MTS Lead Identity and Access Management
Reflection is an AI research lab building open frontier models and a full AI stack for developers, enterprises, and public-sector users.
Funding history
About Reflection
Reflection develops open-weight AI models, open-source software for customizing and running agents, AI-factory infrastructure, and related solutions. Its current research emphasizes large language models, reinforcement learning, and agentic reasoning.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will architect, build, and operate cloud-native identity infrastructure. You will enforce phishing-resistant authentication, develop just-in-time access systems, secure workload identities, automate identity lifecycles, and integrate authorization policies into developer and infrastructure workflows.
Requirements
- 15+ years of experience in identity security, security architecture, or infrastructure engineering
- Experience architecting and operating modern zero-trust identity infrastructure at scale
- Experience securing IAM boundaries across AWS, GCP, Kubernetes, and containerized environments
- Experience building privileged access management systems for large-scale compute environments
- Understanding of OAuth 2.0, OIDC, SAML, WebAuthn, FIDO2, and PKI
- Software engineering capability with Go, Python, or Rust
- Infrastructure as Code experience with Terraform or Pulumi
- Knowledge of identity-focused adversary techniques
Responsibilities
- Design and implement cloud-native identity architecture using modern identity providers, federations, and zero-trust access networks
- Own identity lifecycle architecture across corporate, production, and research environments
- Enforce hardware-backed phishing-resistant authentication across corporate, production, and research endpoints
- Design dynamic least-privilege zero-trust access controls
- Build short-lived just-in-time credentialing for GPU cluster access across cloud environments
- Replace long-lived credentials with ephemeral certificate-based access
- Architect workload identity frameworks for service-to-service communication
- Ensure machine accounts, training jobs, and CI/CD pipelines use dynamic short-lived tokens
- Manage authorization policies as code with version control, testing, and deployment pipelines
- Integrate authorization into developer workflows and infrastructure deployment pipelines
- Automate provisioning and deprovisioning through SCIM and API-first tooling
- Instrument identity telemetry and build detection logic for identity-layer attacks
Benefits
- Stock options
- Comprehensive medical, dental, vision, and life insurance
- Annual wellness allowance
- Daily office lunch and dinner
- 22 weeks of paid parental leave
- Unlimited paid time off in the U.S.
- 30 days of paid time off in the U.K.
- Visa sponsorship support
- Regular off-sites, happy hours, and team celebrations
