Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Engineer (Identity & Access Management) (Okta, Cloud IAM): Architecting and implementing enterprise identity fabric, adaptive MFA, federation, and cloud IAM guardrails across AWS, GCP, and Azure with an accent on automation, zero-trust security, and AI identity governance. Focus on securing machine identities and AI agents, designing API-based identity workflows, mitigating session hijacking, and aligning controls with SOC 2, ISO 27001, and FedRAMP.
Location: Brisbane, Canberra, Melbourne, or Sydney, Australia. Must be a U.S. citizen and work within the U.S. boundary to meet FedRAMP Level 2 requirements. Hybrid and remote work arrangements are indicated; occasional travel is required.
Company
Okta provides identity and access management infrastructure for organizations, including security for human and AI-driven identities.
What you will do
- Lead internal adoption of Okta capabilities as part of the Customer Zero program and provide technical feedback to product engineering teams.
- Architect and implement enterprise Okta tenant lifecycle management, policy design, adaptive MFA, and SAML/OIDC federation.
- Define cloud IAM guardrails across AWS, GCP, and Azure and build API-based automation pipelines.
- Govern AI agents, machine identities, and service-to-service authentication within the enterprise identity layer.
- Mentor engineers, lead IAM design reviews, establish technical standards, and communicate operational KPIs.
- Partner with Security, Audit, and Compliance teams to align identity controls with SOC 2, ISO 27001, and FedRAMP.
Requirements
- 3+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions.
- Deep expertise with Okta Identity Engine, directory integrations, advanced policies, Workflows, and platform APIs.
- Advanced knowledge of OIDC, OAuth 2.0, SAML 2.0, FIDO2/WebAuthn, and passkeys.
- Experience with Terraform, Okta Workflows, multi-cloud IAM, and machine-to-machine authentication.
- Background in session security, token management and revocation, continuous access evaluation, and mitigating session hijacking.
- U.S. citizenship and work within the U.S. boundary are required. Demonstrated technical leadership, mentoring, and experience aligning controls with enterprise compliance frameworks are also required.
Culture & Benefits
- In-person onboarding is designed to accelerate impact and build connection with colleagues.
- Access to well-being support and talent development programs.
- Opportunities to participate in social-impact initiatives.
- Occasional travel may be required.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 часа назад
Principal Identity Security Engineer
197 000 - 232 000$
14 часов назад
Security Software Engineer (Staff or Senior) (Cybersecurity)
127 000 - 249 000$
11 часов назад
Application Security Engineer (Go/TypeScript)
3 дня назад
Senior Security Engineer I, IAM
163 944 - 215 176$
5 дней назад
Principal Security Engineer, Customer Identity Management (CIAM)
1 день назад
Senior/Staff Product Security Engineer
195 000 - 260 000$