Senior Identity Engineer
Description
Responsibilities
- Serve as the technical owner and subject matter expert for Okta (Workforce Identity + Identity Governance), Microsoft Entra ID, and Active Directory.
- Architect and operate the UKG → Okta → AD identity lifecycle pipeline, including UKG Pro connector validation, attribute mapping, Universal Directory profile design, and Okta AD Agent write-back.
- Design and build Okta Workflows for Joiner / Mover / Leaver automation, including SCIM provisioning, HTTP connector flows, and migration of Azure Runbooks into Okta Workflows.
- Engineer application bridges for downstream targets Okta does not natively integrate, such as with Lambda and Azure Functions.
- Ownership of SSO strategy (SAML, OIDC, SCIM, Federation), application onboarding standards, and the Okta application catalog.
- Design and maintain authentication and access policies. Multifactor Authentication, adaptive risk-based authentication, network zones and authenticator enrollment policies.
- Lead Active Directory hygiene and remediation: stale account cleanup, group rationalization, GPO linkage reviews, SPN management, OU placement standards, and contractor census alignment.
- Build and operate identity dashboards across AD / Okta / Entra ID for operational visibility and license utilization.
- Maintain non-production tenants for testing, validation, and change rehearsal prior to production cutover.
- Mentor IT Analysts and Infrastructure Engineers across Okta, Entra ID, and AD.
- Participate in Agile/Scrumban ceremonies using JSM/Jira as the system of record.
- Document and maintain architecture diagrams, configuration baselines, runbooks, SOPs, and training paths.
- Participate in IT projects, change management, incident response, and on-call rotation for identity platform issues.
Qualifications
- Minimum 5 years of IT experience with a meaningful portion dedicated to identity and access management in a mid-to-large sized enterprise.
- Hands-on experience with Okta --Workforce Identity, Universal Directory, Lifecycle Management, Workflows, Access Gateway, Okta Identity Engine.
- Hands-on experience with Microsoft Entra ID — Conditional Access, app registrations, enterprise apps, PIM, B2B, hybrid join.
- Active Directory engineering experience — multi-domain/multi-forest, Group Policy, Sites & Services, ADFS, AD/Entra Connect, PowerShell.
- Working knowledge of AWS IAM, IAM Identity Center, AWS Managed AD, and federation patterns.
- Production experience designing and operating SAML 2.0, OIDC/OAuth 2.0, SCIM 2.0, and WS-Fed integrations.
- Experience automating identity lifecycle (Joiner / Mover / Leaver) from an HRIS source.
- Strong scripting/automation skills: PowerShell (required) and at least one of Python, JavaScript, Terraform, and/or JSON.
- Experience with MFA platforms and modern authenticators (Okta Verify, Microsoft Authenticator, FIDO2 / hardware-based keys).
- Familiarity with compliance frameworks: NIST CSF, SOC 2, SOX, CJIS, FedRAMP.
- Excellent written and verbal communication and documentation discipline.
- Working knowledge of Windows, Linux and macOS.
- Some travel is required.
- Will be required to undergo and satisfactorily pass a fingerprint background check (for CJIS requirements).
Certifications
- Okta Certified Professional / Administrator / Consultant / Architect
- Microsoft SC-300 — Identity & Access Administrator Associate
- Microsoft AZ-500 — Azure Security Engineer
- Microsoft AZ-800 / AZ-801 — Windows Server Hybrid Administrator
- AWS Certified Security – Specialty (SCS-C02)
- CISSP, SANS GIAC (GCIA / GCIH / GPCS), or equivalent)