Назад
1 день назад

Staff Engineer (Identity & Access Management)

Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Australia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Engineer (Identity & Access Management) (Okta, Cloud IAM): Architecting and implementing enterprise identity fabric, adaptive MFA, federation, and cloud IAM guardrails across AWS, GCP, and Azure with an accent on automation, zero-trust security, and AI identity governance. Focus on securing machine identities and AI agents, designing API-based identity workflows, mitigating session hijacking, and aligning controls with SOC 2, ISO 27001, and FedRAMP.

Location: Brisbane, Canberra, Melbourne, or Sydney, Australia. Must be a U.S. citizen and work within the U.S. boundary to meet FedRAMP Level 2 requirements. Hybrid and remote work arrangements are indicated; occasional travel is required.

Company

Okta provides identity and access management infrastructure for organizations, including security for human and AI-driven identities.

What you will do

  • Lead internal adoption of Okta capabilities as part of the Customer Zero program and provide technical feedback to product engineering teams.
  • Architect and implement enterprise Okta tenant lifecycle management, policy design, adaptive MFA, and SAML/OIDC federation.
  • Define cloud IAM guardrails across AWS, GCP, and Azure and build API-based automation pipelines.
  • Govern AI agents, machine identities, and service-to-service authentication within the enterprise identity layer.
  • Mentor engineers, lead IAM design reviews, establish technical standards, and communicate operational KPIs.
  • Partner with Security, Audit, and Compliance teams to align identity controls with SOC 2, ISO 27001, and FedRAMP.

Requirements

  • 3+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions.
  • Deep expertise with Okta Identity Engine, directory integrations, advanced policies, Workflows, and platform APIs.
  • Advanced knowledge of OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, and passkeys.
  • Experience with Terraform, Okta Workflows, multi-cloud IAM, and machine-to-machine authentication.
  • Background in session security, token management and revocation, continuous access evaluation, and mitigating session hijacking.
  • U.S. citizenship and work within the U.S. boundary are required. Demonstrated technical leadership, mentoring, and experience aligning controls with enterprise compliance frameworks are also required.

Culture & Benefits

  • In-person onboarding is designed to accelerate impact and build connection with colleagues.
  • Access to well-being support and talent development programs.
  • Opportunities to participate in social-impact initiatives.
  • Occasional travel may be required.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →