# Staff Identity Governance and Access Engineer

**Company**: Okta
**Location**: Bellevue, Washington; Chicago, Illinois; Washington, DC
**Experience**: staff
**Job type**: full-time
**Salary**: $161,000-$221,000 USD
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/okta/jobs/8180503?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_4f5c5372-622

## Description

We're looking for a Staff Identity Security Engineer to take deep technical ownership of our Okta Identity Governance (OIG), Okta Privileged Access (OPA), and ISPM implementations.

This is a senior individual-contributor role where you'll set technical direction for how the team builds on top of these platforms and raise the bar for the engineering team through review, mentorship, and documentation.

**Key Responsibilities:**

- OIG Architecture Ownership: Own OIG architecture end-to-end , design access request workflows, entitlement/Resource Collections structures, and certification campaigns that reduce reviewer fatigue and rubber-stamping.

- Lifecycle, Birthright & RBAC Strategy: Lead lifecycle, birthright, and RBAC strategy , design and deploy automated birthright access rules, RBAC frameworks, and seamless joiner/mover/leaver (JML) processes across the enterprise.

- Workday Integration Architecture: Drive Workday integration architecture , balance scheduled reconciliation (attribute accuracy) with Real-Time Sync (immediate termination), and define the attribute sets that access rules depend on.

- Mover/Leaver Automation: Design and harden mover/leaver automation , implement attribute-driven group re-evaluation on role changes, safe decommissioning of stale access, and close gaps between automated joiner flows and historically manual processes.

- OPA, ISPM & Zero Standing Privilege: Lead OPA, ISPM, and Zero Standing Privilege (ZSP) initiatives , design privileged session access, Just-In-Time (JIT) elevation, break-glass emergency access, identity security vulnerability detection, and tiering models for Tier 0/Tier 1 systems.

- PAM & ISPM Metrics: Own PAM and ISPM telemetry and KPIs , establish and track metrics around standing-privilege reduction, JIT adoption, stale access cleanup, and break-glass test success as ongoing operational measures.

- Okta Workflows Automation: Build and maintain Okta Workflows automation , streamline access requests, approvals, and remediation across IGA and PAM processes using the Okta Workflows engine.

- Technical Leadership & Mentorship: Mentor engineers, review designs, and communicate with leadership , be the technical escalation point for the team's hardest problems, help junior engineers grow, and present clear updates, risk assessments, and roadmaps to executive stakeholders.

**Requirements:**

- Domain Experience: Minimum 4+ years of direct, advanced experience managing and administering enterprise IGA, PAM/ISPM tools and platforms.

- Birthright Provisioning & RBAC: Demonstrated hands-on experience designing and deploying Birthright Provisioning models and RBAC architectures in production environments.

- PAM/OPA Tooling: Production experience with OPA or equivalent PAM tooling, including Zero Standing Privilege, Just-In-Time access models, break-glass design, and admin tiering.

- ISPM Tooling: Production experience with ISPM tools (such as Okta ISPM) that integrate with EDR solutions like Crowdstrike Falcon.

- Identity Standards: Solid grounding in identity and access standards (SAML, OIDC, OAuth 2.0, SCIM) and role/attribute-based access control concepts.

- Lifecycle Ownership: Track record of owning technical designs for identity lifecycle problems (joiner/mover/leaver) end-to-end, from design doc through production rollout.

- Compliance Experience: Experience operating in SOX and compliance-critical environments , understanding audit evidence requirements, segregation of duties, and access certification integrity.

- Autonomy & Executive Communication: Works independently and drives initiatives without waiting for direction, with the executive-ready communication skills to present updates, risks, and roadmaps to leadership.

**Nice to Have:**

- Experience governing non-human identities (service accounts, API tokens, secrets, AI agents/workload identities) and scaling access certification programs , including distinct ownership models, lifecycle states, and certification approaches.

- Familiarity with ServiceNow and JIRA-based service request intake for IGA/PAM/ISPM operations.

- Okta certifications , Okta Certified Administrator, Okta Certified Consultant, or Okta Workflows Specialist.

- Technical integration experience with REST APIs, JSON parsing, webhooks, and Workday-to-IdP patterns (real-time event delivery vs. scheduled reconciliation tradeoffs).

- Experience supporting compliance audits across multiple frameworks beyond SOX (SOC 2, ISO 27001, HIPAA, GDPR).

**What We Offer:**

- Competitive salary: $161,000-$221,000 USD per year.

- Equity (where applicable).

- Bonus.

- Benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave).

## Skills

### Required
- IGA
- PAM
- ISPM
- Okta Identity Governance
- Okta Privileged Access
- Identity Security Posture Management
- Birthright Provisioning
- RBAC
- Workday Integration
- Zero Standing Privilege
- Just-In-Time access models
- break-glass design
- admin tiering
- SAML
- OIDC
- OAuth 2.0
- SCIM
- role/attribute-based access control

### Nice to have
- ServiceNow
- JIRA-based service request intake
- Okta certifications
- REST APIs
- JSON parsing
- webhooks
- Workday-to-IdP patterns
- SOC 2
- ISO 27001
- HIPAA
- GDPR

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/okta/jobs/8180503?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
