Staff Security Risk & Compliance Program Manager - Access Management
ConfluentData Streaming company
United StatesLead
Benchmark
Index Ventures
Sequoia Capital
Coatue
Altimeter Capital
Franklin Templeton Investments
Legal & Compliance
About the role
TL;DR
Leads Confluent's internal access management program and machine and workload identity evolution.
- •We are seeking a highly motivated and experienced Staff Security Risk & Compliance Program Manager
- •Access Management to join our Trust & Security team.
- •This senior role owns Confluent's internal access management program and leads its evolution toward machine and workload identity.
- •Key Responsibilities Own the strategic direction and roadmap for Confluent's internal access management program.
- •Lead the program to enforce service-to-service authentication across Trust & Security-owned surfaces.
- •Formalize non-human identity from pilot into a funded, governed program.
- •Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access.
- •Own access metrics and reporting (e.g., JIT/unilateral-access volume, broad-privilege usage, prod-access reduction).
- •Requirements 8+ years in security program management, identity & access management, or a closely related security discipline, with at least 3 years running an enterprise
- •or platform-scale access program in a technology company.
- •Deep expertise in identity and access management concepts: least privilege, separation of duties, RBAC/ABAC, just-in-time (JIT) and privileged access management (PAM), and access review/certification.
- •Working knowledge of machine and workload identity
- •service-to-service authentication, non-human identity, service accounts, secrets/key management, and emerging AI-agent access patterns.
- •Strong security engineering fundamentals across cloud infrastructure security controls in GCP, AWS, and/or Azure, including Kubernetes and cloud control-plane access models.
Required skills
Kubernetes
Domain expertise
cybersecurity
Tech stack
Kubernetes