IAM 安全工程师
查看雇主原标题
IAM Security EngineerCloudflare · Hybrid
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 50/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译关于我们
在 Cloudflare,我们的使命是帮助构建更好的互联网。如今,公司运营着全球最大的网络之一,为从个人博主到中小企业再到《财富》500 强企业的客户提供支持,驱动着数百万个网站和其他互联网资产。Cloudflare 无需添加硬件、安装软件或更改一行代码,即可保护和加速任何在线互联网应用。由 Cloudflare 提供支持的互联网资产,其网络流量都会通过其智能全球网络进行路由,而该网络会随着每一次请求变得更加智能。因此,它们的性能显著提升,垃圾邮件和其他攻击也减少了。Cloudflare 曾入选《Entrepreneur Magazine》的顶级公司文化榜单,并被《Fast Company》评为全球最具创新力公司之一。
在 Cloudflare,我们寻找的不是等待一份完美路线图的人;我们寻找的是那些看到互联网裂缝的构建者,而其他人只是学会了忍受这些裂缝。我们看重那些有直觉发现“被正常化”的问题,并具备 AI 原生好奇心、能够利用最新工具创造解决方案的候选人。我们的文化建立在迭代之上,利用 AI 今天更快交付,以便明天做得更好,同时确保每一项改进,无论多么微小,都会在团队中共享,以提升每个人。如果你是那种重视好奇心而非官僚作风,并且认为 AI 是解决棘手问题、推动互联网前进的伙伴的人,你会非常适合这里。
可选工作地点:德克萨斯州奥斯汀,混合办公
关于部门 身份与访问管理(IAM)团队致力于确保跨内部系统、应用程序和数据的用户身份、访问权限和身份验证机制得到安全高效的管理。我们的使命是保护组织免受未经授权的访问,保护敏感信息,并在遵守行业最佳实践和合规标准的同时,实现无缝的用户体验。
关于该职位
作为一名身份与访问管理(IAM)安全工程师,你将在为 Cloudflare 内部员工和工作负载设计、实施和扩展身份与访问管理解决方案方面发挥关键作用。你将负责通过确保安全的用户访问、身份验证和授权机制,保护我们的系统、应用程序和数据。
你将做什么
• 在身份验证、授权和审计方面设计、构建、测试和部署 IAM 解决方案
• 利用 Cloudflare 产品保护我们的身份
• 利用 SAML、OIDC、OAuth 和 SCIM 构建 SSO 集成
• 构建和管理身份治理与管理平台
• 利用 RBAC 和 ABAC 开发自动化角色
• 构建和管理访问认证平台
• 构建和管理特权访问管理(PAM)平台
• 为 IAM 系统提供运营支持,包括可能涉及非工作时间电话的待命轮值
岗位职责
作为一名身份与访问管理(IAM)安全工程师,你将在为 Cloudflare 内部员工和工作负载设计、实施和扩展身份与访问管理解决方案方面发挥关键作用。你将负责通过确保安全的用户访问、身份验证和授权机制,保护我们的系统、应用程序和数据。
• 在身份验证、授权和审计方面设计、构建、测试和部署 IAM 解决方案
• 利用 Cloudflare 产品保护我们的身份
• 利用 SAML、OIDC、OAuth 和 SCIM 构建 SSO 集成
• 构建和管理身份治理与管理平台
• 利用 RBAC 和 ABAC 开发自动化角色
• 构建和管理访问认证平台
• 构建和管理特权访问管理(PAM)平台
• 为 IAM 系统提供运营支持,包括可能涉及非工作时间电话的待命轮值
理想技能、知识和经验
安全工程师会参与团队中各种各样的任务和项目。不期望一个人了解所有内容,但需要具备以下几个领域的实用知识:
• 对身份联合(SAML、OAuth、OpenID Connect 等)有深入理解
• 具备实施身份治理与管理(IGA)解决方案的经验,包括生命周期管理、SCIM、默认访问权限(RBAC、ABAC)和访问认证
• 已证明具备构建生产级自动化脚本和工具的能力。必须具备利用 AI/LLM 解决运营或技术挑战的动手工程经验。
• 具备容器化应用平台(例如 Kubernetes)的安全配置经验
• 高级脚本编写经验(Python、TypeScript、Bash 等)
任职要求
• 具备使用基础设施即代码和配置管理工具(如 Terraform、Ansible 等)的经验
Cloudflare 有何特别之处?
