RefolkCandidates
Open nowEngineeringSoftware

IT Security & Identity Engineer

Neuralink · Austin, Texas

Location
Austin, Texas, United States
Employment
Full time
Level
Mid level
Posted
4 days ago

About this role

About Neuralink:

We are creating devices that enable a bi-directional interface with the brain. These devices allow us to restore movement to the paralyzed, restore sight to the blind, and revolutionize how humans interact with their digital world.

Team Description:

Neuralink's Information Technology team owns the corporate environment that every engineer, scientist, and clinician depends on to do their work. Within IT, the Security & Identity function is responsible for who can access what, from which device, under what conditions. That means running the identity provider and SSO federation, enforcing strong authentication and device trust, securing endpoints across macOS, Windows, and Linux, centralizing logs and detections, and producing the audit evidence that supports HIPAA and SOC 2. We manage this environment as code in Terraform and GitLab, and we hold a high bar for making access both secure and low-friction for a fast-moving company.

Job Description and Responsibilities:

Neuralink is looking for a hands-on IT Security & Identity Engineer to own identity, access, and endpoint security for our corporate environment. You will be the technical owner of our identity provider, SSO federation, and lifecycle automation, and you will drive endpoint protection, detection, and vulnerability management alongside the rest of the IT team. This is a build-and-operate role: you will design controls, implement them in Terraform through GitLab, and then run them in production, including on-call. The ideal candidate has strong opinions grounded in experience, takes full ownership of the systems they build, makes practical risk decisions without slowing the company down, and can explain security tradeoffs clearly to engineers and non-technical staff alike. The job responsibilities will include:

  • Design, deploy, and operate identity and access management across Google Workspace, Microsoft Entra, and integrated SaaS applications; own SSO federation (SAML, OIDC, OAuth 2.0) and SCIM provisioning for business-critical tools.
  • Manage identity infrastructure and access policy as code using Terraform and GitLab CI/CD; treat the IdP, group membership, application assignments, and conditional access as versioned, reviewable state.
  • Drive identity lifecycle automation from onboarding through offboarding, including role-based access control (RBAC), attribute-driven group membership, just-in-time access, and reduction of standing privilege.
  • Design and operate strong authentication: phishing-resistant MFA (FIDO2/WebAuthn, passkeys, hardware tokens), certificate-based authentication (X.509, 802.1x), and device-trust conditions tied to MDM compliance.
  • Own endpoint security posture across macOS, Windows, and Linux alongside the IT team: EDR policy and operations, disk encryption, secure baselines, and compliance enforcement through MDM (Intune, Jamf, or similar).
  • Build and maintain security logging and detection for corporate IT: centralize identity, endpoint, SaaS, and network logs (Grafana/Loki, Prometheus, or a SIEM), write detections for identity abuse and endpoint compromise, and tune alerting.
  • Run enterprise vulnerability management: scanning, prioritization, remediation workflows with system owners, and evidence of closure.
  • Harden traditional IT services used by engineering, science, and clinical staff (email, file shares, directory services, collaboration tools, internal applications); review and improve permissions, group membership, and access models.
  • Partner with systems, network, and application owners to securely design and operate services on the Tailscale and FortiGate-based network: authentication and authorization, logging, patching, and least privilege.
  • Lead or support detection, triage, and incident response for the corporate IT environment; participate in the IT on-call rotation.
  • Conduct regular access reviews and audits; produce evidence supporting HIPAA, PII handling, and SOC 2 or comparable frameworks in partnership with Compliance.
  • Drive scripting and automation (Python, Bash, PowerShell) for repeatable security tasks: baselines, evidence collection, health checks, and remediation.
  • Recommend, justify, and implement improvements through an accepted change control process; define, document, and follow standards for design, testing, and implementation.
  • Serve as the IAM and security subject matter expert for the IT team, providing technical guidance and mentoring teammates.

