远程工作雷达

资深安全风险与合规项目经理 - 访问管理

Staff Security Risk & Compliance Program Manager - Access Management

开发工程限定地区(需当地身份)
公司Confluent
薪资$222,100 - $261,000
工作地点Remote, United States / Remote, Texas
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型FullTime
发布时间2026-07-10
数据来源Ashby
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Remote, United States、Remote, Texas 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

我们不仅仅在打造更先进的技术。我们在重新定义数据的流动方式,以及世界能通过它实现什么。在 Confluent,数据不会静止不动。我们的平台让信息实时流动,使企业能够更快响应、更智能地构建,并提供与周围世界一样动态的体验。

需要某种特定类型的人加入这个团队。那些提出难题、给予诚实反馈并互相支持的人。没有自大,没有单打独斗。只有聪明、好奇的人们一起朝着更大的目标前进。

一个 Confluent。一个团队。一个数据流平台。

职位简介:

我们正在寻找一位高度积极且经验丰富的高级安全风险与合规项目经理 - 访问管理,加入我们的信任与安全团队。这个高级职位负责 Confluent 内部访问管理计划,并领导其向机器和工作负载身份——服务间(S2S)认证、非人类身份(NHI)以及 AI 代理的访问控制——演进,作为 Confluent Cloud 平台最小权限安全的下一个前沿领域。

你将作为横向负责人,管理 Confluent 如何治理访问:访问管理标准、访问指标和高管报告频率。由于访问操作分布在多个合作职能中,你将负责政策、风险和度量,以确保 Confluent 保持统一的访问姿态,而不是碎片化的孤岛。

你将负责:

- 战略与领导力:负责 Confluent 内部访问管理计划的战略方向和路线图,以机器和工作负载身份为核心。推动该计划从控制建设向持续治理和最小权限结果演进。

- 机器与工作负载身份:领导该计划,在信任与安全团队负责的范围内强制执行服务间(S2S)认证,接管身份工程团队的执行交接。将非人类身份(NHI)——服务账户、密钥和工作负载凭证——从试点阶段正式转化为有资金支持、受监管的计划。为 AI 代理建立访问控制,当这些代理工作负载获得生产访问时。

- 访问治理与标准:负责访问管理标准及实施最小权限、职责分离和定期访问审查的政策,覆盖人类和机器访问。确保标准与不断变化的访问范围同步,并保持可审计性

查看英文原文

We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them.

It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together.

One Confluent. One Team. One Data Streaming Platform.

ABOUT THE ROLE:

We are seeking a highly motivated and experienced Staff Security Risk & Compliance Program Manager - Access Management to join our Trust & Security team. This senior role owns Confluent's internal access management program and leads its evolution toward machine and workload identity — service-to-service (S2S) authentication, non-human identity (NHI), and access controls for AI agents — as the next frontier of least-privilege security for the Confluent Cloud platform.

You will be the horizontal owner of how Confluent governs access: the Access Management Standard, access metrics, and the executive reporting cadence. As access operations are distributed across partner functions, you will hold the policy, risk, and measurement line so Confluent maintains one coherent access posture rather than fragmented silos.

WHAT YOU WILL DO:

- Strategy and Leadership: Own the strategic direction and roadmap for Confluent's internal access management program, with machine and workload identity as the durable center of gravity. Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes.

- Machine & Workload Identity: Lead the program to enforce service-to-service (S2S) authentication across Trust & Security-owned surfaces, taking ownership of the enforcement hand-off from the identity engineering team. Formalize non-human identity (NHI) — service accounts, keys, and workload credentials — from pilot into a funded, governed program. Stand up access controls for AI agents as agentic workloads acquire production access.

- Access Governance & Standards: Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access. Ensure the standard keeps pace with the evolving access surface and remains audit-ready.

- Metrics, Reporting & Governance Cadence: Own access metrics and reporting (e.g., JIT/unilateral-access volume, broad-privilege usage, prod-access reduction). Define and track program OKRs and run the monthly execution and executive-review cadence, articulating risk posture and progress to senior leadership.

- Cross-Functional Execution & Transitions: Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.

- Integration with GRC and Partner Functions: Ensure the access management program is tightly integrated with adjacent GRC domains and partner teams (Insider Threat, IT/Identity, Detection & Response, and engineering owners), with clear RACI across governance and operations.

WHAT YOU WILL BRING:

- Experience: 8+ years in security program management, identity & access management, or a closely related security discipline, with at least 3 years running an enterprise- or platform-scale access program in a technology company.

- Technical Skills:

- Deep expertise in identity and access management concepts: least privilege, separation of duties, RBAC/ABAC, just-in-time (JIT) and privileged access management (PAM), and access review/certification.

- Working knowledge of machine and workload identity — service-to-service authentication, non-human identity, service accounts, secrets/key management, and emerging AI-agent access patterns.

- Strong security engineering fundamentals across cloud infrastructure security controls in GCP, AWS, and/or Azure, including Kubernetes and cloud control-plane access models.

- Familiarity with identity platforms and access tooling (e.g., Okta, JIT/access-orchestration tooling) and how access controls are enforced in production.

- Tooling and Automation: Experience integrating access processes, controls, or findings into GRC and access-orchestration platforms, and a bias toward automating access decisions over manual operations.

- Program Management Skills:

- Strong project management and organizational skills.

- Exceptional analytical and problem-solving skills, with a data-driven approach to decision-making.

- Experience running long-term, complex security programs that deliver iterative, measurable risk reduction.

- Communication and Collaboration Skills:

- Excellent written and verbal communication, with the ability to influence and lead without direct authority across engineering and security teams.

- Ability to articulate complex technical concepts and program status to executive-level audiences and technical teams alike.

READY TO BUILD WHAT'S NEXT? LET’S GET IN MOTION.

COME AS YOU ARE

Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible.

We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law.

PRIVACY STATEMENT

Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization. By proceeding with this application, you understand that Confluent will share your personal information with other IBM affiliates involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross-border data transfer, are available here http://ibm.com/careers/us-en/privacy-policy/.

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级软件工程师 II

ConfluentBoston, Massachusetts / Chicago, Illinois $176,000 - $230,000FullTime2026-05-07
开发工程全球可投

资深软件工程师

ConfluentMountain View, California / New York, New $235,700 - $277,000FullTime2026-07-22
开发工程未标注地域

分布式系统软件工程师

ConfluentUnited States$197,400 - $271,200/年permanent2026-07-21
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位