14 hours ago
Base Salary
$101k - $158k/yr
Responsibilities
- Own the technical roadmap and architecture for enterprise Identity & Access Management with Okta as a core platform.
- Architect and improve Okta SSO, authentication, lifecycle automation, Workflows, Identity Governance, and Access Requests.
- Design reliable onboarding, role-change, and offboarding processes for employees, contractors, partners, and other populations.
- Build integrations between Okta and systems including Workday, Google Workspace, Slack, GitHub, and Atlassian.
- Drive identity automation using Okta Workflows, APIs, scripting, Terraform, and related engineering tools.
- Lead access reviews, access requests, role-based access, approval workflows, entitlement management, least-privilege controls, and SOX-related processes.
- Implement authentication, federation, and provisioning solutions using SAML, OIDC, OAuth, SCIM, MFA, and related standards.
- Design identity solutions for partners, resellers, service accounts, machine identities, and other non-standard access needs.
- Serve as a senior escalation point, lead root cause analysis, establish engineering standards, and reduce manual identity administration.
- Mentor engineers and build reusable patterns, documentation, operational resilience, and independent backup coverage.
Requirements
- Deep hands-on Okta expertise in complex enterprise environments, including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance.
- Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization.
- Experience automating employee onboarding, role changes, and offboarding using an HRIS such as Workday as the authoritative employee-data source.
- Strong experience with identity governance, access reviews, entitlement management, access requests, role-based access control, and least privilege.
- Strong scripting and automation skills using Python, PowerShell, or similar languages.
- Strong API integration experience connecting identity platforms with enterprise systems.
- Experience with Terraform or another infrastructure-as-code framework and with converting manual identity administration into scalable, auditable processes.
- Experience supporting IAM controls in a SOX-regulated or similarly controlled environment.
- Ability to lead complex cross-functional IAM initiatives without formal people-management authority and communicate architecture, technical decisions, and risk to technical and non-technical audiences.
- Preferred qualifications include Okta certifications, Git-based workflows or CI/CD practices for identity or infrastructure changes, familiarity with Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password, external identity architecture experience, and experience with service accounts, machine identities, workload identities, or automated audit evidence.
Benefits
- Hybrid work arrangement with a curated in-office employee experience.
- Competitive compensation that may include equity grants of restricted stock units.
- Retirement and Employee Stock Purchase Plans.
- Flexible paid time off and comprehensive medical, dental, vision, life, and disability benefits.
- Fertility benefits and equal paid parental leave.
- Professional development through career pathing, learning platforms, and a yearly learning stipend.
- Volunteer opportunities, donation matching, and Employee Resource Groups.
About Braze
Braze builds a customer engagement platform used by marketing teams to orchestrate cross-channel messaging across mobile, email, web, and more. The company sells its software via SaaS subscriptions with analytics, segmentation, and journey orchestration. Founded in 2011 and headquartered in New York, Braze is a public company (NASDAQ: BRZE) with global offices.
