Okta

Staff Identity Governance and Access Engineer

Okta
Apply
5 hours ago
Chicago, IL, USA +2 moreStaff+

Base Salary

$161k - $221k/yr

Responsibilities

  • Own end-to-end Okta Identity Governance architecture, including access request workflows, entitlement structures, resource collections, and certification campaigns.
  • Lead birthright provisioning, RBAC, and joiner/mover/leaver lifecycle strategy across the enterprise.
  • Design Workday integration architecture, including scheduled reconciliation, real-time termination sync, and attribute sets for access rules.
  • Design and harden mover/leaver automation, including attribute-driven group re-evaluation and stale-access decommissioning.
  • Lead Okta Privileged Access, Identity Security Posture Management, and Zero Standing Privilege initiatives, including JIT elevation, privileged sessions, break-glass access, vulnerability detection, and system tiering.
  • Own PAM and ISPM telemetry and KPIs covering standing-privilege reduction, JIT adoption, stale-access cleanup, and break-glass testing.
  • Build and maintain Okta Workflows automation for IGA and PAM access requests, approvals, and remediation.
  • Mentor engineers, review designs, serve as a technical escalation point, and communicate risks, roadmaps, and updates to leadership.

Requirements

  • At least 4 years of direct, advanced experience managing and administering enterprise IGA, PAM, or ISPM platforms.
  • Hands-on production experience designing and deploying birthright provisioning models and RBAC architectures.
  • Production experience with OPA or equivalent PAM tooling, including Zero Standing Privilege, JIT access, break-glass design, and administrative tiering.
  • Production experience with ISPM tools that integrate with EDR solutions such as CrowdStrike Falcon.
  • Knowledge of SAML, OIDC, OAuth 2.0, SCIM, and role- and attribute-based access control.
  • Experience owning end-to-end joiner/mover/leaver technical designs from documentation through production rollout.
  • Experience in SOX and compliance-critical environments, including audit evidence, segregation of duties, and access certification integrity.
  • Ability to work independently, drive initiatives, and communicate updates, risks, and roadmaps to executives.
  • Preferred experience governing non-human identities, including service accounts, API tokens, secrets, AI agents, and workload identities.
  • Familiarity with ServiceNow and Jira-based service request intake for IGA, PAM, and ISPM operations.
  • Preferred Okta Certified Administrator, Okta Certified Consultant, or Okta Workflows Specialist certification.
  • Experience with REST APIs, JSON parsing, webhooks, Workday-to-identity-provider integrations, and real-time versus scheduled reconciliation.
  • Experience supporting SOC 2, ISO 27001, HIPAA, or GDPR audits is preferred.
  • Must work on U.S. soil and qualify as a U.S. person under the stated requirements.

Benefits

  • Health, dental, and vision insurance.
  • 401(k) and flexible spending account.
  • Paid leave, including PTO and parental leave.
  • Equity and bonus opportunities where applicable.
  • Immersive in-person onboarding designed to connect employees with the team and mission.
  • Well-being support, social impact programs, talent development, and community-building initiatives.

Categories

Okta

About Okta

5,001-10,000 employees

Okta secures AI. Okta is The World’s Identity Company. Freeing everyone to safely use any technology—anywhere, on any device or app.

Contact me