TL;DR
Identity Security Engineer (Okta & Identity Governance): Designing, building, and operating the Okta platform for identity governance and security controls across the enterprise with an accent on Okta Identity Governance (OIG) modules, lifecycle automation, and identity-centric security. Focus on developing custom workflows, enforcing Segregation of Duties (SOD) rules, designing access certification campaigns, and integrating Okta with SIEM for threat monitoring.
Location: Bangkok Based, relocation provided to Thailand.
Company
hirify.global is a global travel company, part of Booking Holdings, connecting people to destinations and experiences worldwide.
What you will do
- Design, deploy, and maintain Okta Identity Governance modules including Access Requests, Certifications, and Entitlement Management.
- Develop and maintain custom workflows and policies within Okta IGA to enforce Segregation of Duties (SOD) rules.
- Manage Okta organization architecture (Groups, Rules, Policies) using Infrastructure-as-Code (Terraform).
- Build and maintain Okta Workflows for lifecycle automation, custom notifications, and advanced logic.
- Implement and enforce Multi-Factor Authentication (MFA) policies, Risk-Based Authentication, and Global Session Policies.
- Partner with GRC and Audit teams to support SOX and NIST requirements, ensuring measurable and auditable identity controls.
Requirements
- 6+ years of hands-on experience operating Okta in a production environment.
- Experience with Okta Identity Governance (OIG), including setting up Access Requests, Review Campaigns, and Entitlements.
- Proficiency with Terraform (specifically the Okta Provider) for managing configuration as code.
- Ability to write scripts in Python or JavaScript/TypeScript for custom API integrations.
Culture & Benefits
- Be part of a diverse team of over 7,000 people from 90 countries.
- Work in a data and technology-driven culture that fosters curiosity and innovation.
- Opportunity to help build travel solutions for the world.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →