← Back to results

IT Security & Identity Engineer

Own identity, access, and endpoint security for Neuralink's corporate environment as an IT Security & Identity Engineer.

Location
Austin, Texas, United States
Compensation
$99k–$185k/yr
Level
mid
Type
full time

Posted by employer 4 days ago

First seen on Joblaze 3 days ago

Last verified on the company career page 1 day ago

Apply at Neuralink → Save job Scanned from neuralink.com

What you'll build

  • Design, deploy, and operate identity and access management
  • Manage identity infrastructure and access policy as code
  • Drive identity lifecycle automation
  • Design and operate strong authentication
  • Run enterprise vulnerability management

Must have

  • 5+ years of hands-on experience securing corporate IT environments
  • Demonstrated experience administering an enterprise IdP
  • Strong working knowledge of IAM protocols and standards
  • Hands-on experience managing infrastructure with Terraform
  • Scripting proficiency in Python, Bash, or PowerShell

Nice to have

  • Experience implementing phishing-resistant MFA at scale
  • Certificate-based authentication and PKI operations
  • Zero-trust architecture experience
  • Detection engineering experience
  • Hardening Windows, macOS, and Linux endpoints

Requirements

Experience
5+ years
Education
Bachelor's degree

Not disclosed in this posting: work arrangement, visa sponsorship.

Benefits

401k Match Equity/Stock Options Flexible Time Off Health Insurance Parental Leave

Joblaze summary

The IT Security & Identity Engineer at Neuralink is responsible for managing identity, access, and endpoint security within the corporate environment, ensuring that systems are both secure and user-friendly. This role requires expertise in identity management protocols, strong authentication methods, and endpoint protection, utilizing tools like Terraform and GitLab for infrastructure as code. Ideal candidates have significant experience in enterprise IT security and can effectively communicate complex security concepts to both technical and non-technical staff. Neuralink's IT team emphasizes a collaborative approach to security, supporting a fast-paced environment focused on innovative tech

Joblaze insights

  • Listed 3 days ago — first seen on Joblaze September 27, 2026. Last confirmed on Neuralink's careers page September 29, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts at or below all 53 comparable mid security roles in United States that list Python we track (median $130,000 across 22 companies). See Python salary trends
  • Python appears in 44.1% of 195 comparable mid security roles in United States; GitLab appears in 0.5% of 195 comparable mid security roles in United States.

Quick facts

What's the salary range?
Neuralink lists $99,000–$185,000 for this role.
How much experience is required?
At least 5 years of relevant experience for this IT Security & Identity Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: EDR, GitLab, Google Workspace, Microsoft Entra, OAuth 2.0, OIDC.
What seniority level is this role?
Neuralink targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this IT Security & Identity Engineer role at Neuralink.

From the original posting

About Neuralink:

Team Description:

Neuralink's Information Technology team owns the corporate environment that every engineer, scientist, and clinician depends on to do their work. Within IT, the Security & Identity function is responsible for who can access what, from which device, under what conditions. That means running the identity provider and SSO federation, enforcing strong authentication and device trust, securing endpoints across macOS, Windows, and Linux, centralizing logs and detections, and producing the audit evidence that supports HIPAA and SOC 2. We manage this environment as code in Terraform and GitLab, and we hold a high bar for making access both secure and low-friction for a fast-moving company.

Job Description and Responsibilities:

Neuralink is looking for a hands-on IT Security & Identity Engineer to own identity, access, and endpoint security for our corporate environment. You will be the technical owner of our identity provider, SSO federation, and lifecycle automation, and you will drive endpoint protection, detection, and vulnerability management alongside the rest of the IT team. This is a build-and-operate role: you will design controls, implement them in Terraform through GitLab, and then run them in production, including on-call. The ideal candidate has strong opinions grounded in experience, takes full ownership of the systems they build, makes practical risk decisions without slowing the company down, and can explain security tradeoffs clearly to engineers and non-technical staff alike. The job responsibilities will include:

