We’re seeking a curious, analytical, and highly independent Security Analyst to join Shopify’s Identity and Access Management (IAM) team. In this pivotal role, you will apply a data-driven approach to deeply analyze the effectiveness and user experience of our internal security controls and identity systems. Your work will directly enhance the security of our global operations, protect our merchants, and ensure Shopify's rapid pace of development is supported by robust yet user-friendly access mechanisms.
You will be a trusted partner collaborating closely with security engineers, system administrators, and diverse cross-functional teams. Your contributions will be essential in refining and improving our security controls, ensuring they are not only effective but also enable Shopify’s rapid innovation. This is not just about identifying problems; it's about providing the insights and analysis needed to build better, more intuitive security.
This role offers a unique opportunity to apply your technical curiosity and analytical mindset to understand and manage security risk within a dynamic environment. You will be at the forefront of analyzing, monitoring, and improving foundational technical controls, focusing on their real-world impact and effectiveness across Shopify’s programs, platforms, and products.
Key Responsibilities:
- Lead and contribute to projects that build out and harden security at Shopify.
- Conduct in-depth analysis of the security and employee impact of our current and future IAM security controls, advocating for solutions that balance strong security with optimal user experience.
- Contribute to identifying and advocating for opportunities to automate and improve security workflows and tasks, providing analysis that guides engineering and operations teams.
- Proactively identify gaps in existing security controls during incidents or reviews, providing actionable analysis to inform engineering and operational solutions.
- Utilize data and key metrics to understand and measure the effectiveness of Shopify’s security controls and IAM program.
Qualifications:
- Demonstrated technical curiosity and a drive to independently investigate complex systems and challenges.
- Strong analytical skills with the ability to design experiments, collect diverse data, and derive actionable insights from complex datasets.
- Proven experience with SQL and building data dashboards for analysis and reporting.
- Coding literacy: Ability to understand and interpret code (e.g., for system analysis) to analyze control functionality.
- Experience leveraging AI tools for code interpretation is a plus.
- Effective communication skills, with a proven ability to translate complex technical concepts and data findings into clear, compelling narratives.
- An understanding of information security fundamentals, privacy, and compliance standards.
- Familiarity with concepts of identity providers (e.g., Okta) and access management at scale.
- Exceptional ability to create and maintain trusted relationships across the organization, approaching interactions with a non-judgmental and collaborative mindset.
- Experience in roles requiring significant independence and problem-solving, even if the primary domain was not security (e.g., technical support, operations, program coordination).