Senior individual contributor · India · Reports to the Director of Information Security
Our products are the access control layer for the companies that buy them. Identity Manager, Active Roles, Safeguard and OneLogin decide who gets into everything else a customer runs. That sets the security bar for our code higher than it sits at most software companies, and it's the reason this role works inside engineering rather than alongside it.
Much of what we build is deployed by customers in their own datacenters. When a defect ships, remediation moves at their upgrade cadence, not ours. That changes where the effort belongs: a design flaw caught in a threat model costs a conversation, and the same flaw caught after release costs a coordinated disclosure and a year of upgrade calls. This role is funded to move security earlier.
We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role is the security voice in the product organization. Scope comes from what you build into the development lifecycle and from what engineering chooses to adopt.
Six or more years in software engineering or security, with at least three focused on application or product security. Equivalent depth counts.
The three above are the bar. Everything below is depth we'd like and can build. If you meet the requirements and bring most of the rest, apply. We'd rather assess the gap ourselves than have you decide it for us.
Also matters: threat modeling at design time with engineering in the room; static, dynamic and composition analysis tooling and the judgment to tune it; identity and authentication protocols including OAuth, OIDC, SAML and SCIM; coordinated vulnerability disclosure and CVE handling; secure code review depth in web and API surfaces; the ability to hold a position with senior engineers and change it when they're right.
Helpful: SBOM standards and license compliance, cryptographic review, security champions programs, PCI DSS or FedRAMP applied to a product rather than a company, prior time as a product engineer.
This role is embedded in engineering by design, with the access to prove it. You'll work across every product line, which means breadth before depth and a constant judgment call about where your attention is worth most. The work is visible to engineering leadership and it reaches customers directly through what ships and what we're able to tell them. If you want to be measured by what got fixed rather than what got filed, this is that seat.
One Identity enables organizations of all sizes to better secure, manage, monitor, protect, and analyse information and infrastructure to help fuel innovation and drive their businesses forward.
With team members around the globe, we intend to continue to grow revenues and add value to customers.
When you join our team, you will have the opportunity to build and develop products at a scale few others can provide.
Our product portfolio serves a large base of customers and we are addressing the strategic imperatives for enterprise businesses.
Working with some of the most talented employees the industry has to offer, we provide enhanced career opportunities for team members to learn and grow in a rapidly changing environment.
Why work with us?
Life at One Identity means collaborating with dedicated professionals with a passion for technology.
When we see something that could be improved, we get to work inventing the solution.
Our people demonstrate our winning culture through positive and meaningful relationships.
We invest in our people and offer a series of programs that enables them to pursue a career that fulfills their potential.
Our team members’ health and wellness is our priority as well as rewarding them for their hard work.
One Identity is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: One Identity is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment.
All employment decisions at One Identity are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate.
One Identity will not tolerate discrimination or harassment based on any of these characteristics. One Identity encourages applicants of all ages.
Come join us.
Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be One Identity employees if they have an email address ending in @oneidentity.com.

With flexible deployment options – from self-managed to fully managed – our solutions integrate seamlessly into your environment to strengthen your identity perimeter, protect against breaches and ensure governance and compliance. One Identity unifies identity governance and administration (IGA), privileged access management (PAM), and access management (AM) for security without compromise.
By unifying IAM tools, including identity governance and administration (IGA), access management (AM), privileged access management (PAM), and Active Directory management (AD Mgmt), it ensures optimal functionality and efficiency. This cohesive structure reduces identity sprawl and extends governance to the farthest endpoints of your IAM ecosystem.
Proven and trusted on a global scale, One Identity manages more than 500 million identities for more than 11,000 organizations worldwide. For more information, visit www.oneidentity.com