  • Design, deploy, and operate identity and access management across Google Workspace, Microsoft Entra, and integrated SaaS applications; own SSO federation (SAML, OIDC, OAuth 2.0) and SCIM provisioning for business-critical tools.
  • Manage identity infrastructure and access policy as code using Terraform and GitLab CI/CD; treat the IdP, group membership, application assignments, and conditional access as versioned, reviewable state.
  • Drive identity lifecycle automation from onboarding through offboarding, including role-based access control (RBAC), attribute-driven group membership, just-in-time access, and reduction of standing privilege.
  • Design and operate strong authentication: phishing-resistant MFA (FIDO2/WebAuthn, passkeys, hardware tokens), certificate-based authentication (X.509, 802.1x), and device-trust conditions tied to MDM compliance.
  • Own endpoint security posture across macOS, Windows, and Linux alongside the IT team: EDR policy and operations, disk encryption, secure baselines, and compliance enforcement through MDM (Intune, Jamf, or similar).
  • Build and maintain security logging and detection for corporate IT: centralize identity, endpoint, SaaS, and network logs (Grafana/Loki, Prometheus, or a SIEM), write detections for identity abuse and endpoint compromise, and tune alerting.
  • Run enterprise vulnerability management: scanning, prioritization, remediation workflows with system owners, and evidence of closure.
  • Harden traditional IT services used by engineering, science, and clinical staff (email, file shares, directory services, collaboration tools, internal applications); review and improve permissions, group membership, and access models.
  • Partner with systems, network, and application owners to securely design and operate services on the Tailscale and FortiGate-based network: authentication and authorization, logging, patching, and least privilege.
  • Lead or support detection, triage, and incident response for the corporate IT environment; participate in the IT on-call rotation.
  • Conduct regular access reviews and audits; produce evidence supporting HIPAA, PII handling, and SOC 2 or comparable frameworks in partnership with Compliance.
  • Drive scripting and automation (Python, Bash, PowerShell) for repeatable security tasks: baselines, evidence collection, health checks, and remediation.
  • Recommend, justify, and implement improvements through an accepted change control process; define, document, and follow standards for design, testing, and implementation.
  • Serve as the IAM and security subject matter expert for the IT team, providing technical guidance and mentoring teammates.

Required Qualifications:

  • Bachelor's degree in computer science, cybersecurity, or another STEM discipline, or 5+ years of professional experience in enterprise IT security engineering in lieu of a degree.
  • 5+ years of hands-on experience securing corporate IT environments (identity/MFA, endpoint security, logging and detection, vulnerability management, email or file services).
  • Demonstrated experience administering an enterprise IdP (Google Workspace, Microsoft Entra, or Okta) including SSO federation, SCIM provisioning, MFA enforcement, conditional access, and full user lifecycle management.
  • Strong working knowledge of IAM protocols and standards: SAML, OIDC, OAuth 2.0, SCIM.
  • Hands-on experience managing infrastructure or identity configuration with Terraform and Git-based workflows.
  • Experience administering or operating at least two of the following: enterprise EDR/AV, centralized logging or SIEM, enterprise vulnerability management platform, enterprise MDM.
  • Scripting proficiency in Python, Bash, or PowerShell for security automation and integrations.
  • Excellent communication skills with IT engineers and a diverse user base including non-technical scientists and clinicians; able to explain security tradeoffs and risk decisions clearly.

Preferred Qualifications:

  • Experience implementing phishing-resistant MFA at scale: FIDO2/WebAuthn, passkeys, hardware tokens, smart cards.
  • Certificate-based authentication and PKI operations: TLS, X.509, 802.1x, internal CA management.
  • Zero-trust architecture experience, including device trust, Tailscale or comparable mesh VPN, and identity-aware access.
  • Detection engineering experience: writing and tuning detections in Grafana/Loki, a SIEM, or comparable tooling.
  • Hardening Windows, macOS, and Linux endpoints and servers; securing file shares, email gateways, and internal applications.
  • Privileged access management, just-in-time access, and privilege-escalation reduction.
  • SOC or blue-team incident response experience on enterprise IT estates.
  • Configuration management with Ansible or similar; GitLab CI/CD pipelines.
  • Familiarity with NIST 800-53, CIS Controls, or ISO 27001 control families as implemented by IT security engineering.
  • Experience in regulated environments (HIPAA, SOC 2, or similar).

Compliance & Data Privacy:

Neuralink handles sensitive patient health information and personally identifiable information (PII). All employees are expected to understand and comply with HIPAA regulations and Neuralink’s data privacy policies. This role may involve access to protected health information (PHI) and requires a demonstrated commitment to confidentiality, data security, and responsible handling of sensitive information.

Expected Compensation:

Base Salary Range:
$99,000—$185,000 USD

What We Offer:

Standard company text repeated across Neuralink's postings is omitted here.

Similar positions

Northwood Space
Identity & Endpoint Security Engineer
Northwood Space · Torrance, CA
Northwood Space
Corporate IT Security Engineer
Northwood Space · Torrance, CA
Horizon3.ai
Senior IT Systems Engineer
Horizon3.ai · United States
Okta
Manager, Engineering, SecureAI
Okta · Toronto, Ontario, Canada
Verkada
Senior+ IAM Engineer
Verkada · San Mateo, CA United States