# Staff Identity Engineer

**Company:** [Okta](https://hotfix.jobs/companies/okta)
**Location:** Bellevue, WA, Chicago, IL, Washington, DC
**Role:** Security Engineering
**Salary:** $161k – $221k/yr
**Experience:** 7+ years
**Skills:** Okta, Identity And Access Management, Okta Identity Engine, Okta Workflows, Terraform, AWS, GCP, Azure, OIDC, Oauth 2.0, Saml 2.0, Fido2/Webauthn, Passkeys, Zero Trust
**Posted:** 2026-09-04

> Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.

## Job Description

## Responsibilities
- Lead Customer Zero adoption of Okta capabilities, partnering with internal stakeholders and product engineering teams.
- Own the architecture, policy design, adaptive MFA, federation, and lifecycle management of enterprise Okta tenants.
- Architect and enforce cloud IAM guardrails across AWS, Google Cloud, and Azure.
- Build API-based pipelines and automation for complex identity workflows.
- Mentor engineers, review IAM designs, and establish technical standards.
- Partner with Security, Audit, and Compliance teams to align identity controls with SOC 2, ISO 27001, and FedRAMP requirements.
- Govern AI agents, machine identities, and service-to-service authentication.
- Establish operational KPIs and communicate technical milestones to leadership.

## Requirements
- 4+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions.
- Deep expertise with enterprise Okta environments, including Okta Identity Engine, directory integrations, advanced policies, Okta Workflows, and platform APIs.
- Advanced knowledge of OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, and passkeys.
- Experience defining identity controls as code using Terraform and Okta Workflows.
- Experience designing multi-cloud IAM guardrails across AWS, Google Cloud, and Azure.
- Experience with machine-to-machine and service-to-service authentication.
- Knowledge of session lifecycle security, token management and revocation, and continuous access evaluation.
- Experience mentoring engineers, leading design reviews, and establishing engineering best practices.
- Experience aligning identity controls with SOC 2, ISO 27001, and FedRAMP.
- Must work on U.S. soil and qualify as a U.S. person under applicable federal definitions.
- Occasional travel required.

## Compensation
- Annual base salary: **$161,000–$221,000 USD**.
- Equity, bonus, health, dental and vision insurance, 401(k), flexible spending account, paid leave, PTO, and parental leave may be available under applicable plans and policies.

## Similar jobs

- [Staff Identity Governance and Access Engineer](https://hotfix.jobs/jobs/8fe7fe60-ff7a-48f4-a805-f3f100e1814f) - Okta - Bellevue, WA - $161k – $221k/yr
- [Staff Security Engineer](https://hotfix.jobs/jobs/29576103-a601-455c-a963-ce04128098e5) - Twilio - Remote - $156k – $194k/yr
- [Staff Enterprise Security Engineer, AI Security](https://hotfix.jobs/jobs/f0299624-eaec-4b80-89d9-94fde4d866e9) - Twilio - Remote - $156k – $194k/yr
- [Staff Security Researcher](https://hotfix.jobs/jobs/6b308cd8-be33-459a-b904-08e54567ad7b) - GitLab - Remote - $168k – $238k/yr
- [Staff Security Engineer, IAM](https://hotfix.jobs/jobs/f79f024d-e0b6-41b0-b434-9f047bfa2630) - GitLab - Remote - $168k – $238k/yr

**Apply:** https://hotfix.jobs/jobs/9840c62b-d314-4749-aa98-2057f5343be2
**Canonical:** https://hotfix.jobs/jobs/9840c62b-d314-4749-aa98-2057f5343be2