Match Group is seeking a Senior Information Security Engineer to advance a unified identity and access security strategy across its global portfolio. The role will shape identity lifecycle controls, modern authentication and authorization patterns, and automation that reduces manual effort while strengthening security outcomes.
Key Responsibilities
- Lead a comprehensive identity and access lifecycle strategy for global teams, including authentication (AuthN) with enforcement of device trust, post-auth detection, and DPoP.
- Own authorization (AuthZ) with least privilege and right-sized entitlements to balance security controls with business velocity.
- Establish secure management practices for non-human identities (NHIs), such as OAuth tokens, service accounts, and API keys, and define security guardrails for AI agents and MCP connections.
- Modernize Privileged Access Management (PAM) and implement Just-in-Time (JIT) access to reduce standing privileges and better secure high-risk administrative actions.
- Harden Cloudflare ZTNA policies and support the transition from traditional network-based access approaches.
- Integrate identity strategy with broader enterprise security efforts by bringing together device signals from endpoint posture (Fleet/EDR), SaaS security, and vulnerability management into unified access controls.
- Reduce manual operational toil by engineering automated solutions using scripting, no-code tools, or AI, focusing on scalable fixes instead of repetitive manual work.
Required Qualifications
- 7+ years in security engineering, IT engineering, or infrastructure, with substantial depth in identity and access.
- Strong hands-on experience with Okta, including policy design, device assurance, FastPass, device trust, and RBAC.
- Experience with Cloudflare Zero Trust or an equivalent platform.
- Solid understanding of SAML, OIDC, OAuth 2.0, and SCIM.
- Experience with IGA platforms (for example, Okta Identity Governance and SailPoint), with deep knowledge of identity lifecycles and compliance requirements.
- Experience securing non-human identities (service accounts, OAuth apps, tokens) and building guardrails for AI agents, including the ability to articulate approach and perspective on emerging challenges.
- Hands-on experience using Terraform or other IaC tools for infrastructure changes, with a strong focus on GitOps workflows.
- Practical understanding of least privilege, with the ability to right-size access while minimizing friction for the business.
- Experience building automation (for example, Okta Workflows, Lambda, Windmill) using Python or similar technologies, with judgment on when to automate and when to avoid over-engineering.
- Practical use of AI tooling within personal workflow.
- Proven ability to influence cross-functional outcomes without relying on direct formal authority.
- Capability to proactively identify, scope, and drive complex problems to completion.
Technologies
Okta, Cloudflare Zero Trust, SAML, OIDC, OAuth 2.0, SCIM, Okta Identity Governance, SailPoint, Terraform, GitOps, Okta Workflows, Lambda, Windmill, Python, Fleet/EDR, DPoP, RBAC, Cloudflare ZTNA, MCP.
Nice to Have
- Endpoint management or EDR exposure (for example, Jamf, CrowdStrike, or similar).
- Audit and compliance experience with access controls, including SOX, PCI-DSS, or ISO 27001.
- Experience supporting global environments (EMEA/APAC).
Role Details
- Location: New York, NY (onsite)
- Compensation: USD 180,000 - 200,000 per year
- Minimum Experience: 7 years
Company Values
- Take the Lead: Do not ghost work or teammates.
- Move Fast: Maintain a bias for action and urgency.
- Better Together: Keep collaboration and connection at the center of how work gets done.
- Real Talk: Communicate clearly, including the hard conversations with candor.
- Safety First: Act with integrity, transparency, and consistency.
- Spark Fun: Encourage creativity and innovation through positive energy.