Senior Okta & IAM Automation Engineer

Full-time Hiring Now

Location: Available to work during US Hours (8:00 AM PST to 6:00 PM PST — no overtime required) or India Hours (8:00 AM IST to 6:00 PM IST)

About the Company

The company’s identity environment spans employee records, application access, and security policies. The work includes keeping access information audit-ready and providing evidence for SOC 2, ISO 27001, and internal audits.

About the Role

This is a hands-on Okta Identity Engineering role focused on automation, not a helpdesk or IT support role. You’ll own day-to-day Okta administration and improve how access is managed across the company: automating joiners, movers, and leavers, managing SSO-integrated applications, and keeping app and user inventories accurate and audit-ready. You’ll also work across Okta and Active Directory to reduce manual work.

Key Responsibilities

Identity Lifecycle and HR Integration

  • Own the ADP, Okta, and Active Directory integration so employee records stay in sync automatically.
  • Automate joiner, mover, and leaver workflows, including same-day offboarding and access removal.
  • Map and maintain Okta profile attributes, and make sure they push correctly to downstream apps.
  • Manage the Okta user schema and profile mappings, maintaining each attribute's source of truth.

SSO and App Integration

  • Set up single sign-on (SAML, OIDC) for new and existing apps.
  • Set up automatic user provisioning (SCIM) for those apps.
  • Keep a complete app inventory; retire unused, duplicate, or orphaned app integrations.
  • Track app owners, assignment methods, and the renewal of SAML certificates.

Access Control and Governance

  • Design and maintain access groups based on role and department, plus group rules that assign apps automatically.
  • Enforce least-privilege access so people get only what their role needs.
  • Run periodic access reviews and certifications with app owners.
  • Manage Okta admin roles and separation of duties, and review privileged access regularly.
  • Own GitHub access management, including SSO, team-to-group mapping, and onboarding/offboarding.

Policies and Security

  • Maintain sign-on, password, MFA, authenticator, and app-level authentication policies.
  • Review policies regularly and consolidate redundant or outdated ones.
  • Roll out phishing-resistant MFA (Okta FastPass, FIDO2/WebAuthn) and device assurance policies.
  • Manage network zones, behavior detection, and ThreatInsight settings.
  • Work with Security on incident response, such as suspicious sign-ins, session revocation, and account lockouts.

Hygiene and Cleanup

  • Find and clean up stale, inactive, and orphaned user accounts in Okta and Active Directory.
  • Inventory and govern service accounts: assign owners, rotate credentials, and monitor them.
  • Audit and manage external/guest accounts and contractor access with clear expiration dates.
  • Maintain Okta API tokens: track ownership and rotate or revoke them.

Automation and Workflows

  • Build and maintain Okta Workflows for repetitive tasks such as account deactivation, notifications, group syncs, and reporting.
  • Use the Okta API and scripting to run bulk operations and generate reports.
  • Integrate Okta with ITSM and collaboration tools such as Jira and Slack for access requests and approvals.

Active Directory

  • Manage Okta AD Agents, including their health, upgrades, and redundancy.
  • Plan for gradually reducing the company's reliance on Active Directory where it makes sense.

Backup, Monitoring, and Compliance

  • Own Okta configuration backups and config-as-code (Terraform and Okta configuration tools are a plus).
  • Maintain a disaster recovery plan for the identity platform.
  • Monitor the Okta System Log and stream logs to the SIEM, setting alerts for high-risk events.
  • Provide evidence for SOC 2, ISO 27001, and internal audits.
  • Keep runbooks, architecture diagrams, and standard operating procedures (SOPs) current.

Operations and Support

  • Act as the escalation point for authentication, MFA, and provisioning problems.
  • Evaluate new Okta features and releases, and plan how to adopt them.
  • Train the IT helpdesk on Okta procedures.

Required Qualifications

  • 7+ years of experience primarily administering Okta Identity and Access Management (IAM) systems.
  • 2+ years of hands-on experience with Active Directory (users, groups, OUs, GPOs, and Okta AD Agent integration).
  • Hands-on experience with SAML, OIDC/OAuth 2.0, SCIM, and MFA.
  • Experience integrating an HR system with Okta (ADP preferred) for automated user account creation.
  • Proven 3+ years of experience building Okta Workflows or using Python and the Okta API.
  • Solid grasp of least privilege, role-based access control (RBAC), and access governance.
  • Certifications: Okta Certified Administrator.