Role Overview
Confluent is hiring a Staff Security Risk & Compliance Program Manager - Access Management. This is a full-time remote role, with the team based in Remote, United States. Part of Confluent's Risk hiring, posted last week. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Salary Context
Salary is not disclosed in this posting. Market median for Manager-level Risk roles is $140k-$187k (based on 96 comparable listings). Many employers share specifics during the interview process or after an initial screen.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them.
It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together.
One Confluent. One Team. One Data Streaming Platform.
ABOUT THE ROLE
We are seeking a highly motivated and experienced Staff Security Risk & Compliance Program Manager - Access Management to join our Trust & Security team. This senior role owns Confluent's internal access management program and leads its evolution toward machine and workload identity — service-to-service (S2S) authentication, non-human identity (NHI), and access controls for AI agents — as the next frontier of least-privilege security for the Confluent Cloud platform.
You will be the horizontal owner of how Confluent governs access: the Access Management Standard, access metrics, and the executive reporting cadence. As access operations are distributed across partner functions, you will hold the policy, risk, and measurement line so Confluent maintains one coherent access posture rather than fragmented silos.
WHAT YOU WILL DO:
- Strategy and Leadership: Own the strategic direction and roadmap for Confluent's internal access management program, with machine and workload identity as the durable center of gravity. Drive the program's maturity model from control-building toward sustained governance and least-privilege outcomes.
- Machine & Workload Identity: Lead the program to enforce service-to-service (S2S) authentication across Trust & Security-owned surfaces, taking ownership of the enforcement hand-off from the identity engineering team. Formalize non-human identity (NHI) — service accounts, keys, and workload credentials — from pilot into a funded, governed program. Stand up access controls for AI agents as agentic workloads acquire production access.
- Access Governance & Standards: Own the Access Management Standard and the policies that operationalize least privilege, separation of duties, and periodic access review across human and machine access. Ensure the standard keeps pace with the evolving access surface and remains audit-ready.
- Metrics, Reporting & Governance Cadence: Own access metrics and reporting (e.g., JIT/unilateral-access volume, broad-privilege usage, prod-access reduction). Define and track program OKRs and run the monthly execution and executive-review cadence, articulating risk posture and progress to senior leadership.
- Cross-Functional Execution & Transitions: Drive cross-functional delivery with engineering, platform, and identity teams without direct authority.
- Integration with GRC and Partner Functions: Ensure the access management program is tightly integrated with adjacent GRC domains and partner teams (Insider Threat, IT/Identity, Detection & Response, and engineering owners), with clear RACI across governance and operations.
WHAT YOU WILL BRING:
- Experience: 8+ years in security program management, identity & access management, or a closely related security discipline, with at least 3 years running an enterprise- or platform-scale access program in a technology company.
- Technical Skills:
- Deep expertise in identity and access management concepts: least privilege, separation of duties, RBAC/ABAC, just-in-time (JIT) and privileged access management (PAM), and access review/certification.
- Working knowledge of machine and workload identity — service-to-service authentication, non-human identity, service accounts, secrets/key management, and emerging AI-agent access patterns.
- Strong security engineering fundamentals across cloud infrastructure security controls in GCP, AWS, and/or Azure, including Kubernetes and cloud control-plane access models.
- Familiarity with identity platforms and access tooling (e.g., Okta, JIT/access-orchestration tooling) and how access controls are enforced in production.
- Tooling and Automation: Experience integrating access processes, controls, or findings into GRC and access-orchestration platforms, and a bias toward automating access decisions over manual operations.
- Program Management Skills:
- Strong project management and organizational skills.
- Exceptional analytical and problem-solving skills, with a data-driven approach to decision-making.
- Experience running long-term, complex security programs that deliver iterative, measurable risk reduction.
- Communication and Collaboration Skills:
- Excellent written and verbal communication, with the ability to influence and lead without direct authority across engineering and security teams.
- Ability to articulate complex technical concepts and program status to executive-level audiences and technical teams alike.
READY TO BUILD WHAT'S NEXT? LET’S GET IN MOTION.
COME AS YOU ARE
Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible.
We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law.
PRIVACY STATEMENT
Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization. By proceeding with this application, you understand that Confluent will share your personal information with other IBM affiliates involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross-border data transfer, are available here http://ibm.com/careers/us-en/privacy-policy/.
About Confluent
Confluent
confluent.io
18 other open roles at Confluent on TryApplyNow.
Frequently Asked Questions
How do I apply for the Staff Security Risk & Compliance Program Manager - Access Management position at Confluent?
Use the Apply button above to submit your application directly to Confluent. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Is the Staff Security Risk & Compliance Program Manager - Access Management role at Confluent remote?
Yes. This is a remote role. The team is based in Remote, United States, but the position itself does not require relocating to that office.
What does a Staff Security Risk & Compliance Program Manager - Access Management at Confluent earn?
Confluent has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Staff Security Risk & Compliance Program Manager - Access Management role at Confluent posted?
This role was posted on July 10, 2026 (12 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
Similar Jobs
Senior Software Engineer, Cloud Security
Iambic Therapeutics
Principal Program Manager, Tech Risk (BC/DR)
Upstart
Data Analyst, Home Lending HMDA
Upstart
Treasury Manager
Upstart
Assistant General Counsel - HELOC
Upstart
More Jobs at Confluent
View all →Staff Software Engineer
Confluent
Senior Software Engineer - Infrastructure
Confluent
Senior Software Engineer II, Kora Compute
Confluent
Senior Software Engineer II
Confluent
Senior Software Engineer - Streaming AI (Remote - Ontario / British Columbia)
Confluent
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start