Назад
5 дней назад

Staff Identity Engineer (Cybersecurity)

161 000 - 221 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Identity Engineer (IAM/Cybersecurity): Architecting and implementing enterprise identity fabrics, Okta tenants, cloud IAM guardrails, and automated identity workflows with an accent on adaptive MFA, federation, machine identities, and AI security. Focus on designing zero-trust session controls, governing service-to-service authentication, meeting SOC 2, ISO 27001, and FedRAMP requirements, and mentoring engineers.

Location: Bellevue, Washington; Chicago, Illinois; or Washington, DC. The employee must be on U.S. soil and be a U.S. person.

Salary: $161,000–$221,000 annual base salary, plus equity where applicable, bonus, and benefits.

Company

Okta provides identity and access management infrastructure designed to secure human, machine, and AI identities.

What you will do

  • Drive internal adoption and technical validation of new Okta capabilities through the Customer Zero program.
  • Architect and implement enterprise Okta tenant lifecycle management, policies, adaptive MFA, federation, and API-based automation.
  • Define cloud IAM guardrails across AWS, GCP, and Azure, including machine-to-machine and service-to-service authentication.
  • Mentor engineers, lead design reviews, and establish identity engineering standards.
  • Partner with Security, Audit, and Compliance teams to align identity controls with SOC 2, ISO 27001, and FedRAMP.
  • Govern AI agents, machine identities, session security, token management, and continuous access evaluation.

Requirements

  • 4+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions.
  • Deep expertise with Okta Identity Engine, directory integrations, advanced policies, Workflows, and platform APIs.
  • Advanced knowledge of OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, and passkeys.
  • Experience with Terraform, Okta Workflows, multi-cloud IAM guardrails, and service-to-service authentication.
  • Background in session lifecycle security, token revocation, continuous access evaluation, technical leadership, and mentorship.
  • Must be on U.S. soil and qualify as a U.S. person; working on a U.S. visa does not qualify. Occasional travel is required.

Culture & Benefits

  • In-person onboarding is designed to accelerate impact and build connection from the first day.
  • Benefits include health, dental, and vision insurance; 401(k); flexible spending account; and paid leave including PTO and parental leave.
  • Equity and bonus opportunities may be available in accordance with applicable plans and policies.
  • The global community spans more than 20 offices and supports talent development, connection, and social impact.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →