Posted today · be early
Principal Identity Engineer
Hard Rock Digital
WorldwideremotePosted today
Skill Required
Identity-EngineerSecurity-EngineerIAM-EngineerIdentity-And-Access-Management-EngineerPrincipal-EngineerPrincipal-Identity-EngineerPrincipal-Identity-And-Access-Management-EngineerSenior-Identity-Engineering-SpecialistIdentity-Management-EngineerIdentity-Security-EngineerIdentity-Platform-EngineerIdentity-Integration-EngineerSenior-Cloud-Identity-EngineerStaff-Identity-Engineerrelated fieldIstioEngineeringCloud SecurityISO 27001automationShell ScriptingObservabilitydesigningsecuritybuildingPythonwrittendesignAzureOAuthCloudRustIAMAWSGCPandAIFulltime
Key highlights
- Required experience: 10+ years in IAM or security engineering
- Key benefit: Hybrid / remote working environment
- Notable requirement: Hands-on experience applying AI to security or engineering work
- Reporting line: Reports directly to VP Security / CISO
Role overview
Hard Rock Digital is building a world-class online sportsbook, casino, and social gaming company. They are seeking a Principal Identity Engineer to serve as the technical authority on identity systems, acting as the backbone of their Zero Trust security program. This is a high-trust, senior role reporting directly to the VP Security / CISO. As the first dedicated identity hire within a 16-person security organization, the successful candidate will own the identity domain end-to-end, focusing on architecture, automation, and governance to ensure safe access across the organization.
Responsibilities
- Own the security architecture, standards, authentication methods, and roadmap for Microsoft Entra ID, our primary identity provider — partnering with IT on tenant operations
- Design and continuously refine Conditional Access policies that balance strong protection with a smooth experience for a globally distributed workforce
- Advance our rollout of phishing-resistant, passwordless authentication (passkeys, certificate-based, FIDO2)
- Own federation and single sign-on across our SaaS estate (SAML, OIDC, OAuth 2.0, SCIM provisioning)
- Own our privileged access model using Microsoft Entra PIM — separate admin identities, just-in-time elevation, and approval workflows
- Design and maintain break-glass procedures and safeguards for our most sensitive administrative paths
- Reduce standing privilege across the environment and make "least privilege, just in time" the default
- Automate the joiner-mover-leaver lifecycle so access is granted, changed, and revoked accurately and promptly
- Build and run access reviews and entitlement governance, partnering with our GRC team on audit evidence (ISO 27001, SOC 2, PCI DSS, GLI-19/GLI-33)
- Make access decisions auditable, explainable, and continuously right sized
- Govern service principles, managed identities, and workload/federated credentials across AWS, Azure, and GCP
- Partner on secrets governance across our secrets management platforms to shrink the number of long-lived, standing secrets
- Partner with our Principal Cloud & Network Security Engineer, who owns service-to-service authentication (mTLS, service mesh)
- Serve as the identity authority for our Zero Trust program, aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model (Identity pillar)
- Partner with our cloud and network security function on identity-aware access through Cloudflare Access
- Partner with Security Operations to make identity signals (risky sign-ins, privileged elevation, MFA anomalies) first-class inputs to detection and response
- Advise on customer identity (CIAM) and account-security architecture — partnering with our Principal Product Security Engineer, who owns the application security of player-facing account flows, and with product engineering
- Set the identity roadmap with the CISO
- Act as the escalation point for identity-related incidents
Requirements
- 10+ years in identity and access management, security engineering, or a closely related field — or equivalent practical experience
- Deep, hands-on expertise with a modern enterprise identity platform — Conditional Access, PIM/PAM, authentication methods, and identity governance (we run Microsoft Entra ID)
- Strong command of identity protocols and patterns: SAML, OIDC, OAuth 2.0, SCIM, and modern MFA
- Experience automating the identity lifecycle and integrating identity across a large SaaS and multi-cloud estate
- Scripting and automation skills (PowerShell, Microsoft Graph API, Python) and comfort with Infrastructure as Code
- A track record of designing least privilege, just-in-time access in a real production environment
- Excellent written and verbal communication — you can explain an access decision to an engineer and a risk to an executive
- Fluency with AI — you lead with it, reaching for AI tools daily to work faster and sharper; hands-on experience applying AI to security or engineering work is a must
- Strategic and hands-on — you set direction and you build the thing
- Fiercely focused - zero in on the control that matters most and finishes strong
- Deeply curious — you test assumptions and keep learning as the identity landscape shifts
- Customer obsessed about access — you treat login friction as a security outcome and design controls people don't have to fight
- A clear communicator who builds trust across security, IT, engineering, and leadership
Nice to have
- Experience in a regulated industry (gaming, financial services, healthcare)
- Exposure to customer/player identity (CIAM) and KYC providers
- Passwordless or phishing-resistant MFA rollouts at scale
- Familiarity with Identity Threat Detection & Response (ITDR)
- Relevant certifications (e.g., Microsoft Identity & Access Administrator, CISSP)
Benefits
- Competitive pay and benefits
- Flexible vacation allowance
- A hybrid / remote working environment
- Startup culture backed by a secure, global brand
Additional details
- This is one of three Principal openings reporting directly to our VP Security / CISO
- Day-to-day provisioning and helpdesk sit with our IT team
- The role is within a 16-person security organization spanning Security Operations, Risk Management, and Architecture & Engineering
- Year one is focused on sequencing the identity roadmap
- 24/7 Security Operations team owns monitoring
- This role is part of a trio of Principal openings: Identity, Cloud & Network Security, and Product Security
- Equal opportunity employer
- Originally posted on Himalayas