
Principal individual contributor · India · Reports to the Director of Information Security
The architecture set in this role decides which certifications One Identity can hold and which markets we can sell into. That is unusual commercial weight for an engineering seat, and it comes with a mandate from leadership to build the program behind it.
We sell on-premises and hosted solutions. Some products run as hosted services we operate in Azure and AWS. Others ship as software customers deploy in their own datacenters. Infrastructure security here has two audiences: the environments we run, and the base images, container definitions, and deployment defaults we publish, which become part of every customer's environment. A hardening decision made once is inherited by everyone who deploys it.
We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role is its senior technical voice. Scope comes from what you design and automate, and from what engineering chooses to adopt.
Ten or more years in security engineering or infrastructure engineering, with substantial time in cloud architecture. Equivalent depth counts.
The three above are the bar. Everything below is depth we'd like and can build. If you meet the requirements and bring most of the rest, apply. We'd rather assess the gap ourselves than have you decide it for us.
Also matters: enough seniority in infrastructure as code to improve on what strong teams already do; network security fundamentals applied to cloud, covering segmentation, private connectivity, egress control, and east-west traffic; container and Kubernetes security, image hardening, supply chain integrity, and secrets management; policy-as-code frameworks and a view on where enforcement belongs in the lifecycle; controls you designed that held up under an audit you were personally accountable for; judgment about which risks to carry and which to escalate.
Helpful: shipping software customers deploy themselves, FedRAMP or IRAP, a carve-out or large-scale cloud migration.
This is a builder's seat with leadership behind it. You'll set the infrastructure security architecture for a newly independent company, with the backing to build a program rather than the job of holding one together. The work enables engineering directly and opens new markets. If you've wanted to define the direction, this is that seat.
One Identity enables organizations of all sizes to better secure, manage, monitor, protect, and analyse information and infrastructure to help fuel innovation and drive their businesses forward.
With team members around the globe, we intend to continue to grow revenues and add value to customers.
When you join our team, you will have the opportunity to build and develop products at a scale few others can provide.
Our product portfolio serves a large base of customers and we are addressing the strategic imperatives for enterprise businesses.
Working with some of the most talented employees the industry has to offer, we provide enhanced career opportunities for team members to learn and grow in a rapidly changing environment.
Why work with us?
Life at One Identity means collaborating with dedicated professionals with a passion for technology.
When we see something that could be improved, we get to work inventing the solution.
Our people demonstrate our winning culture through positive and meaningful relationships.
We invest in our people and offer a series of programs that enables them to pursue a career that fulfills their potential.
Our team members’ health and wellness is our priority as well as rewarding them for their hard work.
One Identity is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: One Identity is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment.
All employment decisions at One Identity are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate.
One Identity will not tolerate discrimination or harassment based on any of these characteristics. One Identity encourages applicants of all ages.
Come join us.
Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be One Identity employees if they have an email address ending in @oneidentity.com.

With flexible deployment options – from self-managed to fully managed – our solutions integrate seamlessly into your environment to strengthen your identity perimeter, protect against breaches and ensure governance and compliance. One Identity unifies identity governance and administration (IGA), privileged access management (PAM), and access management (AM) for security without compromise.
By unifying IAM tools, including identity governance and administration (IGA), access management (AM), privileged access management (PAM), and Active Directory management (AD Mgmt), it ensures optimal functionality and efficiency. This cohesive structure reduces identity sprawl and extends governance to the farthest endpoints of your IAM ecosystem.
Proven and trusted on a global scale, One Identity manages more than 500 million identities for more than 11,000 organizations worldwide. For more information, visit www.oneidentity.com