Okta2 дня назад

Staff Identity Engineer

Зарплата не указана
Bellevue

Обязанности

  • 01Drive Customer Zero Execution: Act as a key technical bridge between internal stakeholders, the Okta on Okta team, and core Product teams. Lead the early adoption of cutting-edge internal capabilities, providing rigorous technical feedback to mature products before global release
  • 02Architecture & Hands-On Implementation: Own the lifecycle, policy design, adaptive MFA, and federation (SAML, OIDC) for enterprise Okta tenants. Architect and enforce cloud IAM guardrails across AWS, GCP, and Azure, building API-based pipelines to automate complex workflows
  • 03Technical Leadership & Mentorship: Serve as a core technical anchor for the engineering team. Mentor engineers, act as a primary review authority for IAM designs, and set technical standards across the organization
  • 04Operational & Security Governance: Drive automation-first initiatives to eliminate systemic inefficiencies. Partner directly with Security, Audit, and Compliance teams to ensure identity controls natively meet audit requirements (SOC 2, ISO 27001, FedRAMP)
  • 05AI Security Integration: Drive the secure adoption of AI technologies by governing AI agents, machine identities, and service-to-service authentication within the enterprise identity layer
  • 06Cross-Functional Partnering & Metrics: Collaborate with cross-functional partners to advance identity security, establish operational KPIs, and translate complex technical milestones into actionable leadership updates

Требования

  • 014+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions
  • 02Deep expertise in managing complex enterprise Okta environments, including hands-on proficiency with Okta Identity Engine (OIE), Directory Integrations, Advanced Policies, Workflows, and Platform APIs
  • 03Advanced expertise in modern authentication and authorization standards (OIDC, OAuth 2.0, SAML 2.0) and phishing-resistant MFA paradigms (FIDO2/WebAuthn, Passkeys)
  • 04Proven experience defining identity controls as code using Terraform and Okta Workflows. Practical experience designing cloud IAM guardrails across multi-cloud environments (AWS, GCP, Azure) and M2M/service-to-service authentication
  • 05Solid background in session lifecycle security, token management/revocation strategies, and continuous access evaluations (CAEP/eSSO) to mitigate session hijacking
  • 06Demonstrated experience mentoring engineers, driving design reviews, and establishing engineering best practices across teams
  • 07Strong orientation toward automation-first design, with practical experience building identity controls that align with enterprise frameworks (SOC 2, ISO 27001, FedRAMP)
  • 08Occasional travel required as needed
  • 09U.S. soil status - the employee must be on U.S. soil, which means the 50 states, the District of Columbia, or outlying areas of the United States, as defined in Federal Acquisition Regulation (FAR) 2.101, and be a U.S. person
  • 10U.S. person status - the employee must be either a U.S. citizen as defined in 42 U.S. Code § 9102; a natural person who is a lawful permanent resident as defined in 8 U.S.C. 1101(a)(20) or who is a protected individual as defined by 8 U.S.C. 1324b(a)(3); or a U.S. national (i.e. includes citizens and non-citizens born in outlying possessions such as American Samoa and Swains Island), green card holders, refugees, and asylees

Условия

  • 01Travel: Occasional travel required as needed
  • 02Working on a U.S. visa does NOT qualify as a U.S. person
  • 03Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO)
Staff Identity Engineer · Rekru