Iam Engineer Jobs in California
Iam Engineer jobs in California are among the most active in the country, concentrated in enterprise technology, financial services, healthcare IT, and defense contracting, with openings at every level from junior analyst through principal architect. The largest hiring centers are the San Francisco Bay Area, Los Angeles, and San Diego, where established employers such as Salesforce, Kaiser Permanente, and Northrop Grumman maintain significant IAM programs. The most in-demand specialties are identity governance and administration, privileged access management, and cloud identity platforms such as Okta, SailPoint, and Azure Active Directory. Find a role that fits below and apply directly.
Find Iam Engineer JobsOverview
Showing 5 of 15+ Iam Engineer jobs











Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.
At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there.
A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.
As a Principal Security Software Engineer on the Production IAM team, you will set the technical direction for how identity and access work across Roblox's production infrastructure, from the mTLS-based identity that services use to authenticate to one another, to the privileged access controls that govern how engineers reach production. The team is accountable for Roblox's machine and workload identity platform, its centralized authorization engine, its production access management platform, production PKI and certificate lifecycle, and just-in-time privileged access for engineers. As an individual contributor in Production IAM, you will define multi-year strategy, drive alignment across Roblox Platform, mentor senior and staff engineers, and personally build the hardest parts of these systems. As AI agents become first-class actors in production, you will also help pioneer how they get identity, prove who they are, and receive safely-scoped access.
You will
- Lead the architecture for production identity and access. Define and evolve the end-to-end design for machine, workload, human, and AI-agent identity across our hybrid on-prem and cloud fleet, making secure access invisible when it can be and intuitive when it needs attention.
- Drive mTLS and workload identity to full production enforcement. Lead the technical strategy for our SPIFFE/SPIRE-based identity platform, service-mesh integration, managed service accounts, and certificate issuance, storage, and rotation.
- Advance just-in-time, least-privilege access for engineers. Architect just-in-time, least-privilege, and break-glass access to production, replacing static, long-lived credentials with short-lived, auditable access that stays reliable even during dependency or identity-provider outages.
- Evolve the centralized authorization engine and a secure golden path. Mature our centralized authorization engine and the access-control models behind it (RBAC/ABAC and risk-based access) so decisions are consistent, fine-grained, and testable.
- Pioneer identity and access for AI agents. Define how agents obtain credentials, receive scoped permissions, and have their sessions managed across their lifecycle, setting the patterns for agentic identity at Roblox..
- Lead across the org and raise the bar. Author RFCs and multi-year roadmaps, align stakeholders across Roblox Platform, mentor senior and staff engineers, and raise the technical bar through design review, on-call ownership, and hiring.
You have
- 8+ years of relevant professional experience building scalable, distributed backend systems, with a track record of driving architecture end to end.
- Deep expertise in identity and access management — authentication, authorization, and access-control models such as RBAC, ABAC, or risk-based access control.
- Hands-on experience with several of: PKI and certificate/key lifecycle management, mTLS, SPIFFE/SPIRE or comparable workload-identity systems, service mesh, secret management (e.g., Vault), and privileged access management (PAM).
- Proficiency in at least one systems language such as Go, Rust, Java, C++, Python, or C# .NET, and a habit of building systems rather than only configuring vendor tools.
- Experience leading the technical work of other engineers — setting direction across teams, writing influential design docs, and mentoring senior talent.
- AI fluency: you use AI tools in your daily workflow, understand LLM capabilities and limitations, and can reason about what it means to give an AI agent an identity and permissions.
- A Bachelor's degree or equivalent experience in Computer Science, Computer Engineering, or a similar technical field.
You are
- A systems thinker. You reason about failure modes, blast radius, and reliability, and you design access that stays secure and available even when dependencies fail.
- Security-minded and pragmatic. You are passionate about least privilege and zero trust, but you optimize for the Builder experience and adoption, not controls for their own sake.
- A force multiplier. You make the engineers and teams around you better through mentorship, clear writing, and high-quality technical leadership.
