Staff Identity Governance and Access Engineer
Core
Own Okta's internal Identity Governance (OIG), Privileged Access (OPA), and Identity Security Posture Management (ISPM) implementations to serve as the reference architecture for customers.
Role type
Staff Identity Security Engineer (Individual Contributor)
Builds
Enterprise identity lifecycle workflows, RBAC frameworks, automated birthright access rules, and Zero Standing Privilege (ZSP) models.
Domain
Identity Governance and Administration (IGA), Privileged Access Management (PAM), and Identity Security Posture Management (ISPM)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Enterprise IGA/PAM/ISPM administration, Birthright Provisioning, RBAC architecture, Workday integration, Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, Identity Standards (SAML, OIDC, OAuth 2.0, SCIM), Lifecycle Ownership (Joiner/Mover/Leaver), Compliance (SOX)
Preferred skills
Non-human identity governance, ServiceNow/JIRA integration, Okta certifications, REST API/JSON parsing, Multi-framework compliance (SOC 2, ISO 27001, HIPAA, GDPR)
Technologies
Okta Workflows, Workday, Okta ISPM, Crowdstrike Falcon, JIRA, ServiceNow
Responsibilities
Design access request workflows and entitlement structures; Lead lifecycle and RBAC strategy; Drive Workday integration architecture; Design mover/leaver automation; Lead OPA, ISPM, and ZSP initiatives; Own PAM and ISPM telemetry and KPIs; Mentor engineers and communicate with leadership
Seniority
Staff, hands-on IC with technical leadership