Required Qualifications:

  • Bachelor's degree in computer science, cybersecurity, or another STEM discipline, or 5+ years of professional experience in enterprise IT security engineering in lieu of a degree.
  • 5+ years of hands-on experience securing corporate IT environments (identity/MFA, endpoint security, logging and detection, vulnerability management, email or file services).
  • Demonstrated experience administering an enterprise IdP (Google Workspace, Microsoft Entra, or Okta) including SSO federation, SCIM provisioning, MFA enforcement, conditional access, and full user lifecycle management.
  • Strong working knowledge of IAM protocols and standards: SAML, OIDC, OAuth 2.0, SCIM.
  • Hands-on experience managing infrastructure or identity configuration with Terraform and Git-based workflows.
  • Experience administering or operating at least two of the following: enterprise EDR/AV, centralized logging or SIEM, enterprise vulnerability management platform, enterprise MDM.
  • Scripting proficiency in Python, Bash, or PowerShell for security automation and integrations.
  • Excellent communication skills with IT engineers and a diverse user base including non-technical scientists and clinicians; able to explain security tradeoffs and risk decisions clearly.

Preferred Qualifications:

  • Experience implementing phishing-resistant MFA at scale: FIDO2/WebAuthn, passkeys, hardware tokens, smart cards.
  • Certificate-based authentication and PKI operations: TLS, X.509, 802.1x, internal CA management.
  • Zero-trust architecture experience, including device trust, Tailscale or comparable mesh VPN, and identity-aware access.
  • Detection engineering experience: writing and tuning detections in Grafana/Loki, a SIEM, or comparable tooling.
  • Hardening Windows, macOS, and Linux endpoints and servers; securing file shares, email gateways, and internal applications.
  • Privileged access management, just-in-time access, and privilege-escalation reduction.
  • SOC or blue-team incident response experience on enterprise IT estates.
  • Configuration management with Ansible or similar; GitLab CI/CD pipelines.
  • Familiarity with NIST 800-53, CIS Controls, or ISO 27001 control families as implemented by IT security engineering.
  • Experience in regulated environments (HIPAA, SOC 2, or similar).

Compliance & Data Privacy:

Neuralink handles sensitive patient health information and personally identifiable information (PII). All employees are expected to understand and comply with HIPAA regulations and Neuralink’s data privacy policies. This role may involve access to protected health information (PHI) and requires a demonstrated commitment to confidentiality, data security, and responsible handling of sensitive information.

Expected Compensation:

The anticipated base salary for this position is expected to be within the following range. Your actual base pay will be determined by your job-related skills, experience, and relevant education or training. We also believe in aligning our employees’ success with the company's long-term growth. As such, in addition to base salary, Neuralink offers equity compensation (in the form of Restricted Stock Units (RSU)) for all full-time employees.

Base Salary Range:$99,000-$185,000 USD

What We Offer:

Full-time employees are eligible for the following benefits listed below.

  • An opportunity to change the world and work with some of the smartest and most talented experts from different fields
  • Growth potential; we rapidly advance team members who have an outsized impact
  • Excellent medical, dental, and vision insurance through a PPO plan
  • Paid holidays
  • Commuter benefits
  • Meals provided
  • Equity (RSUs) *Temporary Employees & Interns excluded
  • 401(k) plan *Interns initially excluded until they work 1,000 hours
  • Parental leave *Temporary Employees & Interns excluded
  • Flexible time off *Temporary Employees & Interns excluded

As published by Neuralink. Applications are handled on their site.

Skills this posting mentions

TerraformAutomationEndpoint Security

About Neuralink

Neuralink is a team of exceptionally talented people. We are creating the future of brain-machine interfaces: building devices now that will help people with paralysis and inventing new technologies that will expand our abilities, our community, and our world. Our goal is to build a system with at least two orders of magnitude more communication channels (electrodes) than current clinically-approved devices. This system needs to be safe, it must have fully wireless communication through the skin, and it has to be ready for patients to take home and use on their own. Our device, called the Link, will be able to record from 1024 electrodes and is designed to meet these criteria.

All 81 openings at Neuralink

One click, then it is written

Apply to Neuralink with a resume written for this role.

Queue IT Security & Identity Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Neuralink’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at Neuralink

See all

Similar roles elsewhere

See more

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board Neuralink publishes. Refolk is not the employer and does not handle their hiring. Applications go to Neuralink directly.