Skip to content
← Back to job listings

Staff Identity Engineer

Okta · Washington, United States

Imported listingfull-time4 days ago

About The Role

Join Okta as a Staff Identity Engineer, where you will be a technical authority within our internal IAM team. You will drive the architecture and execution of our identity fabric, champion our "Customer Zero" philosophy, and serve as a mentor to other engineers. This role requires a deep understanding of modern identity and cloud infrastructure, as well as experience in designing and implementing enterprise-scale IAM solutions.

  • Act as a key technical bridge between internal stakeholders, the Okta on Okta team, and core Product teams, leading the early adoption of cutting-edge internal capabilities.
  • Own the lifecycle, policy design, adaptive MFA, and federation (SAML, OIDC) for enterprise Okta tenants, architecting and enforcing cloud IAM guardrails across AWS, GCP, and Azure.
  • Serve as a core technical anchor for the engineering team, mentoring engineers, acting as a primary review authority for IAM designs, and setting technical standards across the organization.
  • To be successful in this role, you should have deep, hands-on architectural experience across the modern identity and cloud infrastructure lifecycle. We are looking for a practitioner who understands both theory and real-world implementation
  • Session & Zero Trust Security: Solid background in session lifecycle security, token management/revocation strategies, and continuous access evaluations (CAEP/eSSO) to mitigate session hijacking
  • Compliance & Automation Mindset: Strong orientation toward automation-first design, with practical experience building identity controls that align with enterprise frameworks (SOC 2, ISO 27001, FedRAMP)
  • Okta Platform Mastery: Deep expertise in managing complex enterprise Okta environments, including hands-on proficiency with Okta Identity Engine (OIE), Directory Integrations, Advanced Policies, Workflows, and Platform APIs
  • Core Identity Protocols: Advanced expertise in modern authentication and authorization standards (OIDC, OAuth 2.0, SAML 2.0) and phishing-resistant MFA paradigms (FIDO2/WebAuthn, Passkeys)
  • Cloud & Infrastructure as Code: Proven experience defining identity controls as code using Terraform and Okta Workflows. Practical experience designing cloud IAM guardrails across multi-cloud environments (AWS, GCP, Azure) and M2M/service-to-service authentication
  • Technical Leadership & Mentorship: Demonstrated experience mentoring engineers, driving design reviews, and establishing engineering best practices across teams
  • Domain Experience: 4+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions
  • Travel: Occasional travel required as needed
  • U.S. soil status - the employee must be on U.S. soil, which means the 50 states, the District of Columbia, or outlying areas of the United States, as defined in Federal Acquisition Regulation (FAR) 2.101, and be a U.S. person
  • U.S. person status - the employee must be either a U.S. citizen as defined in 42 U.S. Code § 9102; a natural person who is a lawful permanent resident as defined in 8 U.S.C. 1101(a)(20) or who is a protected individual as defined by 8 U.S.C. 1324b(a)(3); or a U.S. national (i.e. includes citizens and non-citizens born in outlying possessions such as American Samoa and Swains Island), green card holders, refugees, and asylees. Working on a U.S. visa does NOT qualify as a U.S. person

This is an external listing. JobSpring does not represent or verify the employer. Report this listing