Senior Cybersecurity Engineer SaaS / Identity Management
Needs to work in PST time zone
100% remote
Contract Role
Overview
We are seeking a highly skilled Senior SaaS / Identity Engineer to design, implement, and manage enterprise-grade identity and SaaS automation solutions. This role focuses on Identity & Access Management (IAM), DevOps automation, and SaaS ecosystem integration, ensuring secure, scalable, and efficient user lifecycle management across both cloud and on-premise environments.
You will play a key role in architecting automation frameworks, enhancing identity workflows, and improving operational efficiency across a diverse application landscape.
Key Responsibilities
Identity & SaaS Administration
Manage and administer enterprise SaaS and on-premise applications supporting multiple business units.
Design and maintain user provisioning and deprovisioning workflows, ensuring compliance and security.
Implement and manage SAML SSO, MFA/2FA, and Identity Federation solutions across platforms.
Configure and maintain IAM integrations for applications such as Okta, Google Workspace (G-Suite), Azure AD, SAP, ADP, Concur, and others.
DevOps & Automation
Architect and develop automation tools to streamline:
o User lifecycle management
o Identity access workflows
o SaaS application onboarding and integration
Build and maintain DevOps pipelines and toolchain improvements for IAM operations.
Develop automation using scripting languages such as Python, Bash, PowerShell, and Java.
Use APIs, webhooks, and event-driven architecture to integrate systems and workflows.
Identity & Security Engineering
Design and implement IAM solutions leveraging:
o OIDC, SAML, SCIM, and modern authentication protocols
o Secure token handling and lifecycle management
Configure and manage advanced Okta capabilities including:
o Okta Access Gateway (OAG)
o Device Trust
o Adaptive MFA (AMFA)
o Desktop SSO (DSSO)
o Okta Workflows and API automation
o Okta Expression Language
Integration & Systems Architecture
Analyze dependencies and design robust solutions integrating multiple SaaS and on-prem systems.
Build and maintain integrations using:
o REST/SOAP APIs, LDAP, RADIUS, SFTP, SSH
o Data formats such as JSON, XML, YAML
Utilize synchronization tools including:
o GAM/GADS (Google), Okta APIs, Okta Workflows, Google APIs
Security Analytics & Monitoring
Develop security analytics and reporting using:
o Python (Pandas)
o Log aggregation tools such as Sumo Logic
o XDR query frameworks
Monitor system health, user activity, and identity risks.
Collaboration & Stakeholder Engagement
Partner with senior leaders, operations teams, and cross-functional stakeholders to deliver scalable SaaS solutions.
Act as a technical advisor on IAM and SaaS strategy.
Documentation & Enablement
Produce clear and comprehensive technical documentation including:
o Architecture diagrams
o Integration templates
o Runbooks and SOPs
Develop training materials and provide knowledge transfer to operations/support teams.
________________________________________
Required Qualifications
8+ years of experience in Identity & Access Management, SaaS administration, or DevOps automation
Strong expertise in IAM platforms, especially Okta
Hands-on experience with:
o SAML, OIDC, SCIM, and modern authentication protocols
o Enterprise identity integrations
Advanced scripting experience in:
o Python, Bash, PowerShell, Java
Deep knowledge of networking and integration protocols:
o LDAP, RADIUS, REST, SOAP, HTTP(S), SSH, SFTP
Experience building automation using APIs and workflow engines
Strong understanding of security best practices and identity governance
________________________________________
Preferred Qualifications
Experience with cloud platforms (Azure, Google Cloud Platform, AWS IAM)
Familiarity with Zero Trust security models
Previous experience with enterprise-scale automation and DevOps pipelines
Knowledge of log analytics and SIEM/XDR tools
Certifications such as:
o Okta Certified Professional / Administrator
o Certified Identity and Access Manager (CIAM)
o Cloud certifications (Azure/AWS/Google Cloud Platform)