Lead IAM Engineer

Posted Yesterday
Easy Apply
Be an Early Applicant
Austin, TX, USA
Hybrid
91K-158K Annually
Senior level
Marketing Tech • Mobile • Software
Find your people. Make real impact.
The Role
Own the technical architecture and roadmap for enterprise IAM centered on Okta. Design and improve SSO, authentication, lifecycle management, identity governance, access reviews, provisioning, and least-privilege controls. Build integrations with Workday and enterprise applications using APIs, scripting, Terraform, and automation. Strengthen SOX controls, reliability, documentation, and deployment practices while serving as a senior escalation point and mentoring engineers.
Summary Generated by Built In

At Braze, we have found our people. We’re a genuinely approachable, exceptionally kind, and intensely passionate crew.

We seek to ignite that passion by setting high standards, championing teamwork, and creating work-life harmony as we collectively navigate rapid growth on a global scale while striving for greater equity and opportunity – inside and outside our organization.

To flourish here, you must be prepared to set a high bar for yourself and those around you. There is always a way to contribute: Acting with autonomy, having accountability and being open to new perspectives are essential to our continued success.

Our deep curiosity to learn and our eagerness to share diverse passions with others gives us balance and injects a one-of-a-kind vibrancy into our culture.

If you are driven to solve exhilarating challenges and have a bias toward action in the face of change, you will be empowered to make a real impact here, with a sharp and passionate team at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you.

WHAT YOU'LL DO

We’re seeking a Lead IAM Engineer to own the technical direction and evolution of our enterprise identity and access management strategy. In this senior individual contributor role, you’ll architect, build, and continuously improve a secure, scalable, and automated identity ecosystem centered on Okta, identity lifecycle, access governance, and automation.

You’ll partner across Information Systems, Security, Engineering, Financial, and People Systems to ensure employees, contractors, partners, applications, and services have the right access at the right time while maintaining strong security, governance, reliability, and user experience.

A major focus of this role will be improving onboarding, access-change, and offboarding reliability, reducing manual administration, strengthening access governance, and expanding automation across our identity ecosystem. You’ll help modernize how identity configuration changes are managed through APIs, infrastructure as code, automated workflows, and repeatable engineering practices.

You’ll also help strengthen the broader Identity & Access capability by developing reusable patterns, improving documentation and operational resilience, mentoring other engineers, and reducing key-person dependencies across critical identity services.

If you’re an experienced IAM engineer with deep Okta expertise who enjoys both defining architecture and getting hands-on with automation, integrations, governance, and platform engineering, we’d love to meet you.

Main responsibilities:

  • Own the technical roadmap and architecture for enterprise Identity & Access Management, with Okta as a core identity platform
  • Architect and continuously improve Okta capabilities across SSO, authentication, lifecycle automation, Workflows, Identity Governance, and Access Requests
  • Design reliable onboarding, role-change, and offboarding identity processes for employees, contractors, partners, and other user populations
  • Build and improve integrations between Okta and systems such as Workday, Google Workspace, Slack, GitHub, Atlassian, MDM, and other enterprise applications
  • Drive identity automation using Okta Workflows, APIs, scripting, Terraform, and other engineering tools
  • Modernize how identity configuration changes are made through infrastructure as code, automated validation, peer review, and controlled deployment where appropriate
  • Lead identity governance initiatives including access reviews, access requests, role-based access, approval workflows, entitlement management, and least-privilege controls
  • Design and implement authentication, federation, and provisioning solutions using SAML, OIDC, OAuth, SCIM, MFA, and related identity standards
  • Partner with Security on authentication standards, privileged access, identity risk, and zero-trust initiatives
  • Support and continuously improve identity-related SOX controls, audit evidence, access reviews, and remediation processes
  • Design identity solutions for partners, resellers, service accounts, machine identities, and other non-standard access needs
  • Serve as a senior escalation point for complex identity issues and lead root cause analysis when identity or lifecycle processes fail
  • Identify recurring administrative or support work and create automation, self-service, runbooks, or delegated workflows to reduce manual intervention
  • Establish repeatable engineering standards for how identity changes are designed, tested, deployed, and documented
  • Mentor other engineers and help build broader IAM expertise and independent backup coverage across the team
  • Evaluate emerging identity capabilities and recommend where they can improve security, reliability, scalability, or user experience

WHO YOU ARE

  • Deep hands-on expertise with Okta in a complex enterprise environment, including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance
  • Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization
  • Experience automating employee onboarding, role changes, and offboarding using an HRIS such as Workday as the authoritative source for employee data
  • Strong experience with identity governance including access reviews, entitlement management, access requests, role-based access control, and least privilege
  • Strong scripting and automation skills using Python, PowerShell, or similar languages
  • Strong API integration experience and the ability to connect identity platforms with broader enterprise systems
  • Experience with Terraform or another infrastructure-as-code framework
  • Experience turning manual identity administration into scalable, automated, and auditable processes
  • Experience supporting IAM controls in a SOX-regulated or similarly controlled environment
  • Proven ability to lead complex cross-functional IAM initiatives without requiring formal people-management authority
  • Strong communication skills with the ability to explain identity architecture, technical decisions, and risk to both technical and non-technical audiences

