Senior Identity Engineer

• Posted 8 hours ago • Updated 8 hours ago
Full Time
USD $110,000.00 - 140,000.00 per year
Fitment

Dice Job Match Score™

📋 Comparing job requirements...

Job Details

Skills

  • Mapping
  • Provisioning
  • HTTP
  • Migration
  • Bridging
  • SSO
  • Onboarding
  • Authentication
  • Network
  • GPO
  • Management
  • Dashboard
  • Testing
  • Mentorship
  • Agile
  • Scrumban
  • JIRA
  • Training
  • Change Management
  • Incident Management
  • Identity Management
  • Lifecycle Management
  • Workflow
  • Access Gateways
  • Enterprise Software
  • PIM
  • Business-to-business
  • Active Directory
  • Group Policy
  • ADFS
  • SAML
  • OIDC
  • OAuth
  • HR Management System
  • Scripting
  • Windows PowerShell
  • Python
  • JavaScript
  • Terraform
  • JSON
  • Multi-factor Authentication
  • Computer Hardware
  • Regulatory Compliance
  • System On A Chip
  • Sarbanes-Oxley
  • FedRAMP
  • Communication
  • Documentation
  • Microsoft Windows
  • Linux
  • OS X
  • PASS
  • Microsoft Azure
  • Microsoft
  • Microsoft Windows Server
  • Microsoft Operating Systems
  • Amazon Web Services
  • SCS
  • CISSP
  • SANS
  • GCIA
  • GCIH

Summary

Description

Responsibilities
  • Serve as the technical owner and subject matter expert for Okta (Workforce Identity + Identity Governance), Microsoft Entra ID, and Active Directory.
  • Architect and operate the UKG Okta AD identity lifecycle pipeline, including UKG Pro connector validation, attribute mapping, Universal Directory profile design, and Okta AD Agent write-back.
  • Design and build Okta Workflows for Joiner / Mover / Leaver automation, including SCIM provisioning, HTTP connector flows, and migration of Azure Runbooks into Okta Workflows.
  • Engineer application bridges for downstream targets Okta does not natively integrate, such as with Lambda and Azure Functions.
  • Ownership of SSO strategy (SAML, OIDC, SCIM, Federation), application onboarding standards, and the Okta application catalog.
  • Design and maintain authentication and access policies. Multifactor Authentication, adaptive risk-based authentication, network zones and authenticator enrollment policies.
  • Lead Active Directory hygiene and remediation: stale account cleanup, group rationalization, GPO linkage reviews, SPN management, OU placement standards, and contractor census alignment.
  • Build and operate identity dashboards across AD / Okta / Entra ID for operational visibility and license utilization.
  • Maintain non-production tenants for testing, validation, and change rehearsal prior to production cutover.
  • Mentor IT Analysts and Infrastructure Engineers across Okta, Entra ID, and AD.
  • Participate in Agile/Scrumban ceremonies using JSM/Jira as the system of record.
  • Document and maintain architecture diagrams, configuration baselines, runbooks, SOPs, and training paths.
  • Participate in IT projects, change management, incident response, and on-call rotation for identity platform issues.
Qualifications
  • Minimum 5 years of IT experience with a meaningful portion dedicated to identity and access management in a mid-to-large sized enterprise.
  • Hands-on experience with Okta --Workforce Identity, Universal Directory, Lifecycle Management, Workflows, Access Gateway, Okta Identity Engine.
  • Hands-on experience with Microsoft Entra ID - Conditional Access, app registrations, enterprise apps, PIM, B2B, hybrid join.
  • Active Directory engineering experience - multi-domain/multi-forest, Group Policy, Sites & Services, ADFS, AD/Entra Connect, PowerShell.
  • Working knowledge of AWS IAM, IAM Identity Center, AWS Managed AD, and federation patterns.
  • Production experience designing and operating SAML 2.0, OIDC/OAuth 2.0, SCIM 2.0, and WS-Fed integrations.
  • Experience automating identity lifecycle (Joiner / Mover / Leaver) from an HRIS source.
  • Strong scripting/automation skills: PowerShell (required) and at least one of Python, JavaScript, Terraform, and/or JSON.
  • Experience with MFA platforms and modern authenticators (Okta Verify, Microsoft Authenticator, FIDO2 / hardware-based keys).
  • Familiarity with compliance frameworks: NIST CSF, SOC 2, SOX, CJIS, FedRAMP.
  • Excellent written and verbal communication and documentation discipline.
  • Working knowledge of Windows, Linux and macOS.
  • Some travel is required.
  • Will be required to undergo and satisfactorily pass a fingerprint background check (for CJIS requirements).

Certifications
  • Okta Certified Professional / Administrator / Consultant / Architect
  • Microsoft SC-300 - Identity & Access Administrator Associate
  • Microsoft AZ-500 - Azure Security Engineer
  • Microsoft AZ-800 / AZ-801 - Windows Server Hybrid Administrator
  • AWS Certified Security - Specialty (SCS-C02)
  • CISSP, SANS GIAC (GCIA / GCIH / GPCS), or equivalent)
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 80180573
  • Position Id: 972823bb7a350250cbd59f834150a08f
  • Posted 8 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Austin, Texas

Today

Full-time

USD 190,000.00 - 215,000.00 per year

No location provided

Today

Full-time

New Jersey

Today

Full-time

USD 133,000.00 - 173,000.00 per year

Maplewood, Minnesota

Today

Full-time

USD 145,676.00 - 178,049.00 per year

Search all similar jobs