Назад
Company hidden
5 дней назад

Lead IAM Engineer (Okta)

104 000 - 164 000CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
France/UK/Singapore +10 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead IAM Engineer (Okta): Architecting and automating a secure enterprise identity ecosystem centered on Okta, identity lifecycle, access governance, and integrations with an accent on reliable onboarding, role changes, offboarding, and infrastructure-as-code practices. Focus on designing federated authentication and provisioning, strengthening least-privilege controls and SOX governance, and solving complex identity failures across enterprise systems.

Location: Toronto, Canada; hybrid

Salary: CA$104,000–CA$164,000 per year at the start of employment; expected OTE of CA$115,000–CA$182,000 per year including bonus or commission.

Company

hirify.global is a customer engagement platform that helps brands deliver personalized experiences through cross-channel messaging, journey orchestration, AI-powered decisioning, and optimization.

What you will do

  • Own the technical roadmap and architecture for enterprise identity and access management, with Okta as the core platform.
  • Design and improve Okta SSO, authentication, lifecycle management, Workflows, Identity Governance, and Access Requests.
  • Build reliable onboarding, role-change, and offboarding processes for employees, contractors, partners, applications, and services.
  • Integrate Okta with Workday, Google Workspace, Slack, GitHub, Atlassian, MDM platforms, and other enterprise systems.
  • Drive automation through Okta Workflows, APIs, scripting, Terraform, infrastructure as code, automated validation, and controlled deployment.
  • Lead access governance, SOX controls, authentication standards, complex incident resolution, documentation, engineering standards, and mentoring.

Requirements

  • Deep hands-on Okta experience in a complex enterprise environment, including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance.
  • Advanced knowledge of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization.
  • Experience automating employee onboarding, role changes, and offboarding using an HRIS such as Workday.
  • Strong identity governance, API integration, scripting, and automation experience using Python, PowerShell, or similar tools.
  • Experience with Terraform or another infrastructure-as-code framework and with SOX-regulated or similarly controlled environments.
  • Ability to lead cross-functional IAM initiatives, communicate architecture and risk clearly, and mentor engineers without formal management authority.

Nice to have

  • Okta certifications, including Administrator, Consultant, Developer, or Identity Governance credentials.
  • Experience with Git-based workflows, CI/CD, partner or B2B identity architectures, service accounts, machine identities, or workload identities.
  • Familiarity with Google Workspace, Slack, GitHub, Atlassian, Kandji, Jamf, Zscaler, or 1Password.

Culture & Benefits

  • Hybrid ways of working with a curated in-office experience focused on community, collaboration, and innovation.
  • Competitive compensation with potential equity grants, retirement and employee stock purchase plans.
  • Flexible paid time off and comprehensive medical, dental, vision, life, and disability benefits.
  • Fertility benefits, equal paid parental leave, professional development, formal career pathing, learning platforms, and a yearly learning stipend.
  • Employee Resource Groups, volunteer opportunities, donation matching, and an inclusive workplace culture.

Hiring process

  • AI-assisted tools may support application screening, interview scheduling, recording, and interview-note summaries.
  • Recruiting teams remain responsible for hiring decisions, with options to request an alternative or manual review process where applicable.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →