Job Description
Are you a security visionary obsessed with access control? Nexus Security Labs is revolutionizing the digital identity landscape, and we are seeking a world-class Senior Security Engineer to lead our 2FA (Two-Factor Authentication) and Multi-Factor Authentication (MFA) initiatives.
In this pivotal role, you will architect and implement next-generation identity protection strategies, ensuring our enterprise clients remain impenetrable against evolving phishing and credential-stuffing attacks. You will work at the intersection of security engineering and user experience, deploying seamless yet robust authentication layers.
Why Join Us?
- Impact: Directly shield millions of users from cyber threats.
- Innovation: Work with cutting-edge Zero Trust architecture and FIDO2 standards.
- Culture: A diverse, elite team of hackers, cryptographers, and engineers.
Join us in building the secure future of the web.
Responsibilities
- Architect & Deploy 2FA/MFA: Design and implement scalable 2FA and MFA solutions using hardware keys (FIDO2), TOTP, and SMS.
- Identity Governance: Manage and refine Identity Access Management (IAM) policies, ensuring the Principle of Least Privilege is strictly enforced.
- Zero Trust Implementation: Spearhead the adoption of Zero Trust Network Access (ZTNA) principles across the organization.
- Threat Mitigation: Conduct regular audits of authentication flows to identify and patch vulnerabilities against phishing and man-in-the-middle attacks.
- Collaboration: Partner with DevOps and Product teams to integrate secure authentication into CI/CD pipelines and SaaS applications.
- Security Awareness: Educate stakeholders on the importance of strong authentication hygiene and emerging credential security trends.
Qualifications
- Experience: 5+ years of experience in cybersecurity, with a strong focus on authentication protocols (OAuth 2.0, SAML, OIDC).
- Technical Expertise: Deep understanding of 2FA mechanisms, including TOTP, push notifications, and hardware key protocols.
- Tools: Proficiency with tools like Okta, Duo, Auth0, Keycloak, or Azure AD B2C.
- Programming: Strong scripting skills in Python or Go to automate security controls.
- Certifications: CISSP, CEH, or Security+ is highly preferred.
- Problem Solving: Ability to troubleshoot complex authentication failures and optimize performance.