Senior Information Security Engineer
Job Description
Match Group is hiring a Senior Information Security Engineer (onsite) in New York, NY to drive a unified identity and access security strategy across a global portfolio.
Responsibilities
- Lead a comprehensive identity and access lifecycle strategy across the global portfolio
- Authentication (AuthN): enhance identity security by enforcing device trust, enabling post-auth detection, and supporting DPoP
- Authorization (AuthZ): apply least privilege and right-size entitlements to balance security with delivery velocity
- Non-Human & AI Agent Identity: modernize secure handling for NHIs such as OAuth tokens, service accounts, and API keys
- Establish security guardrails for emerging AI agents and MCP connections
- PAM & Just-in-Time (JIT) access: modernize privileged access and implement JIT models to reduce standing privileges and secure high-risk admin actions
- Own and harden Cloudflare ZTNA policies and support migration away from traditional network-based access patterns
- Integrate identity strategy with broader CorpSec efforts by incorporating device signals from Fleet/EDR, SaaS security, and vulnerability management into access controls for a unified security posture
- Reduce manual toil by engineering automated solutions using scripting, no-code tools, or AI to solve problems at scale
Requirements
- 7+ years in security engineering, IT engineering, or infrastructure, with meaningful depth in identity and access
- Strong hands-on experience with Okta, including policy design, device assurance, FastPass, device trust, and RBAC
- Experience with Cloudflare Zero Trust or a comparable platform
- Strong knowledge of SAML, OIDC, OAuth 2.0, and SCIM
- Experience with IGA solutions (e.g., Okta Identity Governance, SailPoint), including deep understanding of identity lifecycles and compliance requirements
- Experience securing non-human identities (service accounts, OAuth apps, tokens) and setting guardrails for AI agents
- Experience using Terraform or other IaC tools to manage infrastructure changes, with emphasis on GitOps fluency
- Practical approach to least privilege with the ability to right-size access without excessive friction to the business
- Experience building automation (e.g., Okta Workflows, Lambda, Windmill) using Python or similar, with judgment on when to automate versus avoid over-engineering
- Practical use of AI tooling in your own workflow
- Proven ability to influence cross-functional outcomes without formal authority
- Ability to proactively identify, scope, and drive complex problems to completion
Technologies
- Okta
- Cloudflare Zero Trust / Cloudflare ZTNA
- SAML, OIDC, OAuth 2.0, SCIM
- Okta Identity Governance, SailPoint
- Terraform, GitOps
- Okta Workflows, Lambda, Windmill
- Python
- Fleet/EDR
- DPoP, RBAC
- MCP
Nice to Have
- Endpoint management or EDR exposure (Jamf, CrowdStrike, or similar)
- Audit and compliance experience with access controls (SOX, PCI-DSS, ISO 27001)
- Experience working in global environments (EMEA/APAC)
Core Values
- Take the Lead: do not ghost work or each other
- Move Fast: bias for action and urgency
- Better Together: collaboration and connection
- Real Talk: direct communication with kindness and candor
- Safety First: integrity, transparency, and consistency
- Spark Fun: unlock creativity and innovation
Compensation: USD 180,000 - 200,000 per year
Location: New York, NY (onsite)