Bonus Points:

  • Okta certifications such as Okta Certified Administrator, Consultant, Developer, or Identity Governance credentials
  • Experience managing Okta configuration through Terraform or similar tooling
  • Experience using Git-based workflows or CI/CD practices to manage identity or infrastructure changes
  • Familiarity with adjacent enterprise platforms such as Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password
  • Experience with partner, reseller, B2B, or external identity architectures
  • Experience managing service accounts, machine identities, workload identities, or other non-human access
  • Experience automating audit evidence or identity governance controls

For candidates based in the United States, the pay range for this position at the start of employment is expected to be between $91,000 and $142,000/year, with an expected On Target Earnings (OTE) between $101,000 and $158,000/year (including bonus or commission). Your exact offer may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition to cash compensation, this role qualifies for a comprehensive Total Rewards package that includes equity grants of restricted stock (RSUs) so that you will own a piece of our company.

#LI-Hybrid

WHAT WE OFFER

Braze benefits vary by location, and we encourage you to review our specific benefits offerings for each country here. More details on benefits plans will be provided if you receive an offer of employment.

From offering comprehensive benefits to fostering hybrid ways of working, we’ve got you covered so you can prioritize work-life harmony. Braze offers benefits such as:

  • Competitive compensation that may include equity
  • Retirement and Employee Stock Purchase Plans
  • Flexible paid time off
  • Comprehensive benefit plans covering medical, dental, vision, life, and disability
  • Family services that include fertility benefits and equal paid parental leave
  • Professional development supported by formal career pathing, learning platforms, and a yearly learning stipend
  • A curated in-office employee experience, designed to foster community, team connections, and innovation
  • Opportunities to give back to your community, including an annual company-wide Volunteer Week and donation matching 
  • Employee Resource Groups that provide supportive communities within Braze
  • Collaborative, transparent, and fun culture recognized as a Great Place to Work®

ABOUT BRAZE

Braze is the leading customer engagement platform that empowers brands to Be Absolutely Engaging.™ Braze helps brands deliver great customer experiences that drive value both for consumers and for their businesses. Built on a foundation of composable intelligence, BrazeAI™ allows marketers to combine and activate AI agents, models, and features at every touchpoint throughout the Braze Customer Engagement Platform for smarter, faster, and more meaningful customer engagement. From cross-channel messaging and journey orchestration to Al-powered decisioning and optimization, Braze enables companies to turn action into interaction through autonomous, 1:1 personalized experiences.
The company has repeatedly been recognized as a Leader in marketing technology by industry analysts, and was voted a G2 “Best of Marketing and Digital Advertising Software Product” in 2025.
Braze was also named a 2025 Best Companies To Work For by U.S. News & World Report, a 2025 America’s Greatest Companies by Newsweek, and a 2025 Fortune Best Workplace in Technology™ by Great Place To Work®, among other accolades. Braze is also proudly certified as a Great Place to Work® in the U.S., the UK, Australia, and Singapore.
The company is headquartered in New York with offices in Austin, Berlin, Bucharest, Chicago, Dubai, Jakarta, London, Paris, San Francisco, São Paulo, Singapore, Seoul, Sydney and Tokyo.

BRAZE IS AN EQUAL OPPORTUNITY EMPLOYER

At Braze, we strive to create equitable growth and opportunities inside and outside the organization.

Building meaningful connections is at the heart of everything we do, and that includes our recruiting practices. We're committed to offering all candidates a fair, accessible, and inclusive experience – regardless of age, color, disability, gender identity, marital status, maternity, national origin, pregnancy, race, religion, sex, sexual orientation, or status as a protected veteran. When applying and interviewing with Braze, we want you to feel comfortable showcasing what makes you you.

We know that sometimes different circumstances can lead talented people to hesitate to apply for a role unless they meet 100% of the criteria. If this sounds familiar, we encourage you to apply, as we’d love to meet you

OUR AI-POWERED BRAZE RECRUITMENT PROCESS

At Braze, we’re committed to a fair and transparent candidate experience. To help our recruitment teams focus on what matters most — the person behind each application — we use AI-assisted tools at certain stages of our recruitment process. 

This includes using AI to analyze the experience, skills and qualifications in your application materials to help with screening and prioritizing candidates. Such screening may amount to a form of solely automated decision-making. We also use AI for administrative support, like scheduling and recording interviews and summarizing interview notes. Our recruiting teams remain responsible for all hiring decisions and are involved throughout the process.

Depending on where you are located, you may have certain rights available to you in relation to Braze’s use of AI:

  • To opt out of AI-assisted review of your application, please click the “Learn More” at the end of the application form below and follow the instructions before submitting your application. Please note, if you apply to multiple roles at Braze, you will need to opt out in relation to each application.
  • To exercise other types of rights, such as rights to request further information about how AI is used in our recruitment process, to request a manual review of any decision made or to contest a decision, please contact us at [email protected]

Please contact us at [email protected] with any questions. To find out more about our hiring process, check out this page.

