Skip to content
CrusoeCrusoe

Senior Systems Engineer - IAM

Senior Systems Engineer manages Okta-based identity and access management, builds automation workflows with Workato and Lumos, implements RBAC and security policies, troubleshoots complex issues, and integrates applications. Requires 5+ years experience, Okta expertise, scripting skills, and bachelor's degree.

About the job

What You’ll Be Working On

  • Managing advanced Okta functionality, including Device Trust, Okta Expression Language, and complex identity lifecycle management
  • Implementing and maintaining RBAC best practices and adaptive security policies to ensure global consistency in access governance
  • Building automated workflows using Workato, Okta Workflows, and Lumos to eliminate manual processes and improve operational efficiency
  • Planning and executing application integrations (SAML, OIDC, OAuth) and system changes with minimal disruption to business operations
  • Partnering with IAM leadership and integration engineers to connect business systems and support feature adoption across the IT ecosystem
  • Acting as a Tier 2 escalation point for complex access issues, supporting the Service Desk and broader infrastructure needs
  • Mentoring and training Service Desk team members, developing documentation and SOPs to enable independent execution of common IAM tasks
  • Participating in global team collaboration, including occasional off-hours syncs to support distributed operations

What You’ll Bring to the Team

  • 5+ years of experience in Systems Engineering or Identity & Access Management, with strong expertise in Okta administration and identity lifecycle management
  • Deep knowledge of Okta’s security capabilities; Okta Administrator or Consultant certifications are strongly preferred
  • Experience with Lumos or similar identity governance platforms
  • Proven ability to build automation workflows using tools such as Workato or Okta Workflows
  • Strong troubleshooting skills, including diagnosing authentication issues, API failures, and access-related incidents. Must be fluent in interacting with REST APIs and using scripting languages (Python, PowerShell, or similar) to troubleshoot failures or perform bulk operations
  • Solid understanding of RBAC, identity governance, PAM (Privileged Access Management) rollout and strategy, and zero-trust security principles
  • Strong communication skills with the ability to translate technical concepts into clear documentation and processes
  • Familiarity with Google Workspace Enterprise (organizational units, policies, and security configurations)
  • Bachelor’s or Master’s degree in Computer Science, Engineering, or equivalent professional experience

Bonus Points

  • Strong planning, communication, and change management skills
  • Experience working in fast-paced, global environments with distributed teams

Compensation

Compensation Range: up to $165,000 - $200,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's knowledge, education, and abilities, as well as internal equity and alignment with market data.

Skills

Okta, RBAC, Workato, Okta Workflows, Lumos, SAML, OIDC, OAuth, REST APIs, Python, PowerShell, Google Workspace, Pam, Identity Governance

Upstart

Upstart

United States

Senior Application Security Engineer
$167k+/yrRemote5+ YOESecurity Engineering

Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.

GitLab

GitLab

United States
Senior Manager, Product Security Engineering
$168k+/yrRemote5+ YOESecurity Engineering

Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.

Censys

Censys

United States

Research Systems Analyst
$170k+/yrRemote6+ YOESecurity Engineering

Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.

Flex

Flex

United States

Senior Software Engineer, Security
$170k+/yrRemote5+ YOESecurity Engineering

Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.

Wiz

Wiz

United States

Compliance Engineer - Public Sector
$174k+/yrRemote6+ YOESecurity Engineering

Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.