Назад
4 дня назад

Staff Identity Governance and Access Engineer (Cybersecurity)

161 000 - 221 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Identity Governance and Access Engineer (Okta IGA/PAM/ISPM): Building and operating identity governance, privileged access, and identity security posture capabilities for Okta's workforce with an accent on lifecycle automation, RBAC, Workday integration, and zero standing privilege. Focus on designing JML workflows, JIT and break-glass access, access certifications, and telemetry that reduce standing privilege and improve security posture.

Location: Bellevue, Washington; Chicago, Illinois; or Washington, DC. Must work on U.S. soil and qualify as a U.S. person.

Annual base salary: $161,000–$221,000 USD, plus potential equity, bonus, and benefits.

Company

Okta provides identity and access management infrastructure that helps organizations secure human and AI identities.

What you will do

  • Own the architecture and implementation of Okta Identity Governance, including access requests, entitlement structures, and certification campaigns.
  • Design birthright provisioning, RBAC, and joiner/mover/leaver lifecycle processes across the enterprise.
  • Drive Workday integration architecture, attribute strategy, reconciliation, and real-time termination synchronization.
  • Lead privileged access, identity security posture management, zero standing privilege, JIT elevation, break-glass access, and administrative tiering initiatives.
  • Build Okta Workflows automation and establish PAM and ISPM metrics for standing-privilege reduction, stale-access cleanup, and operational effectiveness.
  • Provide technical leadership through design reviews, mentorship, documentation, executive communication, and escalation support.

Requirements

  • 4+ years of advanced experience administering enterprise IGA, PAM, or ISPM platforms.
  • Production experience designing birthright provisioning and RBAC architectures.
  • Production experience with OPA or equivalent PAM tooling, including zero standing privilege, JIT access, break-glass design, and admin tiering.
  • Knowledge of SAML, OIDC, OAuth 2.0, SCIM, identity lifecycle management, and role- or attribute-based access control.
  • Experience with SOX and compliance-critical environments, including audit evidence, segregation of duties, and access certification integrity.
  • Must be a U.S. person working on U.S. soil; working on a U.S. visa does not qualify.

Nice to have

  • Experience governing non-human identities, service accounts, API tokens, secrets, AI agents, or workload identities.
  • Familiarity with ServiceNow, Jira, Okta certifications, REST APIs, JSON, webhooks, and Workday-to-IdP integrations.
  • Experience with SOC 2, ISO 27001, HIPAA, or GDPR audits.

Culture & Benefits

  • In-person onboarding designed to accelerate impact and build connections.
  • Health, dental, and vision insurance; 401(k); flexible spending account; PTO; and parental leave.
  • Equity and bonus opportunities may be available.
  • Programs focused on well-being, social impact, talent development, and community.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →