Configure and maintain enterprise IAM platforms, including identity lifecycle workflows, SSO integrations, automated provisioning, MFA policies, and access governance. Enforce least-privilege access controls and support secure integrations, platform updates, regression testing, and patch cycles.
This is a remote position.
IAM (Identity & Access Management) Engineer (Okta / SailPoint)
Job Details
Employment Type: Contract
Work Mode: Remote
Location: Offshore
Total Experience Required: 4 to 8 years
Relevant Experience Required: 3+ years of dedicated implementation and configuration experience across enterprise IAM platforms (Okta or SailPoint)
Mandatory Certification: Okta Certified Professional/Consultant or SailPoint Certified IdentityNow Engineer
Job Summary
We are seeking an experienced IAM Engineer to design, configure, and secure our global identity and access governance footprint. The ideal candidate will orchestrate complex lifecycle management pathways, configure secure single sign-on integrations, build automated user provisioning workflows, and enforce strict zero-trust boundary guidelines across cloud and on-premise application matrices.
Key Responsibilities
Configure and deploy core IAM framework modules, managing user onboarding pipelines, automated lifecycle states, and access certification governance campaigns.
Design and maintain Single Sign-On (SSO) configurations, setting up federated cross-app connections, custom SAML 2.0 / OpenID Connect (OIDC) profiles, and OAuth authorization parameters.
Build automated provisioning workflows, writing system rules, attribute transformations, and direct API connector scripts to manage directory feeds (Active Directory, HR systems).
Govern identity security and access access levels, structuring complex role-based access control (RBAC), attribute-based access control (ABAC), and least-privilege security lines.
Collaborate with enterprise infrastructure teams to support secure connectivity with directory endpoints, internal databases, and downstream SaaS application rings.
Lead update regression validations and patch cycles, auditing platform custom configurations across sandboxes to prevent authentication processing drops.
Requirements
4 to 8 years of core enterprise IT security experience, with 3+ dedicated years actively designing, building, and deploying software within Okta or SailPoint environments.
Strong technical mastery of web identity languages (SAML, OIDC, OAuth), directory structures (LDAP, Active Directory), and SCIM provisioning protocol architectures.
Deep structural understanding of zero-trust network principles, cloud application architectures, security boundary perimeters, and lifecycle tracking metrics.
Mandatory certification: Okta Certified Professional/Consultant OR SailPoint Certified IdentityNow/IdentityIQ Engineer.
Preferred Qualifications
Prior scripting proficiency utilizing JavaScript, Python, or PowerShell to extend platform workflows, automate bulk user transitions, or parse system API logs.
Familiarity with Privileged Access Management (PAM) architectures like CyberArk or BeyondTrust.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”