Match Group Logo

Match Group

Senior Information Security Engineer

Posted Yesterday
Be an Early Applicant
Hybrid
Vancouver, BC, CAN
Senior level
Hybrid
Vancouver, BC, CAN
Senior level
Lead identity and access security across a global portfolio, including authentication, authorization, non-human identities, PAM, JIT access, and Cloudflare ZTNA. Design Okta policies, integrate endpoint and SaaS security signals, manage identity governance and compliance, and automate security workflows using infrastructure-as-code, scripting, and AI tooling. Influence cross-functional teams, modernize access controls, and drive complex security initiatives to completion.
The summary above was generated by AI
Know where you belong!
Match Group is a leading provider of dating products across the globe. Our portfolio includes Tinder, Hinge, Match, Meetic, PlentyOfFish, OkCupid, The League, HER, and others, each designed to spark meaningful connections for singles worldwide. Creating a sense of belonging doesn’t stop at our products - it’s the foundation of every team we hire.
 
When it comes to dating, the connection starts online, but the real magic happens once you meet in real life (IRL).  We think the same is true for creating the best platforms, so we work together IRL 3 days/week.

About the role

Match Group runs one unified security program across Tinder, Hinge, Match, Meetic, OkCupid, Plenty of Fish, Azar, Pairs, and the rest of the portfolio. Enterprise Security owns the corporate attack surface: who gets access to what, on which device, from where.


Identity is the center of gravity for this role and where you will spend most of your time. Our Enterprise Security function is built on two core pillars—Identity & Access Security and CorpSec—and while this role is anchored in Identity & Access Security, you will work fluidly across boundaries. Because identity is so tightly coupled with other CorpSec domains—such as endpoint, SaaS, and data access—you will collaborate fluidly across both teams to drive a unified security strategy.

What you'll do

    • Drive a comprehensive identity and access lifecycle strategy for our global portfolio, such as:

      • Authentication (AuthN): Drive identity security to the next level by enforcing device trust, post-auth detection, and DPoP.

      • Authorization (AuthZ): Enforce least privilege and right-size entitlement that balance security and velocity.

      • Non-Human & AI Agent Identity: Lead secure management for NHIs (e.g., OAuth tokens, service accounts, and API keys) and establish security guardrails for emerging AI agents and MCP connections.

      • Privileged Access Management (PAM) & Just-in-Time (JIT) Access: Modernize privileged access and implement JIT models to reduce standing privileges and secure high-risk administrative actions.

      • Own and harden Cloudflare ZTNA policies and support transitioning from traditional network-based access model.

      • Leverage your experience in broader enterprise security domains to ensure our identity strategy is integrated with our CorpSec efforts—device signals from endpoint posture (Fleet/EDR), SaaS security, and vulnerability management into our access controls to drive a unified security posture.

      • Eliminate manual toil and accelerate delivery by engineering automated solutions—using scripting, no-code tools, or AI—to solve problems at scale rather than manually managing repetitive tasks.

What we're looking for

    • 7+ years in security engineering, IT engineering, or infrastructure, with meaningful depth in identity and access

    • Strong hands-on experience with Okta: policy design, device assurance, FastPass, device trust, RBAC

    • Experience with Cloudflare Zero Trust or a comparable platform

    • Strong knowledge of SAML, OIDC, OAuth 2.0, and SCIM

    • Experience with IGA solutions (e.g., Okta Identity Governance, SailPoint), including a deep understanding of identity lifecycles and compliance requirements.

    • Experience securing non-human identities (service accounts, OAuth apps, tokens) and establishing guardrails for AI agents; we value your thought process and perspective on these emerging challenges.

    • Experience with using Terraform or other IaC tools to manage infrastructure changes, with a strong emphasis on GitOps fluency.

    • Practical view of least privilege. You can right-size access without introducing too much friction to the business.

    • Experience building automated solutions (e.g., Okta Workflows, Lambda, Windmill) using Python or similar; you know when to automate for high impact and when to avoid it to prevent over-engineering.

    • Practical use of AI tooling in your own workflow

    • Proven ability to influence cross-functional outcomes, even without direct formal authority.

    • Proactively identify, scope, and drive complex problems to completion.

Nice to have

    • Endpoint management or EDR exposure (Jamf, CrowdStrike, or similar)

    • Audit and compliance experience with access controls (SOX, PCI-DSS, ISO 27001)

    • Experience working in global environments (EMEA/APAC)

Why Match Group?
 
Our mission is simple – to help people find love and happiness! We love our employees too and understand the importance of all life's milestones. Here are some of the benefits we are proud to offer:
 
Mind & Body  Medical, mental health, and wellness benefits to support your overall health and well-being
Financial Wellness  Competitive compensation, 100% employer match on 401k contributions up to 10% (cap at $10,000), as well as an employee stock purchase program to help you feel supported in your financial security
Unplug Generous PTO and 14 paid holidays so you can unplug
Career  Annual training allowance for professional development and ERG membership opportunities and events so you feel connected and empowered in your work
Family Families come in all shapes and sizes so we offer 20 weeks of 100% paid parental leave, fertility, adoption, and child care resources, as well as pet insurance and discounts  
Company Gatherings We host company events where our employees get to know each other and build a sense of connection and belonging!
 
We are proud to be an equal opportunity employer and we value the rich dynamics that diversity brings to our company. We do not discriminate on the basis of race, religion, color, creed, national origin, ancestry, disability, marital status, age, sexual orientation, sex (including pregnancy and sexual harassment), gender identity or expression, uniformed service or veteran status, genetic information, or any other legally protected characteristic.  Period. 
 
If you require a reasonable accommodation to participate in the hiring process — such as during pre-employment testing or interviews — please indicate this by selecting “Yes” in the accommodation request field. We’ll reach out to discuss your needs if you're selected for the interview stage.   
 
#MG

Match Group Vancouver, British Columbia, CAN Office

Vancouver, Canada

Similar Jobs

9 Days Ago
Easy Apply
Remote or Hybrid
Easy Apply
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Protect corporate data through DLP implementation, tuning, alert review, false-positive reduction, and control optimization across web, endpoint, email, cloud, and SaaS environments. The engineer will review data protection programs, improve monitoring and blocking controls, collaborate with business partners, and use automation and emerging AI tools to strengthen security operations.
Top Skills: Ai ToolsCloud Data StoresData Loss Prevention (Dlp)SaaSZscaler DspmZscaler Zero Trust ExchangeZscaler Zia
Yesterday
In-Office
Senior level
Senior level
Hardware • Software • Cybersecurity • Defense
Provides senior cybersecurity engineering support across system lifecycles, implementing DoD RMF and Zero Trust controls. Performs ACAS vulnerability assessments, remediation validation, continuous monitoring, Azure security architecture, Azure Policy administration, and Defender for Cloud security posture management. Develops Xacta automation and Infrastructure as Code workflows for evidence collection, compliance validation, and continuous authorization. Collaborates with cloud, DevSecOps, architecture, and security teams while supporting assessments and authorization activities.
Top Skills: AcasAzure PolicyContinuous MonitoringDod Risk Management Framework (Rmf)Infrastructure As Code (Iac)AzureMicrosoft Defender For CloudVulnerability ManagementXactaZero Trust Architecture
13 Days Ago
In-Office
Senior level
Senior level
Aerospace • Security • Defense
Designs, deploys, hardens, and secures Microsoft Windows infrastructure supporting air traffic control systems. Responsibilities include Windows Server and workstation administration, Active Directory and Group Policy management, security architecture, vulnerability assessments, penetration testing, endpoint protection, RBAC, system hardening, remediation, documentation, and customer technical guidance. The role also leads security and deployment teams and ensures compliance with applicable security frameworks and regulations.
Top Skills: Active DirectoryAntivirusBiosCis BenchmarksEndpoint ProtectionGroup PolicyIamIso 27001Microsoft Hyper-VWindowsNistPdqPowershellPxe BootRbacRsa Authentication ManagerSIEMSplunkWindows Deployment ServicesWindows Server

What you need to know about the Vancouver Tech Scene

Raincouver, Vancity, The Big Smoke — Vancouver is known by many names, and in recent years, it has gained a reputation as a growing hub for both tech and sustainability. Renowned for its natural beauty, the city has become a magnet for professionals eager to create environmental solutions, and with an emphasis on clean technology, renewable energy and environmental innovation, it's attracted companies across various industries, all working toward a shared goal: advancing clean technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account