我们不仅仅是一家雄心勃勃的大型科技公司。我们是一家有灵魂的雄心勃勃的大型科技公司。我们帮助构建更好的互联网这一使命的根本,是保护自由开放的互联网。
Project Galileo :自 2014 年以来,我们已为 111 个国家的 2,400 多个新闻和公民社会组织提供了强大的工具,使其能够抵御原本会审查其工作的攻击,这些技术已被 Cloudflare 的企业客户使用——而且是免费的。
Athenian Project :2017 年,我们创建了 Athenian Project,以确保州和地方政府免费获得最高级别的保护和可靠性,使其选民能够获取选举信息和选民登记。自该项目启动以来,我们已为 33 个州的 425 多个地方政府选举网站提供服务。
1.1.1.1 :我们发布了 1.1.1.1,通过构建更快、更安全且以隐私为中心的公共 DNS 解析器,帮助修复互联网的基础。这公开供所有人使用——这是 Cloudflare 有史以来发布的第一个面向消费者的服务。事情是这样的——我们永远不会存储客户端 IP 地址。我们将继续遵守我们的隐私承诺,并确保不会将任何用户数据出售给广告商或用于定向消费者。
听起来像是你想参与的事情?我们很乐意听到你的消息!
请注意,进入面试流程录用阶段的申请人可能会被要求前往 Cloudflare 办公室或 Cloudflare Hub 之一参加现场面试。有关此事的更多细节将在面试流程的该阶段提供。
该职位可能需要访问受美国出口管制法律(包括美国出口管理条例)保护的信息。请注意,任何录用通知都可能以你能够在无需申请出口许可证担保的情况下接收受这些美国出口法律管制的软件或技术为条件。
Cloudflare 自豪地成为提供平等机会的雇主。我们致力于为所有人提供平等的就业机会,并高度重视多样性和包容性。所有合格申请人都会获得就业考虑,不因其或任何其他人的实际或被认为的种族、肤色、宗教、性别、性别认同、性别表达、性取向、国籍、血统、公民身份、年龄、身体或精神残疾、医疗状况、家庭照护状况或任何其他受法律保护的基础而受到歧视。我们是 AA/退伍军人/残障人士雇主。
Cloudflare 为符合条件的残障人士提供合理便利。如果你在申请工作时需要合理便利,请告诉我们。合理便利的示例包括但不限于更改申请流程、以替代格式提供文件、使用手语翻译或使用专业设备。如果你在申请工作时需要合理便利,请通过电子邮件 hr@cloudflare.com 联系我们,或通过邮寄地址 101 Townsend St. San Francisco, CA 94107 联系我们。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
About Us
At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.
At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.
Available Locations: Hybrid from Austin, TX
About the Department The Identity and Access Management (IAM) team is dedicated to ensuring the secure and efficient management of user identities, access privileges, and authentication mechanisms across internal systems, applications, and data. Our mission is to safeguard the organization against unauthorized access, protect sensitive information, and enable seamless user experiences while adhering to industry best practices and compliance standards.
About the Role
As an Identity and Access Management (IAM) Security Engineer, you will play a crucial role in designing, implementing, and scaling identity and access management solutions for Cloudflare’s internal workforce and workloads. You will be responsible for safeguarding our systems, applications, and data by ensuring secure user access, authentication, and authorization mechanisms.
What You’ll Do
• Design, build, test, and deploy IAM solutions across authentication, authorization, and accounting
• Leverage Cloudflare products to secure our identities
• Build SSO integrations leveraging SAML, OIDC, OAuth, and SCIM
• Build and manage the Identity Governance and Administration platform
• Develop automated roles leveraging RBAC and ABAC
• Build and manage an access certification platform
• Build and manage a Privileged Access Management (PAM) platform
• Provide operational support of IAM systems including an on-call rotation that may i
岗位职责
As an Identity and Access Management (IAM) Security Engineer, you will play a crucial role in designing, implementing, and scaling identity and access management solutions for Cloudflare’s internal workforce and workloads. You will be responsible for safeguarding our systems, applications, and data by ensuring secure user access, authentication, and authorization mechanisms.
• Design, build, test, and deploy IAM solutions across authentication, authorization, and accounting
• Leverage Cloudflare products to secure our identities
• Build SSO integrations leveraging SAML, OIDC, OAuth, and SCIM
• Build and manage the Identity Governance and Administration platform
• Develop automated roles leveraging RBAC and ABAC
• Build and manage an access certification platform
• Build and manage a Privileged Access Management (PAM) platform
• Provide operational support of IAM systems including an on-call rotation that may include after hours calls
Desirable skills, knowledge and experience
Security engineers take part in a wide variety of tasks and projects in the team. One individual is not expected to know everything, but a working knowledge in several of the following areas is required:
• Strong understanding of identity federation (SAML, OAuth, OpenID Connect, etc.)
• Experience implementing Identity Governance and Administration (IGA) solutions including lifecycle management, SCIM, birthright access (RBAC, ABAC), and access certifications
• Demonstrated ability to build production-grade automation scripts and tools. Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
• Experience with secure configuration of containerized application platforms (e.g. Kubernetes)
• Advanced scripting experience (Python, TypeScript, Bash, etc.)
任职要求
• Experience working with infrastructure as code and configuration management tools like Terraform, Ansible, etc.
What Makes Cloudflare Special?
We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.
Project Galileo : Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.
Athenian Project : In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.
1.1.1.1 : We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.
Sound like something you’d like to be a part of? We’d love to hear from you!
Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process.
This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.
Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.