Senior Identity Engineer

IT United States Yarmouth, Maine Troy, Michigan Latham, New York Plano, Texas
Salary: USD 110000 - 140000 Annually


Description

Responsibilities

  • Serve as the technical owner and subject matter expert for Okta (Workforce Identity + Identity Governance), Microsoft Entra ID, and Active Directory.
  • Architect and operate the UKG → Okta → AD identity lifecycle pipeline, including UKG Pro connector validation, attribute mapping, Universal Directory profile design, and Okta AD Agent write-back.
  • Design and build Okta Workflows for Joiner / Mover / Leaver automation, including SCIM provisioning, HTTP connector flows, and migration of Azure Runbooks into Okta Workflows.
  • Engineer application bridges for downstream targets Okta does not natively integrate, such as with Lambda and Azure Functions.
  • Ownership of SSO strategy (SAML, OIDC, SCIM, Federation), application onboarding standards, and the Okta application catalog.
  • Design and maintain authentication and access policies. Multifactor Authentication, adaptive risk-based authentication, network zones and authenticator enrollment policies.
  • Lead Active Directory hygiene and remediation: stale account cleanup, group rationalization, GPO linkage reviews, SPN management, OU placement standards, and contractor census alignment.
  • Build and operate identity dashboards across AD / Okta / Entra ID for operational visibility and license utilization.
  • Maintain non-production tenants for testing, validation, and change rehearsal prior to production cutover.
  • Mentor IT Analysts and Infrastructure Engineers across Okta, Entra ID, and AD.
  • Participate in Agile/Scrumban ceremonies using JSM/Jira as the system of record.
  • Document and maintain architecture diagrams, configuration baselines, runbooks, SOPs, and training paths.
  • Participate in IT projects, change management, incident response, and on-call rotation for identity platform issues.

Qualifications

  • Minimum 5 years of IT experience with a meaningful portion dedicated to identity and access management in a mid-to-large sized enterprise.
  • Hands-on experience with Okta --Workforce Identity, Universal Directory, Lifecycle Management, Workflows, Access Gateway, Okta Identity Engine.
  • Hands-on experience with Microsoft Entra ID — Conditional Access, app registrations, enterprise apps, PIM, B2B, hybrid join.
  • Active Directory engineering experience — multi-domain/multi-forest, Group Policy, Sites & Services, ADFS, AD/Entra Connect, PowerShell.
  • Working knowledge of AWS IAM, IAM Identity Center, AWS Managed AD, and federation patterns.
  • Production experience designing and operating SAML 2.0, OIDC/OAuth 2.0, SCIM 2.0, and WS-Fed integrations.
  • Experience automating identity lifecycle (Joiner / Mover / Leaver) from an HRIS source.
  • Strong scripting/automation skills: PowerShell (required) and at least one of Python, JavaScript, Terraform, and/or JSON.
  • Experience with MFA platforms and modern authenticators (Okta Verify, Microsoft Authenticator, FIDO2 / hardware-based keys).
  • Familiarity with compliance frameworks: NIST CSF, SOC 2, SOX, CJIS, FedRAMP.
  • Excellent written and verbal communication and documentation discipline.
  • Working knowledge of Windows, Linux and macOS.
  • Some travel is required.
  • Will be required to undergo and satisfactorily pass a fingerprint background check (for CJIS requirements).

Certifications 

  •  Okta Certified Professional / Administrator / Consultant / Architect
  • Microsoft SC-300 — Identity & Access Administrator Associate
  • Microsoft AZ-500 — Azure Security Engineer
  • Microsoft AZ-800 / AZ-801 — Windows Server Hybrid Administrator
  • AWS Certified Security – Specialty (SCS-C02)
  • CISSP, SANS GIAC (GCIA / GCIH / GPCS), or equivalent)