Staff Identity Engineer
Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.
About the job
Responsibilities
- Lead Customer Zero adoption of Okta capabilities, partnering with internal stakeholders and product engineering teams.
- Own the architecture, policy design, adaptive MFA, federation, and lifecycle management of enterprise Okta tenants.
- Architect and enforce cloud IAM guardrails across AWS, Google Cloud, and Azure.
- Build API-based pipelines and automation for complex identity workflows.
- Mentor engineers, review IAM designs, and establish technical standards.
- Partner with Security, Audit, and Compliance teams to align identity controls with SOC 2, ISO 27001, and FedRAMP requirements.
- Govern AI agents, machine identities, and service-to-service authentication.
- Establish operational KPIs and communicate technical milestones to leadership.
Requirements
- 4+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions.
- Deep expertise with enterprise Okta environments, including Okta Identity Engine, directory integrations, advanced policies, Okta Workflows, and platform APIs.
- Advanced knowledge of OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, and passkeys.
- Experience defining identity controls as code using Terraform and Okta Workflows.
- Experience designing multi-cloud IAM guardrails across AWS, Google Cloud, and Azure.
- Experience with machine-to-machine and service-to-service authentication.
- Knowledge of session lifecycle security, token management and revocation, and continuous access evaluation.
- Experience mentoring engineers, leading design reviews, and establishing engineering best practices.
- Experience aligning identity controls with SOC 2, ISO 27001, and FedRAMP.
- Must work on U.S. soil and qualify as a U.S. person under applicable federal definitions.
- Occasional travel required.
Compensation
- Annual base salary: $161,000–$221,000 USD.
- Equity, bonus, health, dental and vision insurance, 401(k), flexible spending account, paid leave, PTO, and parental leave may be available under applicable plans and policies.
Skills
Okta, Identity And Access Management, Okta Identity Engine, Okta Workflows, Terraform, AWS, GCP, Azure, OIDC, Oauth 2.0, Saml 2.0, Fido2/Webauthn, Passkeys, Zero Trust
Similar jobs
Security Engineering jobsOwn the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Staff-level security engineer leading enterprise IAM, cloud identity, AI platform access, and non-human identity governance. The role requires deep Okta, infrastructure-as-code, Python, GCP or AWS, and regulated-environment experience.