
Software Engineer II, Security
GitHub · United States
- Hybrid
- Full-time
- $150,000 / year
- United States
Job highlights
- Secure GitHub's internal systems and data.
- Manage identity and access for developers.
- Develop automation for IAM processes.
- Collaborate across engineering teams.
- Ensure compliance with audit frameworks.
About the role
About GitHub
GitHub is the world’s leading platform for agentic software development — powered by Copilot to build, scale, and deliver secure software. Over 180 million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate, and more than 77,000 organisations have adopted GitHub Copilot.
Locations
In this role you can work from Remote, United States
Overview
GitHub is changing the way the world builds software, and we want you to help secure GitHub. We're looking for an Identity & Access Security Operations Engineer to ensure the right Hubbers get the right access at the right time for the right reasons and to strengthen the security and availability of GitHub’s internal systems.
As part of Secure Access Engineering – Identity & Access Management, you will enable secure access to GitHub’s internal infrastructure and the sensitive data stored therein. In this position, you will maintain and improve IAM control processes, develop automation to improve efficiency, and collaborate across teams to ensure secure access patterns.
Responsibilities
- Provide guidance and support to Hubbers using GitHub’s internal identity and access management platform
- Develop, maintain, and improve services that support identity lifecycle, access workflows, and paved-path processes for Hubbers
- Work with technical and non technical partner teams to drive consistent IAM practices
- Monitor and maintain IAM services, participate in an on-call rotation, respond to incidents, and enhance operational processes
- Manage services and processes that play a critical role in compliance to several audit frameworks
Qualifications
Required Qualifications:
- 2+ years experience in Software Engineering, Computer Science, or related technical discipline with proven experience maintaining production software coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, Go, Ruby, Rust, or Python OR Associate’s Degree in Computer Science, Electrical Engineering, Electronics Engineering, Math, Physics, Computer Engineering, Computer Science, or related field AND 1+ year(s) experience OR Bachelor's Degree in Computer Science or related field OR equivalent experience.
- 1+ years of experience in Security Operations, Identity & Access Management, Security Engineering, or a related technical field.
- 1+ years experience implementing or operating IAM technologies (e.g., SSO/MFA, directory services, RBAC/ABAC models).
- 1+ years professional experience working with Ruby
Preferred Qualifications:
- Experience operating identity or access management systems at scale.
- Familiarity with identity directories (e.g., Okta, Azure AD), authentication/authorization protocols (OAuth, SAML, OIDC)
- Experience supporting production services in an on-call capacity.
- Experience with cloud environments such as AWS, Azure, or GCP.
- Experience designing paved-path processes for identity lifecycle, access reviews, or entitlements management.
Compensation Range
The base salary range for this job is USD $83,400.00 - USD $221,400.00 /Yr.
These pay ranges are intended to cover roles based across the United States. An individual's base pay depends on various factors including geographical location and review of experience, knowledge, skills, abilities of the applicant. At GitHub certain roles are eligible for benefits and additional rewards, including annual bonus and stock. These rewards are allocated based on individual impact in role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee's relationship with the company.
This position will be open for a minimum of 3 days, with applications accepted on an ongoing basis until the position is filled.
GitHub values
- Customer-obsessed
- Ship to learn
- Growth mindset
- Own the outcome
- Better together
- Diverse and inclusive
Manager fundamentals
- Model
- Coach
- Care
Leadership principles
- Create clarity
- Generate energy
- Deliver success
Who We Are
GitHub is the world’s leading AI-powered developer platform with 150 million developers and counting. We’re also home to the biggest open-source community on earth (and 99% of the world’s software has open-source code in its DNA). Many of the apps and programs you use every day are built on GitHub.
Our teams are dreamers, doers, and pioneers, leading the way in AI, driving humanitarian efforts around the globe, and even sending open source to Mars (and beyond!). At GitHub, our goal is to create the space you need to do your best work. We’re remote-first and offer competitive pay, generous learning and growth opportunities, and excellent benefits to support you, wherever you are—because we know that people flourish when they can work on their own terms.
Join us, and let’s change the world, together.
EEO Statement
GitHub is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life. We don't discriminate against employees or applicants based on gender identity or expression, sexual orientation, race, religion, age, national origin, citizenship, disability, pregnancy status, veteran status, or any other differences. Also, if you have a disability, please let us know if there's any way we can make the interview process better for you; we're happy to accommodate!
Key skills/competency
- Software Engineering
- Security Operations
- Identity & Access Management
- IAM Technologies
- Ruby
- AWS
- Azure
- GCP
- Okta
- Azure AD
Skills & topics
- Software Engineering
- Security Operations
- Identity and Access Management
- IAM
- Ruby
- AWS
- Azure
- GCP
- Okta
- Azure AD
- Security Engineering
- Access Control
- SSO
- MFA
- RBAC
- ABAC
- Remote
- United States
How to get hired
- Tailor your resume: Highlight your 2+ years of software engineering experience and 1+ year in security operations or IAM, emphasizing Ruby and IAM technologies.
- Showcase relevant skills: Emphasize experience with SSO/MFA, directory services, RBAC/ABAC, and cloud platforms like AWS, Azure, or GCP.
- Demonstrate understanding of scale: If you have experience operating IAM systems at scale, make sure to detail this in your application.
- Prepare for technical questions: Be ready to discuss your experience with production software, coding languages, and IAM protocols like OAuth, SAML, and OIDC.
- Express cultural fit: Align your application and interview responses with GitHub's values: customer-obsessed, ship to learn, growth mindset, own the outcome, and better together.
Technical preparation
Behavioral questions
Frequently asked questions
- What are the primary responsibilities of a Security Engineer at GitHub?
- As a Security Engineer at GitHub, you will focus on ensuring the right individuals have the appropriate access to internal systems and sensitive data at the right times. This involves maintaining and improving Identity and Access Management (IAM) control processes, developing automation for efficiency, and collaborating with various teams to enforce secure access patterns.
- What qualifications are essential for the Security Engineer role at GitHub?
- Essential qualifications include at least 2 years of experience in Software Engineering or a related technical field, with proven experience in production software. Additionally, 1+ years of experience in Security Operations, Identity & Access Management, or Security Engineering is required, along with 1+ years of experience implementing or operating IAM technologies and professional experience with Ruby.
- Is this a remote position at GitHub?
- Yes, this Security Engineer position at GitHub is a remote role, allowing you to work from anywhere in the United States.
- What are GitHub's core values and how do they relate to this role?
- GitHub values include being customer-obsessed, embracing a 'ship to learn' mentality, having a growth mindset, owning the outcome, and fostering a 'better together' environment with diversity and inclusion. These values are crucial for this role, as you'll be collaborating with teams, improving processes, and ensuring secure access for all 'Hubbers'.
- What programming languages are relevant for the Security Engineer role at GitHub?
- While the role requires proficiency in Ruby, GitHub's software engineering teams utilize a variety of languages. Your experience with languages such as C, C++, C#, Java, JavaScript, Go, Rust, or Python will be valuable in understanding and contributing to the broader engineering landscape.
- What are some preferred qualifications for this Security Engineer position?
- Preferred qualifications include experience operating identity or access management systems at scale, familiarity with identity directories like Okta or Azure AD, experience with authentication/authorization protocols (OAuth, SAML, OIDC), supporting production services on-call, and experience with cloud environments (AWS, Azure, GCP).
- How does GitHub approach diversity and inclusion for its Security Engineers?