Skip to main content

Senior Engineer - Access Entitlements

Senior Engineer - Access Entitlements

British Columbia, CA
Apply now
Function Tech Team Securiti AI Role Type Permanent Work Location Hybrid Date Posted 09/14/2026

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

About the Role

We are seeking an exceptional Senior Engineer – Access Entitlements to design and scale the systems that discover, normalize, and reason about who has access to what across our customers' entire data estate — on-prem file shares, Active Directory, and SaaS platforms like SharePoint, Google Workspace, and Microsoft 365. You will build the connectors, pipelines, and graph models that turn millions of raw permission grants into an accurate, queryable picture of access across billions of files and identities, powering least-privilege analysis, access certification, and risk detection for enterprise customers

What You'll Do

  • Entitlement Scanning: Build and extend connectors that enumerate identities (users, groups, service accounts, computers) and resource-level permissions (ACLs, role assignments, sharing links) across on-prem and SaaS data sources, handling per-connector quirks like SID resolution, inheritance breakage, and nested group membership
  • Scale & Concurrency: Design entitlement pipelines that safely parallelize across large tenants — correctly handling shared state, batching, and checkpointing so a scan of hundreds of thousands of principals and files can pause, resume, and recover without data loss or duplication
  • Data Modeling: Own the mapping from raw connector output to normalized entitlement records, and from those records into our identity graph — designing node/edge structures that represent principals, resources, and access grants (including sharing links and group-inherited access) in a way that supports fast traversal at scale
  • Multi-Store Architecture: Work across the full data path — Elasticsearch for search-driven access, Databricks/Delta for large-scale analytical joins, and a Neptune-backed graph for relationship queries — making deliberate tradeoffs about what gets synced where, and keeping those stores consistent as data volume grows
  • Entitlement-Activity Correlation: Build the pipelines that join static entitlements against observed activity logs to answer "who can access this, and who actually does" — the core signal behind over-permission detection and access-risk scoring
  • Reliability & Correctness: Instrument and test for the failure modes unique to entitlement data — partial scans, malformed ACLs, race conditions in concurrent principal writes, and inconsistent state between graph and source-of-truth stores

What You'll Bring

  • 6+ years of professional software engineering experience, with meaningful time spent on identity/access systems, security data pipelines, or large-scale distributed data processing
  • Strong Go, Java, or Python skills, with direct experience writing concurrent/parallel data pipelines (goroutines, worker pools, or equivalent) and reasoning about race conditions and shared state
  • Experience with graph databases or graph query languages (Gremlin, Cypher, or similar) and modeling relationship-heavy data
  • Familiarity with Elasticsearch/OpenSearch and at least one large-scale analytical store (Databricks, Snowflake, BigQuery, Redshift)
  • Understanding of identity and access concepts — RBAC, ACLs, group membership

Bonus Skills

  • Experience with Microsoft Graph API, SharePoint REST APIs, or ActiveDirectory/LDAP-based identity systems
  • Familiarity with AWS Neptune, TinkerPop/Gremlin, or other graph-native databases at production scale
  • Background in DSPM, CIEM, IAM governance, or data security posture tooling
  • Experience designing multi-tenant systems with per-tenant data isolation across search, analytical, and graph store

What you'll get

  • Paid vacation starting at 15 days per year and increasing to 20 or 25 days based on tenure, with 4 additional global VeeaMe Days and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental leave that includes 3 weeks for all parents and 12 weeks for birthing parents
  • Medical, dental, and vision coverage from day one
  • Mental health support, therapy sessions, and digital wellness tools
  • RRSP retirement plan with matching contributions
  • Fertility support, plus 24 paid volunteer hours through Veeam Cares
  • AirVet: 24/7 virtual veterinary care at no cost
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning

Compensation Transparency

Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, and skills. Offers are typically made below the midpoint of the range.

Pay Range
$162,300$301,400 CAD

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing. 

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

Apply

Jobs for you 

Find your fit. Discover roles where bold ideas, real impact, and career-defining growth come together.

More jobs

Related content

Sign up for job alerts

Don't see what you’re looking for? Sign up and we'll notify you when roles become available.