Skip to content
← Back to job listings

IAM Pre-Sales Engineer

obscure · Pretoria, GAUTENG, South Africa

Sales - Engineering / Tech / ITQuick applyfull-time18 days ago

About The Role

About the Role

Obscure is looking for a capable IAM Pre-Sales Engineer to join our technical team in Gauteng. Identity is the new perimeter, and this role sits at the heart of how we help clients protect what matters most: the people, systems, and privileged accounts that drive their business.

You will be the trusted techni cal voice on identity, privileged access, and workforce authentication conversations. Working closely with Sales, Engineering, and Professional Services, you will scope solutions, run demonstrations, lead proofs of concept, and partner with clients to design IAM architectures that fit their environment and risk appetite.

Key Responsibilities

  • Identity Discovery: Engage with prospective and existing clients to map their identity landscape — workforce, customer, privileged, and machine identities — and identify the gaps that matter.
  • Solution Design: Architect tailored IAM solutions across our identity portfolio, with a strong focus on CyberArk for privileged access and Okta for workforce identity.
  • Technical Presentations: Present confidently to mixed audiences — from CISOs and risk leaders to IAM administrators and identity architects — translating identity concepts into business outcomes.
  • Demonstrations & Proofs of Concept: Plan, scope, and execute identity demonstrations and POCs, with measurable success criteria agreed up front.
  • Integration Mapping: Position how identity platforms integrate with the broader security stack including SIEM, EDR, MDM, and the wider Obscure vendor portfolio.
  • RFI / RFP Support: Respond to identity-related sections of tenders, RFIs, and RFPs with accuracy and clarity.
  • Client Advisory: Advise clients on identity strategy, zero trust adoption, and the move from on-premise directory services to cloud-first identity.
  • Cross-Functional Collaboration: Work closely with Sales, Marketing, Engineering, and Professional Services to move opportunities through the pipeline and ensure smooth handover to delivery.
  • Industry Engagement: Represent Obscure at industry events, vendor sessions, partner enablement, and customer engagements.

Core Technology Focus

  • This role is anchored in three critical identity domains. The successful candidate must bring real, hands-on familiarity with each.
  • CyberArk — Privileged Access Management
  • Strong understanding of the CyberArk Privileged Access Manager (PAM) suite, including Enterprise Password Vault, Privileged Session Manager (PSM), and Central Policy Manager (CPM)
  • Familiarity with CyberArk Identity (workforce and customer IAM) and the broader Identity Security Platform
  • Understanding of privileged account discovery, onboarding, rotation, and session isolation
  • Awareness of Just-in-Time (JIT) access, Zero Standing Privileges (ZSP), and secrets management for DevOps and machine identities
  • Ability to position CyberArk against competing PAM solutions and articulate clear differentiation

Okta — Workforce Identity

  • Solid working knowledge of Okta Workforce Identity Cloud, including Single Sign-On (SSO), Universal Directory, Adaptive MFA, and Lifecycle Management
  • Familiarity with Okta Identity Governance (OIG) — access requests, certifications, and reporting
  • Understanding of Okta Workflows for low-code identity automation
  • Experience with Okta integrations to common enterprise applications (Microsoft 365, Salesforce, AWS, Workday, ServiceNow)
  • Awareness of Okta Identity Threat Protection and how it complements traditional IAM with continuous risk evaluation

OAuth, OIDC, and Federation Standards

  • Strong grasp of OAuth 2.0 — flows, grant types, scopes, tokens, and where each fits
  • Solid understanding of OpenID Connect (OIDC) as the identity layer on top of OAuth 2.0
  • Working knowledge of SAML 2.0 for legacy federation, and the practical differences between SAML and OIDC
  • Ability to explain federation concepts clearly to both developers and non-technical stakeholders
  • Awareness of common identity attack patterns — token theft, consent phishing, OAuth abuse — and how modern IAM platforms defend against them

Broader IAM Knowledge

Workforce Identity Foundations

  • Understanding of the full workforce identity lifecycle — joiner, mover, leaver — and how it integrates with HR systems
  • Familiarity with role-based access control (RBAC), attribute-based access control (ABAC), and policy-driven access models
  • Working knowledge of access certifications, segregation of duties (SoD), and identity governance principles
  • Awareness of passwordless authentication, FIDO2, WebAuthn, and modern phishing-resistant MFA

Identity in Microsoft and Cloud Environments

  • Solid understanding of Microsoft Entra ID (Azure AD), Active Directory, and how on-premise and cloud directories interoperate
  • Working knowledge of conditional access, privileged identity management (PIM), and identity protection in Microsoft environments
  • Awareness of how identity is deployed and secured in AWS (IAM, IAM Identity Center) and Google Cloud Platform
  • Understanding of cross-cloud identity federation and the challenges of multi-cloud IAM

Identity Security Concepts

  • Strong grasp of zero trust architecture and the central role of identity within it
  • Awareness of Identity Threat Detection and Response (ITDR) and how it complements traditional IAM
  • Understanding of identity-related compliance and regulatory requirements relevant to South African enterprises (POPIA, PCI-DSS, ISO 27001)
  • Familiarity with how identity events feed into a SOC and how IAM platforms integrate with SIEM and SOAR tooling

Experience & Attribute s

  • Experience: Three to five years in an IAM-focused role, ideally with pre-sales or client-facing exposure.
  • Hands-on Foundation: Demonstrable hands-on experience with CyberArk, Okta, or both — not just theoretical knowledge.
  • Presentation Skills: Comfortable presenting to mixed technical and business audiences, both in person and remotely.
  • Technical Depth: Able to explain identity standards and platform mechanics in detail when the audience requires it.
  • Commercial Awareness: Understands how identity decisions tie back to business risk, productivity, and compliance outcomes.
  • Communication: Excellent verbal and written communication skills in English.
  • Self-Driven: Operates with autonomy, manages multiple opportunities in parallel, and follows through to closure.
  • Customer-Centric: Builds trusted relationships with technical and executive stakeholders alike.

This listing was posted by a verified recruiter at obscure. Report this listing