
IT Security & Identity Engineer
Austin, TX at a glance
- Rent
- #25 of 51$1,150/mo-15% vs US avg
- Weather
- #13 of 51154 mild days113 hot · 0 cold
- Income tax
- #51 of 51NoneTexas
What you need
- 5+ yrs enterprise IT security engineering
- Enterprise IdP admin (Google Workspace, Entra, Okta)
- IAM protocols: SAML, OIDC, OAuth 2.0, SCIM
- Terraform & GitLab CI/CD for identity as code
- Scripting in Python, Bash, or PowerShell
What you'll do
- Own identity, access, and endpoint security for corporate environment
- Manage IdP, SSO federation, and lifecycle automation as code
- Drive phishing-resistant MFA and device-trust conditions
- Build security logging, detection, and vulnerability management
- Lead incident response and participate in IT on-call rotation
About Neuralink:
We are creating devices that enable a bi-directional interface with the brain. These devices allow us to restore movement to the paralyzed, restore sight to the blind, and revolutionize how humans interact with their digital world.
Team Description:
Neuralink's Information Technology team owns the corporate environment that every engineer, scientist, and clinician depends on to do their work. Within IT, the Security & Identity function is responsible for who can access what, from which device, under what conditions. That means running the identity provider and SSO federation, enforcing strong authentication and device trust, securing endpoints across macOS, Windows, and Linux, centralizing logs and detections, and producing the audit evidence that supports HIPAA and SOC 2. We manage this environment as code in Terraform and GitLab, and we hold a high bar for making access both secure and low-friction for a fast-moving company.
Job Description and Responsibilities:
Neuralink is looking for a hands-on IT Security & Identity Engineer to own identity, access, and endpoint security for our corporate environment. You will be the technical owner of our identity provider, SSO federation, and lifecycle automation, and you will drive endpoint protection, detection, and vulnerability management alongside the rest of the IT team. This is a build-and-operate role: you will design controls, implement them in Terraform through GitLab, and then run them in production, including on-call. The ideal candidate has strong opinions grounded in experience, takes full ownership of the systems they build, makes practical risk decisions without slowing the company down, and can explain security tradeoffs clearly to engineers and non-technical staff alike. The job responsibilities will include:
- Design, deploy, and operate identity and access management across Google Workspace, Microsoft Entra, and integrated SaaS applications; own SSO federation (SAML, OIDC, OAuth 2.0) and SCIM provisioning for business-critical tools.
- Manage identity infrastructure and access policy as code using Terraform and GitLab CI/CD; treat the IdP, group membership, application assignments, and conditional access as versioned, reviewable state.
- Drive identity lifecycle automation from onboarding through offboarding, including role-based access control (RBAC), attribute-driven group membership, just-in-time access, and reduction of standing privilege.
- Design and operate strong authentication: phishing-resistant MFA (FIDO2/WebAuthn, passkeys, hardware tokens), certificate-based authentication (X.509, 802.1x), and device-trust conditions tied to MDM compliance.
- Own endpoint security posture across macOS, Windows, and Linux alongside the IT team: EDR policy and operations, disk encryption, secure baselines, and compliance enforcement through MDM (Intune, Jamf, or similar).
- Build and maintain security logging and detection for corporate IT: centralize identity, endpoint, SaaS, and network logs (Grafana/Loki, Prometheus, or a SIEM), write detections for identity abuse and endpoint compromise, and tune alerting.
- Run enterprise vulnerability management: scanning, prioritization, remediation workflows with system owners, and evidence of closure.
- Harden traditional IT services used by engineering, science, and clinical staff (email, file shares, directory services, collaboration tools, internal applications); review and improve permissions, group membership, and access models.
- Partner with systems, network, and application owners to securely design and operate services on the Tailscale and FortiGate-based network: authentication and authorization, logging, patching, and least privilege.
- Lead or support detection, triage, and incident response for the corporate IT environment; participate in the IT on-call rotation.
- Conduct regular access reviews and audits; produce evidence supporting HIPAA, PII handling, and SOC 2 or comparable frameworks in partnership with Compliance.
