Location: Available to work during US Hours (8:00 AM PST to 6:00 PM PST — no overtime required) or India Hours (8:00 AM IST to 6:00 PM IST)
About the Company
The company’s identity environment spans employee records, application access, and security policies. The work includes keeping access information audit-ready and providing evidence for SOC 2, ISO 27001, and internal audits.
About the Role
This is a hands-on Okta Identity Engineering role focused on automation, not a helpdesk or IT support role. You’ll own day-to-day Okta administration and improve how access is managed across the company: automating joiners, movers, and leavers, managing SSO-integrated applications, and keeping app and user inventories accurate and audit-ready. You’ll also work across Okta and Active Directory to reduce manual work.
Key Responsibilities
Identity Lifecycle and HR Integration
- Own the ADP, Okta, and Active Directory integration so employee records stay in sync automatically.
- Automate joiner, mover, and leaver workflows, including same-day offboarding and access removal.
- Map and maintain Okta profile attributes, and make sure they push correctly to downstream apps.
- Manage the Okta user schema and profile mappings, maintaining each attribute's source of truth.
SSO and App Integration
- Set up single sign-on (SAML, OIDC) for new and existing apps.
- Set up automatic user provisioning (SCIM) for those apps.
- Keep a complete app inventory; retire unused, duplicate, or orphaned app integrations.
- Track app owners, assignment methods, and the renewal of SAML certificates.
Access Control and Governance
- Design and maintain access groups based on role and department, plus group rules that assign apps automatically.
- Enforce least-privilege access so people get only what their role needs.
- Run periodic access reviews and certifications with app owners.
- Manage Okta admin roles and separation of duties, and review privileged access regularly.
- Own GitHub access management, including SSO, team-to-group mapping, and onboarding/offboarding.
Policies and Security
- Maintain sign-on, password, MFA, authenticator, and app-level authentication policies.
- Review policies regularly and consolidate redundant or outdated ones.
- Roll out phishing-resistant MFA (Okta FastPass, FIDO2/WebAuthn) and device assurance policies.
- Manage network zones, behavior detection, and ThreatInsight settings.
- Work with Security on incident response, such as suspicious sign-ins, session revocation, and account lockouts.
Hygiene and Cleanup
- Find and clean up stale, inactive, and orphaned user accounts in Okta and Active Directory.
- Inventory and govern service accounts: assign owners, rotate credentials, and monitor them.
- Audit and manage external/guest accounts and contractor access with clear expiration dates.
- Maintain Okta API tokens: track ownership and rotate or revoke them.
Automation and Workflows
- Build and maintain Okta Workflows for repetitive tasks such as account deactivation, notifications, group syncs, and reporting.
- Use the Okta API and scripting to run bulk operations and generate reports.
- Integrate Okta with ITSM and collaboration tools such as Jira and Slack for access requests and approvals.
Active Directory
- Manage Okta AD Agents, including their health, upgrades, and redundancy.
- Plan for gradually reducing the company's reliance on Active Directory where it makes sense.
Backup, Monitoring, and Compliance
- Own Okta configuration backups and config-as-code (Terraform and Okta configuration tools are a plus).
- Maintain a disaster recovery plan for the identity platform.
- Monitor the Okta System Log and stream logs to the SIEM, setting alerts for high-risk events.
- Provide evidence for SOC 2, ISO 27001, and internal audits.
- Keep runbooks, architecture diagrams, and standard operating procedures (SOPs) current.
Operations and Support
- Act as the escalation point for authentication, MFA, and provisioning problems.
- Evaluate new Okta features and releases, and plan how to adopt them.
- Train the IT helpdesk on Okta procedures.
Required Qualifications
- 7+ years of experience primarily administering Okta Identity and Access Management (IAM) systems.
- 2+ years of hands-on experience with Active Directory (users, groups, OUs, GPOs, and Okta AD Agent integration).
- Hands-on experience with SAML, OIDC/OAuth 2.0, SCIM, and MFA.
- Experience integrating an HR system with Okta (ADP preferred) for automated user account creation.
- Proven 3+ years of experience building Okta Workflows or using Python and the Okta API.
- Solid grasp of least privilege, role-based access control (RBAC), and access governance.
- Certifications: Okta Certified Administrator.