We're looking for curious and detail-oriented individuals to join Shopify's Identity and Access Management (IAM) team as a Technical Security Analyst.
As a Technical Security Analyst on the IAM team, you'll dig deep into security systems and workflows that manage corporate identities and govern their respective levels of access to enhance the security of our global operations and integrity of our products. You will play a critical role to ensure that employees are equipped with the right technology they need to securely do work that helps us ship and scale the business
You will collaborate with engineers, system administrators, and cross-functional teams to help protect our merchants and company while supporting Shopify's rapid pace of development. You will be an essential member of our group of security professionals and a key player in operating and refining security controls that support Shopify's programs, platforms, and products.
In this role, you'll be leveraging your expertise in technology and security, along with your knowledge of Shopify's products, applications and infrastructure, to understand and manage risk. You will be analyzing, monitoring, and improving technical controls that are foundational components of Shopify's security programs.
The role will provide an opportunity to:
analyze the security and employee impact of our current and future IAM security controls
monitor Shopify's current technology stack and make recommendations to reduce security risk
automate and improve security workflows and tasks across the scope of our security programs
provide operational security guidance to ensure controls are functioning effectively, efficiently and without gaps
collaborate with cross functional teams and gather evidence for assessments, implementations, and use of new tools and workflows
lead and contribute to projects that build out and harden security at Shopify
utilize data and key metrics to understand Shopify's security program
develop and share security best practices
Qualifications
It would be great if you had experience in one or more of the following (don't stress, we are not expecting experience in all of the following!):
an understanding of information security fundamentals, privacy and compliance standards
working with corporate identity providers at scale, such as Okta
effective communication skills, ability to translate technology (complex configuration, code) and leveraging data in storytelling
working with SQL and building data dashboards
demonstrated impact in performing assessments
recommending and writing access policies
monitoring controls and security safeguards for frameworks
passion for documenting strategy and approach
ability to create and maintain trusted relationships across the organization