Principal Identity Engineer✦ anywhere

🏒 Hard Rock Digital · all 18 jobs
πŸ“ Worldwide
πŸ“… Posted Sep 25, 2026 Β· via Himalayas
🏷 Identity Engineer, Security Engineer, Iam Engineer, Identity And Access Management Engineer, Principal Engineer, Principal Identity Engineer +8 more
Apply on original site β†—

What are we building?

Hard Rock Digital is a team focused on becoming the best online sportsbook, casino, and social gaming company in the world. We’re building a team that resonates passion for learning, operating, and building new products and technologies for millions of consumers. We care about each customer interaction, experience, behavior, and insight and strive to ensure we’re always acting authentically.

Rooted in the kindred spirits of Hard Rock and the Seminole Tribe of Florida, Hard Rock Digital taps a brand known the world over as the leader in gaming, entertainment, and hospitality. We’re taking that foundation of success and bringing it to the digital space - ready to join us?
What's the Position?

Identity is the control plane of modern security. In a Zero Trust world, every access decision β€” for every employee, every administrator, and every machine β€” flows through the identity systems you will own. We're looking for a Principal Identity Engineer to be the technical authority on how Hard Rock Digital decides who (and what) can access which systems, when, and under what conditions.

This is a deliberately senior, high-trust role β€” one of three Principal openings reporting directly to our VP Security / CISO β€” because identity is not a slice of our security program; it is the backbone the rest of it is built on.

You'll be our first dedicated identity hire, inside a 16-person security organization spanning Security Operations, Risk Management, and Architecture & Engineering. Day-to-day provisioning and helpdesk sit with our IT team; your job is architecture, automation, and governance that make access safe.

If you think in terms of blast radius, least privilege, and phishing-resistant authentication β€” and you like owning a domain end to end rather than a corner of it β€” you'll feel at home here.
What You'll Do
Identity & Access Architecture

-
Own the security architecture, standards, authentication methods, and roadmap for Microsoft Entra ID, our primary identity provider β€” partnering with IT on tenant operations

-
Design and continuously refine Conditional Access policies that balance strong protection with a smooth experience for a globally distributed workforce

-
Advance our rollout of phishing-resistant, passwordless authentication (passkeys, certificate-based, FIDO2)

-
Own federation and single sign-on across our SaaS estate (SAML, OIDC, OAuth 2.0, SCIM provisioning)

Privileged & Just-in-Time Access

-
Own our privileged access model using Microsoft Entra PIM β€” separate admin identities, just-in-time elevation, and approval workflows

-
Design and maintain break-glass procedures and safeguards for our most sensitive administrative paths

-
Reduce standing privilege across the environment and make "least privilege, just in time" the default

Identity Lifecycle & Access Governance

-
Automate the joiner-mover-leaver lifecycle so access is granted, changed, and revoked accurately and promptly

-
Build and run access reviews and entitlement governance, partnering with our GRC team on audit evidence (ISO 27001, SOC 2, PCI DSS, GLI-19/GLI-33)

-
Make access decisions auditable, explainable, and continuously right sized

Non-Human & Workload Identity

-
Govern service principles, managed identities, and workload/federated credentials across AWS, Azure, and GCP

-
Partner on secrets governance across our secrets management platforms to shrink the number of long-lived, standing secrets

-
Partner with our Principal Cloud & Network Security Engineer, who owns service-to-service authentication (mTLS, service mesh)

Zero Trust Strategy

-
Serve as the identity authority for our Zero Trust program, aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model (Identity pillar)

-
Partner with our cloud and network security function on identity-aware access through Cloudflare Access

-
Partner with Security Operations to make identity signals (risky sign-ins, privileged elevation, MFA an

Travel medical insurance

Working from anywhere means medical cover that follows you, not a policy tied to one country. SafetyWing is built for exactly that: travel medical insurance you can start mid-trip and pay monthly.

Get your global insurance today β†’

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs β†’
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you