- Drive scripting and automation (Python, Bash, PowerShell) for repeatable security tasks: baselines, evidence collection, health checks, and remediation.
- Recommend, justify, and implement improvements through an accepted change control process; define, document, and follow standards for design, testing, and implementation.
- Serve as the IAM and security subject matter expert for the IT team, providing technical guidance and mentoring teammates.
Required Qualifications:
- Bachelor's degree in computer science, cybersecurity, or another STEM discipline, or 5+ years of professional experience in enterprise IT security engineering in lieu of a degree.
- 5+ years of hands-on experience securing corporate IT environments (identity/MFA, endpoint security, logging and detection, vulnerability management, email or file services).
- Demonstrated experience administering an enterprise IdP (Google Workspace, Microsoft Entra, or Okta) including SSO federation, SCIM provisioning, MFA enforcement, conditional access, and full user lifecycle management.
- Strong working knowledge of IAM protocols and standards: SAML, OIDC, OAuth 2.0, SCIM.
- Hands-on experience managing infrastructure or identity configuration with Terraform and Git-based workflows.
- Experience administering or operating at least two of the following: enterprise EDR/AV, centralized logging or SIEM, enterprise vulnerability management platform, enterprise MDM.
- Scripting proficiency in Python, Bash, or PowerShell for security automation and integrations.
- Excellent communication skills with IT engineers and a diverse user base including non-technical scientists and clinicians; able to explain security tradeoffs and risk decisions clearly.
Preferred Qualifications:
- Experience implementing phishing-resistant MFA at scale: FIDO2/WebAuthn, passkeys, hardware tokens, smart cards.
- Certificate-based authentication and PKI operations: TLS, X.509, 802.1x, internal CA management.
- Zero-trust architecture experience, including device trust, Tailscale or comparable mesh VPN, and identity-aware access.
- Detection engineering experience: writing and tuning detections in Grafana/Loki, a SIEM, or comparable tooling.
- Hardening Windows, macOS, and Linux endpoints and servers; securing file shares, email gateways, and internal applications.
- Privileged access management, just-in-time access, and privilege-escalation reduction.
- SOC or blue-team incident response experience on enterprise IT estates.
- Configuration management with Ansible or similar; GitLab CI/CD pipelines.
- Familiarity with NIST 800-53, CIS Controls, or ISO 27001 control families as implemented by IT security engineering.
- Experience in regulated environments (HIPAA, SOC 2, or similar).
Compliance & Data Privacy:
Neuralink handles sensitive patient health information and personally identifiable information (PII). All employees are expected to understand and comply with HIPAA regulations and Neuralink’s data privacy policies. This role may involve access to protected health information (PHI) and requires a demonstrated commitment to confidentiality, data security, and responsible handling of sensitive information.
Expected Compensation:
The anticipated base salary for this position is expected to be within the following range. Your actual base pay will be determined by your job-related skills, experience, and relevant education or training. We also believe in aligning our employees’ success with the company's long-term growth. As such, in addition to base salary, Neuralink offers equity compensation (in the form of Restricted Stock Units (RSU)) for all full-time employees.
What We Offer:
Full-time employees are eligible for the following benefits listed below.
- An opportunity to change the world and work with some of the smartest and most talented experts from different fields
- Growth potential; we rapidly advance team members who have an outsized impact
- Excellent medical, dental, and vision insurance through a PPO plan
- Paid holidays
- Commuter benefits
- Meals provided
- Equity (RSUs) *Temporary Employees & Interns excluded
- 401(k) plan *Interns initially excluded until they work 1,000 hours
- Parental leave *Temporary Employees & Interns excluded
- Flexible time off *Temporary Employees & Interns excluded
Optimize your resume for this job
Get a match score and the keywords you're missing
About Neuralink
Neuralink is developing ultra-high bandwidth brain-computer interfaces to connect humans and computers. Their implantable device, the N1, reads neural signals to enable people with paralysis to control digital devices with their thoughts.
Similar Security roles


