5 hours ago
Chicago, IL, USA +2 moreStaff+
Base Salary
$161k - $221k/yr
Responsibilities
- Own end-to-end Okta Identity Governance architecture, including access request workflows, entitlement structures, resource collections, and certification campaigns.
- Lead birthright provisioning, RBAC, and joiner/mover/leaver lifecycle strategy across the enterprise.
- Design Workday integration architecture, including scheduled reconciliation, real-time termination sync, and attribute sets for access rules.
- Design and harden mover/leaver automation, including attribute-driven group re-evaluation and stale-access decommissioning.
- Lead Okta Privileged Access, Identity Security Posture Management, and Zero Standing Privilege initiatives, including JIT elevation, privileged sessions, break-glass access, vulnerability detection, and system tiering.
- Own PAM and ISPM telemetry and KPIs covering standing-privilege reduction, JIT adoption, stale-access cleanup, and break-glass testing.
- Build and maintain Okta Workflows automation for IGA and PAM access requests, approvals, and remediation.
- Mentor engineers, review designs, serve as a technical escalation point, and communicate risks, roadmaps, and updates to leadership.
Requirements
- At least 4 years of direct, advanced experience managing and administering enterprise IGA, PAM, or ISPM platforms.
- Hands-on production experience designing and deploying birthright provisioning models and RBAC architectures.
- Production experience with OPA or equivalent PAM tooling, including Zero Standing Privilege, JIT access, break-glass design, and administrative tiering.
- Production experience with ISPM tools that integrate with EDR solutions such as CrowdStrike Falcon.
- Knowledge of SAML, OIDC, OAuth 2.0, SCIM, and role- and attribute-based access control.
- Experience owning end-to-end joiner/mover/leaver technical designs from documentation through production rollout.
- Experience in SOX and compliance-critical environments, including audit evidence, segregation of duties, and access certification integrity.
- Ability to work independently, drive initiatives, and communicate updates, risks, and roadmaps to executives.
- Preferred experience governing non-human identities, including service accounts, API tokens, secrets, AI agents, and workload identities.
- Familiarity with ServiceNow and Jira-based service request intake for IGA, PAM, and ISPM operations.
- Preferred Okta Certified Administrator, Okta Certified Consultant, or Okta Workflows Specialist certification.
- Experience with REST APIs, JSON parsing, webhooks, Workday-to-identity-provider integrations, and real-time versus scheduled reconciliation.
- Experience supporting SOC 2, ISO 27001, HIPAA, or GDPR audits is preferred.
- Must work on U.S. soil and qualify as a U.S. person under the stated requirements.
Benefits
- Health, dental, and vision insurance.
- 401(k) and flexible spending account.
- Paid leave, including PTO and parental leave.
- Equity and bonus opportunities where applicable.
- Immersive in-person onboarding designed to connect employees with the team and mission.
- Well-being support, social impact programs, talent development, and community-building initiatives.
Categories
About Okta
Okta secures AI. Okta is The World’s Identity Company. Freeing everyone to safely use any technology—anywhere, on any device or app.