Notice Regarding Automated Employment Decision Tool (NYC Local Law 144)

Our use of AI during the application review process may include the use of automated employment decision tools. Pursuant to New York City Local Law 144, for roles based in New York City, or if you reside in New York City, you have the right to request an alternative selection process or a reasonable accommodation instead of AI-assisted review. 

To opt out of AI-assisted review of your application, please click the “Learn More” button below and follow the instructions before submitting your application. Please note, if you apply to multiple roles at Braze, you will need to opt out in relation to each application. Please submit any other request to our Talent Acquisition team at [email protected] promptly after applying. Summaries of the most recent bias audit results for such tools are available here.

Please see our Candidate Privacy Policy for more information on how Braze processes your personal information during the recruitment process and, if applicable based on your location, how you can exercise any privacy rights.

Skills Required

  • Deep hands-on Okta expertise in a complex enterprise environment, including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance
  • Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization
  • Experience automating employee onboarding, role changes, and offboarding using an HRIS such as Workday
  • Strong experience with identity governance, including access reviews, entitlement management, access requests, RBAC, and least privilege
  • Strong scripting and automation skills using Python, PowerShell, or similar languages
  • Strong API integration experience connecting identity platforms with enterprise systems
  • Experience with Terraform or another infrastructure-as-code framework
  • Experience converting manual identity administration into scalable, automated, and auditable processes
  • Experience supporting IAM controls in a SOX-regulated or similarly controlled environment
  • Ability to lead complex cross-functional IAM initiatives without formal people-management authority
  • Strong communication skills for explaining identity architecture, technical decisions, and risk to technical and non-technical audiences
  • Okta certification such as Administrator, Consultant, Developer, or Identity Governance credentials
  • Experience managing Okta configuration through Terraform or similar tooling
  • Experience using Git-based workflows or CI/CD practices for identity or infrastructure changes
  • Familiarity with Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password
  • Experience with partner, reseller, B2B, or external identity architectures
  • Experience managing service accounts, machine identities, workload identities, or other non-human access
  • Experience automating audit evidence or identity governance controls

What the Team is Saying

Annie
Zana
Todd
Kristin

Braze Compensation & Benefits Highlights

  • Healthcare Strength Healthcare coverage is described as comprehensive, including medical, dental, and vision, with a 100% employer‑paid medical option for employees and dependents plus life and disability insurance. Expanded mental‑health support (e.g., therapy/coaching via Modern Health) and employer payment of all or most premiums reinforce this strength.
  • Parental & Family Support Equal paid parental leave is highlighted at 16 weeks in the US and Singapore (18 weeks in the UK), alongside adoption and surrogacy support and a flexible ramp‑back to work. Family‑forming benefits via Carrot reimburse up to $5,000 annually with a $25,000 lifetime maximum, and there is backup childcare and eldercare support.
  • Leave & Time Off Breadth Flexible or unlimited PTO, company holidays, and up to 12 weeks of fully paid medical/caregiver leave are emphasized. Work arrangements can be hybrid or remote depending on role, with a telecommuter stipend to offset home office costs.

Braze Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
2,000 Employees
Year Founded: 2011

What We Do

At Braze, we believe in the passion of our people. We seek to ignite that passion by setting high standards, championing teamwork, and creating work-life harmony. We thrive when people add their unique perspectives to our ever-growing teams—and we strive to empower you to make an impact that fuels both you, and our business.

Why Work With Us

At Braze, we believe in the passion of our people. We seek to ignite that passion by setting high standards, championing teamwork, and creating work-life harmony. We thrive when people add their unique perspectives to our ever-growing teams—and we strive to empower you to make an impact that fuels both you, and our business.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Braze Teams

Team
Engineering & IT
Team
Product & Design
Team
Revenue
Team
Brand & Marketing
Team
Business Strategy & Operations
Team
People & Social Impact
Team
Finance.
Team
Legal.
About our Teams

Braze Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
Company Office Image
HQNew York
Company Office Image
Austin
Berlin
Company Office Image
Bucharest, RO
Company Office Image
Chicago
DKI Jakarta, ID
Indonesia
Dubai, Dubai
Company Office Image
London
Paris
Company Office Image
San Francisco
Company Office Image
São Paulo, BR
Company Office Image
Singapore
Company Office Image
Sydney
Company Office Image
Tokyo
Learn more

Similar Jobs

Braze Logo Braze

Senior Director, GTM Product Marketing

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
Austin, TX, USA
2000 Employees
149K-257K Annually

Braze Logo Braze

Consultant

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
Austin, TX, USA
2000 Employees
80K-140K Annually

Braze Logo Braze

Director, Customer Success, Enterprise

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
Austin, TX, USA
2000 Employees
163K-284K Annually

Braze Logo Braze

AVP, Agency & SI Partnerships

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
Austin, TX, USA
2000 Employees
155K-407K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account