Staff Engineer, Identity & Access Management

Reposted 22 Days Ago
Be an Early Applicant
4 Locations
In-Office
Expert/Leader
Cloud
The Role
Lead Okta's internal IAM strategy and execution: deploy and validate new identity features, mentor engineers, automate processes, integrate identity into CI/CD and IaC, govern AI agents, and report IAM KPIs to executives.
Summary Generated by Built In

Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Identity Team

Okta's internal Identity team secures the foundational trust layer for our modern enterprise. As organizations adopt phishing-resistant MFA, attackers have shifted toward session hijacking and cookie theft. Furthermore, with the rise of autonomous AI workloads, we are extending our platform to protect and govern a growing sprawl of non-human, agentic workflows. Our mission is to ensure every person and machine can safely connect to the right technology at the right time.

About the Role

As a Staff Engineer at Okta, you will be a technical authority within our internal IAM team, driving the architecture and execution of our identity fabric. You will champion our "Customer Zero" philosophy, partnering with product engineering to deploy Okta's newest features internally before they reach global markets. This role requires a technical leader who acts with ownership and urgency, turning action into traction and ruthlessly simplifying complex problems. You will serve as a mentor, influence architectural decisions, and help determine the future of the platform. Must be a U.S. citizen and will be working within the U.S. boundary to meet requirements of the FedRAMP compliance for Level 2. 

Here is the complete, consolidated job description tailored for the Staff Engineer level.

What You’ll Be Doing (Responsibilities)

  • Drive Customer Zero Execution: Act as a key technical bridge between internal stakeholders, the Okta on Okta team, and core Product teams. Lead the early adoption of cutting-edge internal capabilities, providing rigorous technical feedback to mature products before global release.
  • Architecture & Hands-On Implementation: Own the lifecycle, policy design, adaptive MFA, and federation (SAML, OIDC) for enterprise Okta tenants. Architect and enforce cloud IAM guardrails across AWS, GCP, and Azure, building API-based pipelines to automate complex workflows.
  • Technical Leadership & Mentorship: Serve as a core technical anchor for the engineering team. Mentor engineers, act as a primary review authority for IAM designs, and set technical standards across the organization.
  • Operational & Security Governance: Drive automation-first initiatives to eliminate systemic inefficiencies. Partner directly with Security, Audit, and Compliance teams to ensure identity controls natively meet audit requirements (SOC 2, ISO 27001, FedRAMP).
  • AI Security Integration: Drive the secure adoption of AI technologies by governing AI agents, machine identities, and service-to-service authentication within the enterprise identity layer.
  • Cross-Functional Partnering & Metrics: Collaborate with cross-functional partners to advance identity security, establish operational KPIs, and translate complex technical milestones into actionable leadership updates.

What You’ll Bring (Technical Requirements & Qualifications)

To be successful in this role, you should have deep, hands-on architectural experience across the modern identity and cloud infrastructure lifecycle. We are looking for a practitioner who understands both theory and real-world implementation.

  • Domain Experience: 3+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions.
  • Okta Platform Mastery: Deep expertise in managing complex enterprise Okta environments, including hands-on proficiency with Okta Identity Engine (OIE), Directory Integrations, Advanced Policies, Workflows, and Platform APIs.
  • Core Identity Protocols: Advanced expertise in modern authentication and authorization standards (OIDC, OAuth 2.0, SAML 2.0) and phishing-resistant MFA paradigms (FIDO2/WebAuthn, Passkeys).
  • Cloud & Infrastructure as Code: Proven experience defining identity controls as code using Terraform and Okta Workflows. Practical experience designing cloud IAM guardrails across multi-cloud environments (AWS, GCP, Azure) and M2M/service-to-service authentication.
  • Session & Zero Trust Security: Solid background in session lifecycle security, token management/revocation strategies, and continuous access evaluations (CAEP/eSSO) to mitigate session hijacking.
  • Technical Leadership & Mentorship: Demonstrated experience mentoring engineers, driving design reviews, and establishing engineering best practices across teams.
  • Compliance & Automation Mindset: Strong orientation toward automation-first design, with practical experience building identity controls that align with enterprise frameworks (SOC 2, ISO 27001, FedRAMP).
  • Travel: Occasional travel required as needed.

#LI - hybrid

#LI - remote

P5614_3488197

The Okta Experience

  • Supporting Your Well-Being 
  • Driving Social Impact 
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

Skills Required

  • 10+ years experience implementing and/or supporting enterprise IAM solutions
  • Expertise with SSO, MFA, IGA, and PAM
  • Deep expertise in OIDC, OAuth 2.0, and SAML 2.0
  • Experience with FIDO2/WebAuthn, passkeys, and phishing-resistant MFA
  • Understanding of secure session lifetimes, token binding, token revocation, and continuous access evaluation
  • Proven experience designing and securing M2M and service-to-service authentication
  • Knowledge of enterprise secrets management architectures (e.g., Okta Privileged Access)
  • Advanced proficiency with IaC tools, specifically Okta Workflows and Terraform
  • Experience integrating IAM configuration and testing into CI/CD pipelines (GitHub Actions, GitLab CI)
  • Experience leading and developing other engineers
  • Automation-first mindset

Okta Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Okta and has not been reviewed or approved by Okta.

  • Healthcare Strength Health coverage spans medical, dental, vision, mental-health support, and income protection, complemented by preventive care options and wellness resources. These elements indicate robust coverage for both routine needs and more complex situations.
  • Parental & Family Support Policies include paid parental leave, adoption and surrogacy assistance, and fertility and family‑building benefits. Caregiving resources and flexible arrangements help employees navigate family responsibilities.
  • Leave & Time Off Breadth Flexible or unlimited PTO, separate sick time, paid holidays, and a company Wellbeing Week provide multiple avenues for time away. This breadth supports rest, recovery, and work‑life balance.

Okta Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
6,000 Employees
Year Founded: 2009

What We Do

Okta is the leading independent identity provider. The Okta Identity Cloud enables organizations to securely connect the right people to the right technologies at the right time. With more than 7,000 pre-built integrations to applications and infrastructure providers, Okta provides simple and secure access to people and organizations everywhere, giving them the confidence to reach their full potential. More than 10,000 organizations, including JetBlue, Nordstrom, Siemens, Slack, T-Mobile, Takeda, Teach for America, and Twilio, trust Okta to help protect the identities of their workforces and customers.

Similar Jobs

Boeing Logo Boeing

Contracts Specialist

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Brisbane, Queensland, AUS
170000 Employees

Xero Logo Xero

Senior Search Engineer

Cloud • Fintech • Information Technology • Machine Learning • Software
Hybrid
4 Locations
4500 Employees

HiBob Logo HiBob

Customer Experience Specialist

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
Australia
1350 Employees

Boeing Logo Boeing

Design Engineer

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Brisbane, Queensland, AUS
170000 Employees

Similar Companies Hiring

Rundoo Thumbnail
Cloud • Information Technology • Internet of Things • Software
Redwood City, California
70 Employees
NetBox Labs Thumbnail
Cloud • Software
US
125 Employees
Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account