We are driven to do more. More for our customers and the financial professionals who offer our products. If you are driven to do more and love the challenge of pursuing more, Athene is your kind of company. You will find we offer more than the basics to create an inclusive and dynamic work environment at our various locations.
Purpose:Athene is seeking a Lead Identity & Application Security Engineer to help shape the future of secure software delivery across the enterprise. This role sits at the intersection of identity engineering and application security-two disciplines built on the shared foundations of authentication, authorization, cryptography, secure APIs, and modern cloud identity.
As a senior technical leader, you'll partner with Cloud Platform Engineering, Application Development, Enterprise Architecture, and Information Security to build the platforms, frameworks, and reusable security capabilities that development teams rely on every day. Rather than acting solely as a reviewer or gatekeeper, you'll engineer solutions that make the secure path the easiest path from identity-as-code and policy-as-code guardrails to developer self-service tooling and security platform integrations.
You'll also help define how Athene secures emerging technologies, including AI agents and autonomous workloads, while influencing security strategy across cloud, application, and identity domains. This is an opportunity to solve complex engineering challenges at enterprise scale while helping protect one of the fastest-growing retirement services organizations in the industry. Backed by Apollo Global Management, Athene combines innovation, financial strength, and a culture built on ownership, collaboration, and continuous improvement.
Accountabilities:- Design, build, and maintain reusable identity and application security capabilities-including identity-as-code patterns, policy-as-code guardrails, security libraries, developer self-service capabilities, and integrations between security platforms.
- Lead the engineering and automation of AWS and Azure identity services, including IAM, federated identities, workload identities, permissions boundaries, Azure RBAC, privileged access, secrets management, and Infrastructure as Code.
- Architect and operate enterprise authentication and authorization platforms including Okta and Microsoft Entra ID, implementing SSO, MFA, Conditional Access, application integrations, privileged identity management, and modern access controls.
- Establish scalable identity frameworks for non-human identities, machine identities, and AI agents, including secure credential issuance, lifecycle management, certificate automation, and workload authentication.
- Partner with engineering teams to embed secure authentication, authorization, API security, and secure design patterns into software throughout the SDLC by performing threat modeling, architecture reviews, security testing, and remediation guidance.
- Serve as a technical leader across the Information Security organization by developing automation, integrating security tools, advancing the Security Guardians program, mentoring teammates, and driving innovation through AI-enabled engineering and continuous improvement.
Qualifications and Experience:- 6+ years of experience in identity security, application security, cloud security, software security engineering, or relevant experience.
- Deep expertise designing and implementing authentication and authorization solutions using OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, mTLS, PKI, certificate management, secure API authentication, and modern identity architecture.
- Extensive hands-on experience securing AWS and Azure environments, including AWS IAM, Azure RBAC, cloud secrets management, privileged access, Infrastructure as Code (Terraform and/or CloudFormation), CI/CD pipelines, and security automation using Python, Go, JavaScript, or TypeScript.
- Experience designing and securing enterprise identity platforms including Okta, Microsoft Entra ID, SailPoint, CyberArk, GitHub Advanced Security, API security platforms, or comparable technologies.
- Strong understanding of secure software development practices, OWASP Top 10, threat modeling, secure design reviews, SAST, DAST, Software Composition Analysis (SCA), API security testing, and secure software architecture.
- Demonstrated ability to influence engineering teams through technical leadership, consultative partnership, critical thinking, creativity, and a bias for action. Embraces emerging technologies-including AI-to automate security operations, improve developer experience, and continuously strengthen security capabilities.
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or equivalent professional experience.
Drive. Discipline. Confidence. Focus. Commitment. Learn more about working at Athene.
Athene is a Military Friendly Employer! Learn more about how we support our Veterans.
Athene is committed to inclusion and is proud to be an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, sex, national origin, age, disability, marital status, sexual orientation, veteran status or any other status protected by federal, state or local law.