- A strong communicator. You translate deep technical tradeoffs for both engineers and executives, and you build alignment across organizational boundaries.
- Bar-raising and hands-on. You still love to build, and you set the standard for engineering quality on the hardest problems.
For roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location, business needs and market demand. Therefore, in some circumstances, the actual salary could fall outside of this expected range. This pay range is subject to change and may be modified in the future. All full-time employees are also eligible for equity compensation and for benefits as described on this page.
Roles that are based in an office are onsite Tuesday, Wednesday, and Thursday, with optional presence on Monday and Friday (unless otherwise noted).
Roblox provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Roblox also provides reasonable accommodations to candidates with qualifying disabilities or religious beliefs during the recruiting process.
For US based roles only, please note the Company may not be able to employ candidates for this role who have United States work authorization related to certain U.S. visa categories, or support future H-1B sponsorship at this time.
See All 15 Iam Engineer Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Iam Engineer JobsIam Engineer Jobs by City in California
Where California roles are concentrated, by current openings.
Iam Engineer Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
What California Employers Look For
The qualifications that appear most often in iam engineer jobs across California.
- Hands-on experience with enterprise IAM platforms such as Okta, SailPoint, or Azure AD
- Strong understanding of identity governance, access certification, and role-based access control
- Experience integrating IAM solutions with cloud environments including AWS, Azure, or Google Cloud
- Familiarity with PAM tools such as CyberArk or BeyondTrust in large enterprise environments
- Knowledge of relevant compliance frameworks including SOX, HIPAA, and CCPA as applied in California
- Bachelor's degree in computer science, information security, or a closely related technical field
Iam Engineer Jobs in California: Frequently Asked Questions
How do you become a iam engineer in California?
Most iam engineer roles in California are reached through a combination of a bachelor's degree in computer science, information systems, or cybersecurity and hands-on experience with enterprise identity platforms. There is no California state license required, but industry certifications such as the Certified Identity and Access Manager credential and vendor-specific certifications from Okta, SailPoint, or Microsoft strengthen applications considerably. Many California employers, particularly in financial services and healthcare, also value experience with CCPA compliance as part of an IAM background.
Which companies hire iam engineers in California?
Employers hiring iam engineers in California right now include CRUSOE, Roblox, and Rubrik, based on current listings on Migrate Mate as of August 2026. California's concentration of large technology firms, health systems, and defense contractors means IAM roles appear across a particularly wide range of industries compared to most other states.
Which California cities have the most iam engineer jobs?
The cities with the most iam engineer openings in California are San Francisco, Palo Alto, and San Mateo. The Bay Area leads because it is home to the headquarters and major engineering campuses of some of the largest enterprise software and cloud companies in the world, while Los Angeles and San Diego draw demand from healthcare networks, financial institutions, and defense contractors with significant IAM infrastructure needs.
Are there remote iam engineer jobs in California?
Yes, and more than most fields, because iam engineering is largely configuration, integration, and policy work that can be performed entirely over secure remote access. About 67% of iam engineer openings tied to California are remote or hybrid as of August 2026, reflecting strong adoption across the technology and financial services sectors. Identity governance, access certification reviews, and cloud identity platform work are the sub-areas most commonly offered on a fully remote basis.
How can I get hired as a iam engineer in California with little or no experience?
The most realistic entry path is a help desk or IT support role at a large California employer, which provides direct exposure to Active Directory, user provisioning, and access request workflows that form the foundation of IAM work. University of California and California State University graduates often find associate identity analyst or IT security analyst roles at health systems such as Sutter Health or financial institutions such as Wells Fargo that serve as structured entry points. Completing a vendor-specific Okta or Microsoft certification and building a lab environment demonstrating SailPoint or Azure AD configuration gives candidates without enterprise experience a concrete portfolio to show.
Where can I find and apply to iam engineer jobs in California?
You can find and apply to iam engineer jobs in California on Migrate Mate, which lists current California openings across industries and experience levels. Find roles that fit your background and apply directly to the employers posting them.
See All 15 Iam Engineer Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Iam Engineer Jobs