Staff Identity Governance and Access Engineer
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
About the job
Responsibilities
- Own Okta Identity Governance (OIG) architecture, including access-request workflows, entitlement and resource-collection structures, and certification campaigns.
- Lead lifecycle, birthright provisioning, role-based access control (RBAC), and joiner/mover/leaver (JML) strategy across the enterprise.
- Drive Workday integration architecture, including scheduled reconciliation, real-time synchronization, and access-rule attributes.
- Design and harden mover/leaver automation, including role-change group re-evaluation and stale-access decommissioning.
- Lead Okta Privileged Access (OPA), Identity Security Posture Management (ISPM), and Zero Standing Privilege initiatives, including privileged sessions, just-in-time elevation, break-glass access, vulnerability detection, and system tiering.
- Establish PAM and ISPM telemetry, KPIs, and operational metrics.
- Build and maintain Okta Workflows automation for access requests, approvals, and remediation.
- Mentor engineers, review designs, serve as a technical escalation point, and communicate risks and roadmaps to leadership.
Requirements
- 4+ years of direct, advanced experience managing and administering enterprise IGA, PAM, or ISPM platforms.
- Production experience designing and deploying birthright provisioning models and RBAC architectures.
- Production experience with OPA or equivalent PAM tooling, including Zero Standing Privilege, just-in-time access, break-glass design, and administrative tiering.
- Production experience with ISPM tools integrated with EDR solutions such as CrowdStrike Falcon.
- Knowledge of SAML, OIDC, OAuth 2.0, SCIM, and role- or attribute-based access control.
- Experience owning identity lifecycle designs from design through production rollout.
- Experience in SOX and compliance-critical environments, including audit evidence, segregation of duties, and access certification integrity.
- Ability to work autonomously and communicate updates, risks, and roadmaps to executives.
- Must work on U.S. soil and qualify as a U.S. person under applicable requirements.
Nice-to-haves
- Experience governing non-human identities, including service accounts, API tokens, secrets, AI agents, and workload identities.
- Experience scaling access certification programs.
- Familiarity with ServiceNow and Jira-based service request intake.
- Okta Certified Administrator, Okta Certified Consultant, or Okta Workflows Specialist certification.
- Experience with REST APIs, JSON parsing, webhooks, and Workday-to-identity-provider integrations.
- Experience supporting SOC 2, ISO 27001, HIPAA, or GDPR audits.
Compensation and Benefits
- Annual base salary: $161,000–$221,000 USD.
- Equity, bonus, health, dental and vision insurance, 401(k), flexible spending account, paid time off, and parental leave may be available under applicable plans and policies.
Skills
Okta Identity Governance, Okta Privileged Access, Ispm, RBAC, Birthright Provisioning, SAML, OIDC, Oauth 2.0, SCIM, Okta Workflows, Workday, Servicenow, Jira, REST APIs, Crowdstrike Falcon
Similar jobs
Security Engineering jobsStaff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.
Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Staff-level security engineer leading enterprise IAM, cloud identity, AI platform access, and non-human identity governance. The role requires deep Okta, infrastructure-as-code, Python, GCP or AWS, and regulated-environment experience.