Confluent
Staff Security Risk & Compliance Program Manager - Access Management
Remote, United States · Staff+
Sponsorship not specifiedDetected 11 days ago
ReactAWSGCPAzureCloud PlatformsKubernetesAgentic AICybersecurityComplianceProject ManagementOKRsCadenceLeadershipCommunicationCollaborationProblem Solving
About the role
- We are seeking a highly motivated and experienced Staff Security Risk & Compliance Program Manager - Access Management to join our Trust & Security team.
- You will be the horizontal owner of how Confluent governs access: the Access Management Standard, access metrics, and the executive reporting cadence.
Responsibilities
- Strategy and Leadership: Own the strategic direction and roadmap for Confluent's internal access management program, with machine and workload identity as the durable center of gravity.
- Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes.
- Machine & Workload Identity: Lead the program to enforce service-to-service (S2S) authentication across Trust & Security-owned surfaces, taking ownership of the enforcement hand-off from the identity engineering team.
- Access Governance & Standards: Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access.
- Metrics, Reporting & Governance Cadence: Own access metrics and reporting (e.g., JIT/unilateral-access volume, broad-privilege usage, prod-access reduction).
- Cross-Functional Execution & Transitions: Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.
- Integration with GRC and Partner Functions: Ensure the access management program is tightly integrated with adjacent GRC domains and partner teams (Insider Threat, IT/Identity, Detection & Response, and engineering owners), with clear RACI across governance and operations.
- Experience running long-term, complex security programs that deliver iterative, measurable risk reduction.
- Excellent written and verbal communication, with the ability to influence and lead without direct authority across engineering and security teams.
- And we make space for everyone to lead, grow, and challenge what's possible.
Requirements
- Working knowledge of machine and workload identity - service-to-service authentication, non-human identity, service accounts, secrets/key management, and emerging AI-agent access patterns.
- Familiarity with identity platforms and access tooling (e.g., Okta, JIT/access-orchestration tooling) and how access controls are enforced in production.
Skills
- Strong project management and organizational skills.
- Exceptional analytical and problem-solving skills, with a data-driven approach to decision-making.
- Ability to articulate complex technical concepts and program status to executive-level audiences and technical teams alike.
- Program Management
- Communication and Collaboration
- READY TO BUILD WHAT'S NEXT?
- LET'S GET IN MOTION.
- Belonging isn't a perk here.
- It's the baseline.
- Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization.
Company info
- 8+ years in security program management, identity & access management, or a closely related security discipline, with at least 3 years running an enterprise- or platform-scale access program in a technology company.
Equal opportunity
- We're proud to be an equal opportunity workplace.
Apply directly at Confluent →Create a free account for alerts like thisView Confluent immigration profile
This listing is sourced directly from Confluent's careers page and normalized into a canonical job model.