IT Security & Identity Engineer
Austin, TX - USA
Job Summary
About Neuralink:
We are creating devices that enable a bi-directional interface with the brain. These devices allow us to restore movement to the paralyzed restore sight to the blind and revolutionize how humans interact with their digital world.
Team Description:
Neuralinks Information Technology team owns the corporate environment that every engineer scientist and clinician depends on to do their work. Within IT the Security & Identity function is responsible for who can access what from which device under what conditions. That means running the identity provider and SSO federation enforcing strong authentication and device trust securing endpoints across macOS Windows and Linux centralizing logs and detections and producing the audit evidence that supports HIPAA and SOC 2. We manage this environment as code in Terraform and GitLab and we hold a high bar for making access both secure and low-friction for a fast-moving company.
Job Description and Responsibilities:
Neuralink is looking for a hands-on IT Security & Identity Engineer to own identity access and endpoint security for our corporate environment. You will be the technical owner of our identity provider SSO federation and lifecycle automation and you will drive endpoint protection detection and vulnerability management alongside the rest of the IT team. This is a build-and-operate role: you will design controls implement them in Terraform through GitLab and then run them in production including on-call. The ideal candidate has strong opinions grounded in experience takes full ownership of the systems they build makes practical risk decisions without slowing the company down and can explain security tradeoffs clearly to engineers and non-technical staff alike. The job responsibilities will include:
- Design deploy and operate identity and access management across Google Workspace Microsoft Entra and integrated SaaS applications; own SSO federation (SAML OIDC OAuth 2.0) and SCIM provisioning for business-critical tools.
- Manage identity infrastructure and access policy as code using Terraform and GitLab CI/CD; treat the IdP group membership application assignments and conditional access as versioned reviewable state.
- Drive identity lifecycle automation from onboarding through offboarding including role-based access control (RBAC) attribute-driven group membership just-in-time access and reduction of standing privilege.
- Design and operate strong authentication: phishing-resistant MFA (FIDO2/WebAuthn passkeys hardware tokens) certificate-based authentication (X.509 802.1x) and device-trust conditions tied to MDM compliance.
- Own endpoint security posture across macOS Windows and Linux alongside the IT team: EDR policy and operations disk encryption secure baselines and compliance enforcement through MDM (Intune Jamf or similar).
- Build and maintain security logging and detection for corporate IT: centralize identity endpoint SaaS and network logs (Grafana/Loki Prometheus or a SIEM) write detections for identity abuse and endpoint compromise and tune alerting.
- Run enterprise vulnerability management: scanning prioritization remediation workflows with system owners and evidence of closure.
- Harden traditional IT services used by engineering science and clinical staff (email file shares directory services collaboration tools internal applications); review and improve permissions group membership and access models.
- Partner with systems network and application owners to securely design and operate services on the Tailscale and FortiGate-based network: authentication and authorization logging patching and least privilege.
- Lead or support detection triage and incident response for the corporate IT environment; participate in the IT on-call rotation.
- Conduct regular access reviews and audits; produce evidence supporting HIPAA PII handling and SOC 2 or comparable frameworks in partnership with Compliance.
- Drive scripting and automation (Python Bash PowerShell) for repeatable security tasks: baselines evidence collection health checks and remediation.
- Recommend justify and implement improvements through an accepted change control process; define document and follow standards for design testing and implementation.
- Serve as the IAM and security subject matter expert for the IT team providing technical guidance and mentoring teammates.
Required Qualifications:
- Bachelors degree in computer science cybersecurity or another STEM discipline or 5 years of professional experience in enterprise IT security engineering in lieu of a degree.
- 5 years of hands-on experience securing corporate IT environments (identity/MFA endpoint security logging and detection vulnerability management email or file services).
- Demonstrated experience administering an enterprise IdP (Google Workspace Microsoft Entra or Okta) including SSO federation SCIM provisioning MFA enforcement conditional access and full user lifecycle management.
- Strong working knowledge of IAM protocols and standards: SAML OIDC OAuth 2.0 SCIM.
- Hands-on experience managing infrastructure or identity configuration with Terraform and Git-based workflows.
- Experience administering or operating at least two of the following: enterprise EDR/AV centralized logging or SIEM enterprise vulnerability management platform enterprise MDM.
- Scripting proficiency in Python Bash or PowerShell for security automation and integrations.
- Excellent communication skills with IT engineers and a diverse user base including non-technical scientists and clinicians; able to explain security tradeoffs and risk decisions clearly.
Preferred Qualifications:
- Experience implementing phishing-resistant MFA at scale: FIDO2/WebAuthn passkeys hardware tokens smart cards.
- Certificate-based authentication and PKI operations: TLS X.509 802.1x internal CA management.
- Zero-trust architecture experience including device trust Tailscale or comparable mesh VPN and identity-aware access.
- Detection engineering experience: writing and tuning detections in Grafana/Loki a SIEM or comparable tooling.
- Hardening Windows macOS and Linux endpoints and servers; securing file shares email gateways and internal applications.
- Privileged access management just-in-time access and privilege-escalation reduction.
- SOC or blue-team incident response experience on enterprise IT estates.
- Configuration management with Ansible or similar; GitLab CI/CD pipelines.
- Familiarity with NIST 800-53 CIS Controls or ISO 27001 control families as implemented by IT security engineering.
- Experience in regulated environments (HIPAA SOC 2 or similar).
Compliance & Data Privacy:
Neuralink handles sensitive patient health information and personally identifiable information (PII). All employees are expected to understand and comply with HIPAA regulations and Neuralinks data privacy policies. This role may involve access to protected health information (PHI) and requires a demonstrated commitment to confidentiality data security and responsible handling of sensitive information.
Expected Compensation:
The anticipated base salary for this position is expected to be within the following range. Your actual base pay will be determined by your job-related skills experience and relevant education or training. We also believe in aligning our employees success with the companys long-term growth. As such in addition to base salary Neuralink offers equity compensation (in the form of Restricted Stock Units (RSU)) for all full-time employees.
Base Salary Range:
$99000 - $185000 USD
What We Offer:
Full-time employees are eligible for the following benefits listed below.
- An opportunity to change the world and work with some of the smartest and most talented experts from different fields
- Growth potential; we rapidly advance team members who have an outsized impact
- Excellent medical dental and vision insurance through a PPO plan
- Paid holidays
- Commuter benefits
- Meals provided
- Equity (RSUs) *Temporary Employees & Interns excluded
- 401(k) plan *Interns initially excluded until they work 1000 hours
- Parental leave *Temporary Employees & Interns excluded
- Flexible time off *Temporary Employees & Interns excluded
Required Experience:
IC
About Company
Creating a generalized brain interface to restore autonomy to those with unmet medical needs today and unlock human potential tomorrow.