecture, strategy and design decisions for services that must be highly available, low latency and resilient
- You will also drive alignment across Security, Product, Compliance, and customer-facing teams to build durable platform capabilities that are adopted consistently across Lambda’s services
- Build, lead, and grow the IAM engineering team. Hire exceptional engineers, develop technical leaders, and create a culture of ownership and high engineering standards
- Work closely with the IAM technical leaders to define and deliver the long-term technical and architectural strategy for Lambda’s IAM platform
- Build secure, scalable identity capabilities for people, services, and workloads from federation and SSO to service and workload identity
- Evolve the authorization platform – RBAC, policy evaluation, and resource hierarchy with least privilege and auditability as defaults
- Make IAM easy to adopt across every Lambda service through consistent APIs, resource and action models, and integration standards
- Build and own Lambda’s Key Management Service, including customer-managed keys, HSM-backed protection, key lifecycle controls, and integration across compute, storage, and networking
- Own the reliability, security, performance, and operations of mission-critical IAM services including observability, safe rollouts, incident response, and disaster recovery
- Translate enterprise requirements into durable platform capabilities, and communicate strategy, delivery, risk, and operational health clearly to senior leadership
- Balance the complexity and flexibility required for enterprise-grade IAM with simple, intuitive experiences for customers with varying levels of identity and access expertise Benefits
- Health, dental vision
- 401k match
- 5 sick days and 12 paid holidays
- Flexible PTO
- Paid parental, medical, and caregiver leave
- This role is ideal for an engineering leader who has built security-critical distributed systems and wants to shape the identity and access foundation of a fast-growing cloud platform
- Have a strong track record of building high-performing teams and developing engineers and technical leaders through periods of growth and change
- Bring strong technical judgment across cloud infrastructure and IAM — authentication, authorization, workload identity, privileged access, and policy enforcement
- Have driven cross-functional platform or security initiatives and influenced teams and leaders without direct authority
- Communicate clearly with technical and non-technical stakeholders and set a high bar for engineering quality, operational discipline, and ownership
- Have built and operated large-scale distributed systems with high availability, security, and reliability requirements
- Can engage deeply in architecture, pressure-test designs, and guide tradeoffs across security, correctness, scale, performance, and operability
- Can turn ambiguous infrastructure problems into clear strategy, pragmatic execution, and broadly adopted platform capabilities
- Have 9+ years of professional software engineering experience, including 3+ years leading and developing engineering teams in a fast-paced environment
- Hold a BS, MS, or PhD in Computer Science or a related technical field, or have equivalent practical experience
- Experience with KMS, HSMs, customer-managed keys, secrets management, or encryption platforms
- Experience with public-cloud or multi-tenant IAM, authorization/policy engines, or security token services
- Experience supporting compliance programs such as SOC 2 or translating compliance requirements into platform capabilities
- Experience supporting enterprise or regulated customers, or building foundational platforms in a high-growth environment