# Senior IAM Engineer

**Company:** [Komodo Health](https://hotfix.jobs/companies/komodo-health)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $150k – $210k/yr
**Experience:** 5+ years
**Skills:** Okta, Python, Ruby, Terraform, SAML, OIDC, OAuth, SCIM, Workato, RBAC, abac, MFA, Zero Trust, Workday, AWS
**Posted:** 2026-07-22

> Senior IAM Engineer building integration and orchestration infrastructure to secure AI and data systems at Komodo Health. Design automated identity lifecycle processes, RBAC/ABAC, SSO/MFA, and custom automations with Okta, Workato, and Python while ensuring SOC2/HIPAA compliance.

## Job Description

## Responsibilities
- Design and maintain automated onboarding, offboarding, and departmental transfer processes across ecosystem (WorkDay, Okta, Google Workspace, etc.).
- Build and optimize complex, multi-step automation flows; maintain and grow iPaaS (Workato) environment, treating "Integrations as a Product."
- Build resilient, scalable "recipes" that move data across the enterprise while maintaining strict IAM governance utilizing Okta Workflows.
- Implement and enforce Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models.
- Manage SSO (SAML/OIDC) and MFA configurations.
- Ensure all access remains compliant with SOC2/HIPAA/GDPR standards through regular access reviews and audit logging.
- Develop custom scripts (Python, Perl, Ruby, etc.) and API integrations to bridge gaps where out-of-the-box connectors are unavailable.
- Secure the "Data Perimeter" for AI Infrastructure and Data Infrastructure; manage identity lifecycle for AI Agents and Service Accounts with least-privileged access.
- Collaborate with HR, Finance, Sales Ops and other teams to identify bottlenecks in the lead-to-revenue lifecycle and solve them through identity-driven automation.
- Collaborate with cross-functional teams to improve provisioning/deprovisioning processes.
- Integrate and manage IdPs within the IAM system.
- Handle and streamline access requests.
- Develop and implement IAM policies and procedures.
- Respond to ad-hoc requests.

## Requirements
- 5–8+ years of experience in Identity and Access Management, including significant hands-on expertise with Okta (including OIE & OIG).
- Proficiency in Python, Ruby or other languages for automating repetitive tasks and handling large-scale data imports/exports.
- Automation mindset with proven ability to build event-driven flows, use custom API connectors, and handle error logic.
- Comfortable working with RESTful APIs, JSON, and Webhooks.
- Experience using Terraform or Github to manage identity providers (Infrastructure as Code).
- Understanding of Zero Trust architecture and Privileged Access Management (PAM) tools like CyberArk, BeyondTrust, etc.
- Strong understanding of identity lifecycle management, directory services, SSO, MFA, SCIM provisioning, and federation (SAML, OIDC, OAuth).
- Proven experience partnering with HR, Finance, Compliance, and other cross-functional teams to design and implement IAM & Enterprise solutions.
- Demonstrated ability to streamline and automate processes using automation.
- Experience with auditing, governance, and access certification processes.
- Excellent problem-solving, communication, and stakeholder management skills.

## Nice-to-Haves
- Experience with Workato or similar Integration Orchestrator tools such as Zapier, Snaplogic or Merge.
- Experience with Okta Workflows.
- Certifications: Workato or Okta Certified Professional/Administrator/Consultant.
- Experience integrating IAM with HR systems (e.g., Workday).
- Knowledge of compliance requirements related to IAM.
- Background in cloud platforms (AWS, GCP, Azure) and IAM integrations.
- Experience with IAM tools such as Auth0, or Azure AD.

## Compensation
- San Francisco Bay Area and New York City: $173,000–$210,000 USD
- All Other US Locations: $150,000–$180,000 USD
- Eligible for performance-based bonuses, equity awards, comprehensive benefits including health, dental, vision insurance, flexible time off, 401(k) match, disability and life insurance.

## Similar roles

- [Fraud Strategy Manager / Senior Manager (Onboarding)](https://hotfix.jobs/jobs/23b2e532-412b-4605-8814-e5066cadbe78) - Cardless - San Francisco, CA - $150k – $210k/yr
- [Senior Product Security Engineer](https://hotfix.jobs/jobs/835c4ad3-9606-43f0-8fef-af9ce5b6b455) - Rippling - San Francisco, CA - $151k – $280k/yr
- [Senior Engineer, Security](https://hotfix.jobs/jobs/6bab40d2-5ef3-4633-b280-4b1b41772243) - Grow Therapy - Remote - $152k – $250k/yr
- [Senior Developer, Product Security](https://hotfix.jobs/jobs/bc5c951c-0b14-43d4-85b0-d9db2f3ee585) - 1Password - Remote - $153k – $214k/yr
- [Senior Security Research Scientist](https://hotfix.jobs/jobs/cc7a76ad-0132-4842-9ec4-6a7a1a9c1ab3) - Censys - Remote - $153k – $212k/yr

**Apply:** https://hotfix.jobs/jobs/a54619ea-22d6-4f1e-ab0e-bf3db137b74b
**Canonical:** https://hotfix.jobs/jobs/a54619ea-22d6-4f1e-ab0e-bf3db137b74b