OPT Identity And Access Management Engineer Jobs
Identity and Access Management Engineer jobs are a strong fit for F-1 OPT students with backgrounds in cybersecurity, computer science, or information systems. Employers in this space routinely sponsor H-1B visas, and your 12-month OPT window, extendable to 36 months with a STEM extension, gives you real runway to secure long-term sponsorship.
Find OPT Identity And Access Management Engineer JobsOverview
Showing 5 of 16+ Identity And Access Management Engineer jobs










See all Identity And Access Management Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Identity And Access Management Engineer roles.
Get Access To All Jobs
INTRODUCTION
The mission of TikTok's Global Security Organization is to build and earn trust by reducing risk and securing our businesses and products. Also known as "GSO", this team is the foundation of our efforts to keep TikTok safe, secure, and operating at scale for over 1 billion people around the world. We work to ensure that the TikTok platform is safe and secure, that our users' experience and their data remain safe from external or internal threats, and that we comply with global regulations wherever TikTok operates. Trust is one of TikTok's biggest initiatives, and security is integral to our success. In whatever ways users interact with us — whether they're watching videos on their For You page, interacting with a Live video, or buying products on TikTok Shop — GSO protects their data and privacy, so they can have a secure and trustworthy experience.
The IAM Operation & Validation team is part of the Global Security Organization (GSO), focused on protecting the organization by ensuring that the right identities have the right access to the right resources under the right conditions. Our mission is to strengthen identity and access security through effective governance, reliable security operations, and independent control validation. We develop and evolve IAM governance frameworks and security controls, identify and assess identity and access risks, validate whether controls are designed and operating effectively, and drive remediation and continuous improvement across the organization. Our work spans the identity and access lifecycle and increasingly extends beyond traditional human identities to service accounts, machine and workload identities, and emerging agentic identities. We partner closely with engineering, security, privacy, compliance, and business teams to address complex IAM risks and build scalable, risk-based governance and assurance capabilities. Joining the IAM Operation & Validation team means working at the intersection of security, technology, governance, and risk. You will have the opportunity to solve complex identity security challenges in a large-scale global environment and help shape the next generation of IAM governance, validation, and security capabilities.
Responsibilities
- Define and continuously enhance enterprise IAM governance strategies and control frameworks, including least privilege, role and entitlement governance, segregation of duties (SoD), and risk-based access controls, to strengthen the organization's overall identity and access security posture.
- Establish and evolve governance policies, standards, processes, and control requirements across the identity and access lifecycle, including identity onboarding, access request and provisioning, modification, periodic review, revocation, and auditability.
- Drive IAM governance initiatives across relevant stakeholders, establishing clear control ownership and accountability, identifying governance and control gaps, and partnering with technology, security, privacy, compliance, and business teams to drive remediation and sustainable improvements.
- Leverage identity, access, and authorization data to identify excessive privileges, dormant access, toxic combinations, policy violations, and other access risks; assess their impact and drive risk-based remediation with relevant stakeholders.
- Define and operate IAM governance measurement and monitoring frameworks, including governance metrics, key risk indicators, control effectiveness measures, and compliance baselines, to provide visibility into IAM risk and drive continuous improvement.
- Support the evolution of IAM governance across human and non-human identities, including service, system, and emerging agentic identities, helping establish appropriate governance principles and controls as the organization's identity landscape evolves.
MINIMUM QUALIFICATIONS
- Strong knowledge of Identity and Access Management (IAM) concepts and practices, including identity lifecycle management, authentication, authorization, access control, and access governance.
- Solid understanding of IAM governance principles and controls, including least privilege, role and entitlement governance, segregation of duties (SoD), access reviews, and access lifecycle controls.
- Experience developing, implementing, or assessing IAM policies, standards, governance processes, or control frameworks in complex enterprise environments.
- Strong analytical and problem-solving skills, with the ability to identify identity and access risks, assess control gaps, and drive risk-based remediation.
- Strong cross-functional collaboration and communication skills, with the ability to work with technical and non-technical stakeholders to drive governance initiatives and control improvements.
PREFERRED QUALIFICATIONS
- Bachelor’s degree or higher in Computer Science, Information Security, Information Systems, Engineering, or a related field, or equivalent practical experience.
- 3+ years of relevant experience in IAM, cybersecurity, security governance, technology risk, or related fields, with experience in IAM governance or access governance preferred.
- Experience independently owning IAM governance initiatives or workstreams and driving them from problem identification through remediation and closure.
- Experience designing or operating enterprise-scale IAM governance programs, such as access reviews, entitlement governance, segregation of duties (SoD), privileged access governance, or identity lifecycle governance.
