We are looking for a Senior Identity Engineer to drive the strategy, design, implementation, and operation of secure identity and access management (IAM) solutions for our global, hybrid workforce. In this role, you will help build and operate the identity services that protect our workforce, business partners, applications, and data.
This is a hands-on engineering role ideal for someone who enjoys solving complex access challenges while improving security, usability, and operational efficiency. This role will work closely with Security, IT, Engineering, Compliance, People Operations, and business stakeholders to ensure users have the right access at the right time while reducing identity-related risks.
Design, implement, and maintain identity and access management systems such as Okta, Google Workspace, Active Directory, and Microsoft Entra ID
Support identity lifecycle processes such as joiner, mover, and leaver workflows
Manage and integrate SSO, MFA, federation and conditional access controls
Build and maintain integrations between identity systems, HR systems, SaaS applications, and internal applications
Support access provisioning, deprovisioning, role-based access control, attribute-based access control, and least privilege access models
Partner with business stakeholders to onboard applications into SSO and identity governance platforms
Troubleshoot authentication, authorization, federation, and other directory related issues
Develop automation script and workflows to improve identity operations
Support audits, access reviews, compliance reporting, and evidence collection
Monitor identity systems for availability, performance, and security events
Qualification
Experience with implementing MFA
Required
8+ years of experience in Information Security or Information Technology
Hands-on experience with one or more identity platforms such as Okta, Google Workspace, or Microsoft Entra ID
Proven experience with privileged access management solutions
Strong understanding of authentication and authorization concepts such as SAML, OAuth, OpenID Connect, and SCIM
Experience with implementing MFA, SSO, conditional access, and lifecycle management
Experience with setup and management of access certification campaigns and role mining
Understanding of security principles such as least privilege, zero trust, separation of duties, and defense in depth
Experience with programming or scripting languages such as Python or Bash
Experience with Infrastructure as Code tooling such as Terraform or Pulumi
Experience with responding to security events
Experience with translating complex employee lifecycle events from HR Systems to Identity Platforms
Ability to communicate complex issues to a wide audience, from technical staff to management