Okta Administrator and Automation Engineer

Full-time Hiring Now

About the Company

The company’s identity environment spans ADP, Okta, Active Directory and SSO-integrated applications. The work includes automated employee access changes, access governance, phishing-resistant MFA and audit evidence for SOC 2 and ISO 27001.

About the Role

Own the Okta identity platform end to end in a hands-on engineering role focused on automation rather than helpdesk or IT support. You’ll administer Okta day to day, automate access changes when employees join, change roles or leave, and strengthen access controls across SSO-integrated applications. You’ll also keep app and user inventories accurate and ready for audit.

Location: Available to work during US Hours (8:00 am PST to 6:00 pm PST - no overtime required) or India Hours (8:00 am IST to 6:00 pm IST)

Key Responsibilities

Identity Lifecycle and HR Integration - Own the ADP, Okta , Active Directory integration so employee records stay in sync automatically. - Automate joiner, mover and leaver workflows, including same-day offboarding and access removal. - Map and maintain Okta profile attributes, and make sure they push correctly to downstream apps. Manage the Okta user schema and profile mappings, and maintain each attribute's source of truth. SSO and App Integration - Set up single sign-on (SAML, OIDC) for new and existing apps. - Set up automatic user provisioning (SCIM) for those apps. - Keep a complete app inventory. Retire unused, duplicate or orphaned app integrations. - Track app owners, assignment methods and renewal of SAML certificates. Access Control and Governance - Design and maintain access groups based on role and department, plus group rules that assign apps automatically. - Enforce least-privilege access, so people get only what their role needs. - Run periodic access reviews and certifications with app owners. - Manage Okta admin roles and separation of duties, and review privileged access regularly. - Own GitHub access management, including SSO, team-to-group mapping, and onboarding and offboarding. Policies and Security - Maintain sign-on, password, MFA, authenticator and app-level authentication policies. - Review policies regularly and consolidate redundant or outdated ones. - Roll out phishing-resistant MFA (Okta FastPass, FIDO2/WebAuthn) and device assurance policies. - Manage network zones, behavior detection and ThreatInsight settings. - Work with Security on incident response, such as suspicious sign-ins, session revocation and account lockouts. Hygiene and Cleanup - Find and clean up stale, inactive and orphaned user accounts in Okta and AD. - Inventory and govern service accounts: assign owners, rotate credentials, and monitor them. - Audit and manage external or guest accounts and contractor access, with expiry dates. - Maintain Okta API tokens: track ownership and rotate or revoke them. Automation and Workflows - Build and maintain Okta Workflows for repetitive tasks such as account deactivation, notifications, group syncs and reporting. - Use the Okta API, and scripting to run bulk operations and generate reports. - Integrate Okta with ITSM and collaboration tools such as Jira and Slack for access requests and approvals. Active Directory - Manage Okta AD Agents, including their health, upgrades and redundancy. - Plan for gradually reducing the company's reliance on AD where it makes sense. Backup, Monitoring and Compliance - Own Okta configuration backups and config-as-code. Terraform and Okta configuration tools are a plus. - Maintain a disaster recovery plan for the identity platform. - Monitor the Okta System Log and stream logs to the SIEM. Set alerts for high-risk events. - Provide evidence for SOC 2, ISO 27001 and internal audits. - Keep runbooks, architecture diagrams and standard operating procedures (SOPs) current. Operations and Support - Act as the escalation point for authentication, MFA and provisioning problems. - Evaluate new Okta features and releases, and plan how to adopt them. - Train the IT helpdesk on Okta procedures.

Required Qualifications

  • From 7 years primarily administering Okta identity and access management (IAM) systems, including 2+ years with Active Directory : users, groups, OUs, GPOs and Okta AD Agent integration.
  • Hands-on experience with SAML, OIDC/OAuth 2.0, SCIM and MFA.
  • Experience integrating an HR system with Okta (ADP preferred) for automated user account creation.
  • Proven 3+ years experience building Okta Workflows or Python and using the Okta API.
  • Solid grasp of least privilege, role-based access control (RBAC) and access governance.
  • Certifications: Okta Certified Administrator.