Calling all originals: At Levi Strauss & Co., you can be yourself — and be part of something bigger. We’re a company of people who like to forge our own path and leave the world better than we found it. Who believe that what makes us different makes us stronger. So add your voice. Make an impact. Find your fit — and your future.
We are seeking a Senior Identity Security Engineer to help shape and evolve Levi Strauss & Co.'s Identity and Access Management ecosystem. Reporting to the Senior Manager, Perimeter Security, you'll work with modern identity technologies and partner across security, infrastructure, and business teams to deliver secure, scalable solutions across identity governance, privileged access, authentication, automation, and access management in a global hybrid environment. This is an opportunity to tackle complex challenges, influence the future of identity security at LS&Co., and make a meaningful impact across the enterprise.
You will combine advanced hands-on engineering capability with strong technical judgment and extensive collaboration across Security, Infrastructure, Cloud Engineering, HR, Internal Audit, application, and business teams. Responsibilities include translating approved security strategies, architecture principles, compliance requirements, and business needs into scalable technical solutions and measurable improvements in identity-related risk. You will independently lead assigned identity engineering initiatives, recommends technical improvements, and coordinates implementation across multiple teams.
About the Job
Lead the design, implementation, and continuous improvement of assigned IAM capabilities, including identity lifecycle, authentication, authorization, federation, privileged access, and governance controls.
Translate approved security strategies, architecture principles, control requirements, and business needs into scalable technical designs and implementation plans.
Lead the design, implementation, and continuous improvement of Microsoft identity services, including Microsoft Entra ID, MFA, passwordless authentication, Conditional Access, SSO, OATH, PIM, JIT access, Defender for Identity, and Microsoft Graph-based integrations.
Engineer Privileged Access Management capabilities for administrative users, vendors, service accounts, non-human identities, session controls, credential vaulting, privileged elevation, credential rotation, and privileged remote access use cases.
Lead Identity Governance and Administration engineering initiatives, including access certifications, birthright provisioning, role management, segregation of duties, lifecycle workflows, joiner/mover/leaver controls, and policy-based governance.
Partner with HR, application, infrastructure, cloud, audit, and security teams to improve authoritative identity data quality, attribute mapping, lifecycle triggers, provisioning, deprovisioning, and control effectiveness.
Lead technical discussions across security and technology teams, communicate solution options and tradeoffs, build stakeholder alignment, and coordinate implementation across affected teams.
Develop automation solutions using PowerShell, Python, Microsoft Graph, REST APIs, and platform connectors to improve identity operations, governance, reporting, and control evidence.
Integrate identity platforms with enterprise applications, cloud platforms, SaaS services, PAM tools, IGA systems, SIEM/SOAR tooling, endpoint platforms, and security operations processes.
Independently lead complex production troubleshooting, root-cause analysis, incident response support, and escalation resolution for identity-related issues across hybrid and cloud environments.
Establish technical metrics, service health indicators, control evidence, and operational reporting to demonstrate delivery outcomes, control effectiveness, operational maturity, and risk reduction for assigned capabilities and initiatives.
Provide technical guidance to engineers and analysts, review designs, maintain documentation, and promote secure, reusable engineering practices.
About You
You are curious, collaborative, and passionate about identity security. You enjoy solving complex challenges, improving how security services operate, and working with teams across the organization to deliver secure, reliable, and scalable solutions that support the business.
The ideal candidate will bring a combination of technical expertise, engineering leadership, and experience in the following areas:
8+ years of relevant experience in IAM, PAM, IGA, authentication, authorization, identity lifecycle management, or related cybersecurity engineering disciplines.
Advanced hands-on experience with Microsoft Entra ID, MFA, passwordless authentication, Conditional Access, SSO, PIM, JIT administration, Microsoft Defender for Identity, and Microsoft Graph.
Deep understanding of identity and access protocols including SAML, OIDC, OAuth, SCIM, Kerberos, LDAP, certificate-based authentication, and modern authentication flows.
Hands-on experience with enterprise PAM platforms such as Delinea, CyberArk, or comparable solutions, including privileged access and least-privilege controls.
Experience implementing or administering enterprise IGA solutions such as Saviynt, SailPoint, Microsoft Identity Governance, or comparable platforms.
Strong scripting and automation experience using PowerShell or Python, Microsoft Graph, REST APIs, and platform-native automation capabilities.
Demonstrated experience leading complex identity engineering initiatives across multiple technical teams and business functions.
Strong communication, stakeholder management, and technical leadership skills with accountability for delivering sustainable engineering outcomes.
We are an Equal Opportunity Employer committed to empowering individuals from all walks of life to achieve their professional goals with us, regardless of race, religion, gender, gender identity, pregnancy, disability, sexual orientation, age, national origin, citizenship status, or genetic information. We actively seek and encourage applications from diverse candidates, including those with disabilities, and offer accommodations throughout the selection process upon request.
To ensure that our products and culture continue to incorporate everyone's perspectives and experience, we never discriminate based on race, religion, national origin, gender identity or expression, sexual orientation, age, or marital, veteran, or disability status.
Mexico, D.F., Mexico
Full time