- Experience with enterprise IAM/IGA platforms and technologies such as SailPoint, Saviynt, Tuebora, Okta, Microsoft Entra ID, or comparable solutions.
- Experience working with security or compliance frameworks such as NIST, ISO 27001, SOC 2, SOX, PCI DSS, or similar control environments.
- Experience with governance of non-human identities, including service accounts, machine identities, workload identities, API credentials, or emerging agentic identities.
ABOUT TIKTOK
TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and we also have offices in New York City, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.
WHY JOIN US
Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy – a mission we work towards every day. We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.
DIVERSITY & INCLUSION
TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
TIKTOK ACCOMMODATION
TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://tinyurl.com/RA-request
JOB INFORMATION
【For Pay Transparency】Compensation Description (Annually) The base salary range for this position in the selected city is $134400 - $223200 annually. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units. Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).
The Company reserves the right to modify or change these benefits programs at any time, with or without notice.
For Los Angeles County (unincorporated) Candidates: Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Our company believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment:
1. Interacting and occasionally having unsupervised contact with internal/external clients and/or colleagues;
2. Appropriately handling and managing confidential information including proprietary and trade secret information and access to information technology systems; and
3. Exercising sound judgment.
See all OPT Identity And Access Management Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new OPT Identity And Access Management Engineer Jobs.
Get Access To All JobsTips for Finding OPT Sponsorship as an Identity And Access Management Engineer
Target employers with active IAM infrastructure
Large enterprises in finance, healthcare, and tech maintain dedicated IAM teams and are far more likely to sponsor work visas. Focus your search on companies with mature security programs rather than early-stage startups with limited HR infrastructure.
Apply for your STEM OPT extension early
If your degree is in computer science, cybersecurity, or a related STEM field, file your STEM extension at least 90 days before your initial OPT expires. This gives you 24 additional months of work authorization while pursuing H-1B sponsorship.
Get certified in IAM-relevant frameworks
Certifications like CompTIA Security+, CyberArk Defender, or Microsoft SC-300 signal hands-on competency to hiring managers. Employers sponsoring visas want low-risk hires, and verified credentials reduce perceived onboarding risk significantly.
Highlight experience with enterprise identity platforms
Hands-on experience with Okta, Azure Active Directory, SailPoint, or Ping Identity is what employers actually screen for. Document specific implementations, integrations, or access governance projects from coursework, internships, or personal lab environments.
Address OPT status directly in your cover letter
State your current OPT authorization, your STEM extension eligibility, and your expected H-1B sponsorship timeline. Employers unfamiliar with OPT often assume the process is more complex than it is, so clarity upfront reduces hesitation.
Use Migrate Mate to find sponsorship-open roles
Browse IAM Engineer roles on Migrate Mate, where listings are filtered for employers open to OPT and visa sponsorship. This removes the guesswork of identifying which companies will actually consider international candidates.
Identity And Access Management Engineer OPT: Frequently Asked Questions
Can I work as an Identity and Access Management Engineer on OPT?
Yes, provided your degree is in a qualifying field such as computer science, cybersecurity, information systems, or a related STEM discipline. IAM Engineer roles involve designing and managing authentication and authorization systems, which aligns directly with these degree fields. USCIS requires that your OPT employment be directly related to your major area of study.
Do Identity and Access Management Engineer roles commonly lead to H-1B sponsorship?
IAM engineering is classified as a specialty occupation under H-1B rules, meaning it qualifies for sponsorship without ambiguity. Employers in regulated industries like financial services, healthcare, and government contracting routinely sponsor H-1B visas for IAM roles because demand for qualified candidates significantly exceeds domestic supply. Your 36-month STEM OPT window gives you three H-1B lottery cycles to secure sponsorship.
What qualifies as related employment for an IAM Engineer on OPT?
Your OPT job must be directly related to your degree field. For IAM Engineer roles, this means work involving identity governance, access control systems, directory services, authentication protocols such as SAML or OAuth, or privileged access management. Roles that are primarily administrative or outside the technical scope of your degree would not qualify as valid OPT employment.
How do I find Identity and Access Management Engineer jobs that accept OPT candidates?
Migrate Mate filters job listings specifically for employers open to OPT and visa sponsorship, which makes it significantly more efficient than general job searches where sponsorship willingness is rarely disclosed upfront. Search for IAM Engineer roles on Migrate Mate and filter by work authorization type to surface opportunities where your OPT status is not a disqualifier.
What should I do if my OPT is expiring before I receive an H-1B sponsorship decision?
If you're STEM-eligible, file your 24-month STEM OPT extension before your initial 12-month period ends, which requires your employer to be enrolled in E-Verify. If an H-1B petition is filed on your behalf before your OPT expires, cap-gap protection extends your work authorization through September 30 of that fiscal year, even if your OPT document expires in the interim.