Confluent

Confluent

Staff Security Risk & Compliance Program Manager - Access Management

Remote, United States · Staff+

Sponsorship not specifiedDetected 11 days ago
ReactAWSGCPAzureCloud PlatformsKubernetesAgentic AICybersecurityComplianceProject ManagementOKRsCadenceLeadershipCommunicationCollaborationProblem Solving

About the role

  • We are seeking a highly motivated and experienced Staff Security Risk & Compliance Program Manager - Access Management to join our Trust & Security team.
  • You will be the horizontal owner of how Confluent governs access: the Access Management Standard, access metrics, and the executive reporting cadence.

Responsibilities

  • Strategy and Leadership: Own the strategic direction and roadmap for Confluent's internal access management program, with machine and workload identity as the durable center of gravity.
  • Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes.
  • Machine & Workload Identity: Lead the program to enforce service-to-service (S2S) authentication across Trust & Security-owned surfaces, taking ownership of the enforcement hand-off from the identity engineering team.
  • Access Governance & Standards: Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access.
  • Metrics, Reporting & Governance Cadence: Own access metrics and reporting (e.g., JIT/unilateral-access volume, broad-privilege usage, prod-access reduction).
  • Cross-Functional Execution & Transitions: Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.
  • Integration with GRC and Partner Functions: Ensure the access management program is tightly integrated with adjacent GRC domains and partner teams (Insider Threat, IT/Identity, Detection & Response, and engineering owners), with clear RACI across governance and operations.
  • Experience running long-term, complex security programs that deliver iterative, measurable risk reduction.
  • Excellent written and verbal communication, with the ability to influence and lead without direct authority across engineering and security teams.
  • And we make space for everyone to lead, grow, and challenge what's possible.

Requirements

  • Working knowledge of machine and workload identity - service-to-service authentication, non-human identity, service accounts, secrets/key management, and emerging AI-agent access patterns.
  • Familiarity with identity platforms and access tooling (e.g., Okta, JIT/access-orchestration tooling) and how access controls are enforced in production.

Skills

  • Strong project management and organizational skills.
  • Exceptional analytical and problem-solving skills, with a data-driven approach to decision-making.
  • Ability to articulate complex technical concepts and program status to executive-level audiences and technical teams alike.
  • Program Management
  • Communication and Collaboration
  • READY TO BUILD WHAT'S NEXT?
  • LET'S GET IN MOTION.
  • Belonging isn't a perk here.
  • It's the baseline.
  • Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization.

Company info

  • 8+ years in security program management, identity & access management, or a closely related security discipline, with at least 3 years running an enterprise- or platform-scale access program in a technology company.

Equal opportunity

  • We're proud to be an equal opportunity workplace.

This listing is sourced directly from Confluent's careers page and normalized into a canonical job model.