Headquarters: Remote - United States
About Vercel:
Vercel is the agentic infrastructure company, freeing people and agents to ship what's next. For more than a decade we've helped builders move from idea to production with speed, security, and exceptional developer experience.
Now we're scaling our products for both agents and people to ship and run software, built in the open and trusted by OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.
About the Role:
Traditional IAM teams operate as an approval queue: a request comes in, someone reviews it, grants it, and (hopefully) remembers to revoke it. Access reviews become quarterly spreadsheet exercises, audit evidence is assembled by hand, and the central team becomes the bottleneck for every decision. That model doesn't scale past a certain point, and Vercel is past it. Adding more approvers doesn't close the gap. Building the system that makes access self-serve, time-bound, and provable does.
This role is about building that system. Identity at Vercel should work like the rest of our infrastructure: defined as code, reviewed in pull requests, deployed through CI, and observable in production. You'll own that transformation end to end: migrating Okta and all related IAM configuration fully behind Terraform, and building the self-serve access platform (including just-in-time access) that lets team and system owners define, request, and time-bound their own access instead of routing every decision through a central team. Provisioning, deprovisioning, and access reviews become workflows the system runs, with the audit evidence for SOC 2 and similar generated as a byproduct rather than a manual scramble.
You'll also own the harder connective work: corporate IAM (employee identity, SaaS access, devices) and production IAM (service accounts, infrastructure permissions, on-call and prod access) usually live in separate silos with separate tools and separate evidence trails. You'll build them as one identity plane.
And identity itself is changing shape. As agents increasingly act on behalf of users and systems, the old model of "one human, one identity" doesn't hold, and there's real debate about how to solve it: carry the human's identity through every hop the agent makes, or give the agent its own scoped identity that never impersonates the user. We don't have a fixed answer yet. We want someone who wants to be in the room helping us decide and then build it.
Because of this, we're optimizing for someone who wants to build identity infrastructure as software, not administer identity products. A software engineer who's gone deep on identity, or an IAM engineer with a strong engineering background, is exactly who we're looking for.
You'll work closely with Security Leadership, located remotely within the United States. If you're based within commuting distance of our SF or NY offices, the role includes in-office anchor days on Monday, Tuesday, and Friday.
What You Will Do:
- Own the full IAM strategy for corporate, production, and product environments end to end, and own the bridge between corp IAM and product/prod IAM rather than treating them as separate problems
- Migrate Okta and all related IAM configuration to Terraform, so every identity change is reviewed, tested, and versioned like the rest of our infrastructure, driving infrastructure-as-code adoption and leveling up engineering teams in its use
- Build self-serve access governance tooling, including JIT (just-in-time) access: design and ship the framework that lets team and system owners define, request, and time-bound their own access, rather than security being a bottleneck for every request
- Own provisioning, deprovisioning, and access review workflows, built so the evidence trail generates itself and internal and external audits (SOC 2 and similar) are fast, not a manual scramble
- Work closely with the Accounts team, the engineers who build IAM into Vercel's own product (team and project roles, enterprise SSO, SCIM, API tokens), and find where that world and ours should connect
- Design and enforce least-privilege access controls across cloud, SaaS, and production infrastructure, partnering with platform and engineering teams to embed IAM early in design rather than bolting it on after
- Help define what identity and access should look like as agents, not just people, request and hold access at Vercel, and build the first versions of it
About You:
- 7+ years of experience in identity, access management, or platform security engineering
- Experience building internal tools or self-service platforms, not just administering existing ones. You'd rather build the framework that lets other teams manage their own access than be the sole approver for every request
- Proficient in a production language like TypeScript/Node.js, Go, or Python, comfortable designing and consuming REST APIs, and able to ship and operate reliable services. The access platform you'll build is a production system, not a configuration
- Proficient in Terraform and committed to managing IAM infrastructure as code, ideally with experience migrating existing systems into it
- Hands-on with identity protocols (OAuth2, OIDC, SAML, SCIM) at the implementation level, not just configuration, including the failure modes: token replay, deprovisioned users retaining access, sync drift between identity providers and downstream systems
- Experience designing IAM at scale across both corporate (Okta or equivalent: SSO, MFA, lifecycle management, API-driven automation) and production (AWS or GCP IAM: service accounts, roles, workload identity federation) environments
- A systems thinker who defaults to "why does this class of access request exist" and "how does this scale to the next thousand employees and ten thousand agents," not just resolving the request in front of you
- Strong collaborator who can drive alignment across Engineering, IT, Compliance, and Security teams
- Comfortable operating with autonomy and owning decisions in a fast-moving environment
Bonus If You Have
- Have led a Terraform migration for IAM or identity infrastructure at scale.
- Have designed or built JIT access systems or an access governance/request platform at a previous company.
- Have built or managed MDM/MAM tooling (Jamf, Intune, or equivalent) and device-trust integrations with identity.
- Understand how Vercel's own products handle IAM (team and project roles, enterprise SSO, API tokens) and are excited to partner with the Accounts team to bring internal and product-facing identity closer together.
- Have a point of view on agent identity (delegation, scoped credentials, impersonation boundaries) and want to help invent the architecture rather than apply an existing playbook.
- Have experience at a developer tools, infrastructure, or SaaS company.
- Hold certifications such as Okta Certified Professional/Administrator, AWS Security Specialty, or CISSP. These demonstrate depth, though they're not required.
Compensation & Benefits:
- Competitive compensation package, including equity.
- Inclusive Healthcare Package.
- Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
- Flexible Time Off.
- We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
The San Francisco, CA base pay range for this role is $208,000 - $312,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Disclosures:
- Privacy: Please review our Job Applicant Privacy Policy for more information on how we handle your data.
- Equal Opportunity: Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.
To apply: https://weworkremotely.com/remote-jobs/vercel-security-software-engineer-iam