Architect and deploy enterprise Okta Identity Engine implementations, including SSO, MFA policies, federation, lifecycle management, SCIM provisioning, and Okta Workflows automation.
Implement phishing‑resistant MFA using FIDO2/WebAuthn, platform authenticators, roaming security keys, passkeys, and government‑grade credentials per CISA/OMB guidance.
Design and integrate IGA + PAM capabilities (SailPoint IIQ/IDN, CyberArk, Delinea/Thycotic, BeyondTrust) to enforce least privilege, JIT access, and robust access governance.
Produce engineering deliverables: architecture diagrams, configuration standards, build/run books, migration plans, and cutover strategies.
Mentor engineers and consultants; lead workshops with business & technical stakeholders; support pursuit teams with solutioning and orals.
Requirements
Due to nature of client engagement, must be a US Citizen
High School Diploma AND Fourteen (14+) plus years relevant paid professional experience; Or Associate’s degree AND Twelve (12+) plus years relevant paid professional experience; Or Bachelor’s degree AND Ten (10+) plus years relevant paid professional experience
Total paid professional work experience MUST include 8+ years in IAM AND 5+ years engineering and architecting Okta solutions at enterprise scale
Deep experience with Okta (OIE policies, FastPass, integration network, federation, logs), authentication standards (SAML, OIDC, OAuth2, SCIM, directory integrations).
Hands‑on implementation experience with IAM tools such as SailPoint, CyberArk, Delinea, BeyondTrust, Radiant Logic, and Microsoft Entra ID/AD.