Senior Iam Engineer

Tempus AI · Vertical AI · Chicago, IL

Senior IAM Engineer responsible for architecting, implementing, and maintaining identity solutions, focusing on automation with Okta Workflows and API integrations. Key responsibilities include designing Okta tenant, automating lifecycle management, managing hybrid identity, integrating applications via APIs, and ensuring security and compliance (SOC2/ISO 27001/SOX). Requires deep understanding of SAML, OIDC, OAuth 2.0, SCIM, and Active Directory, with proficiency in Python, PowerShell, or JavaScript.

What you'd actually do

  1. Architectural Leadership: Design and scale our Okta tenant, ensuring high availability and global best practices for SAML, OIDC, and OAuth 2.0 integrations.
  2. Automation & Orchestration: Build complex lifecycle management (LCM) flows using Okta Workflows to automate joiner/mover/leaver processes across HRIS, AD, and downstream SaaS apps.
  3. Hybrid Identity Management: Manage and optimize the synchronization between Active Directory (AD) and cloud identity providers.
  4. API Integration: Develop custom integrations using REST APIs to connect homegrown or niche applications that lack out-of-the-box support.
  5. Security & Compliance: Implement Adaptive Multi-Factor Authentication (MFA), Passwordless strategies, and regular access certifications to meet SOC2/ISO 27001/SOX requirements.

Skills

Required

  • Okta
  • SAML 2.0
  • OIDC
  • OAuth 2.0
  • SCIM
  • Active Directory
  • Python
  • PowerShell
  • JavaScript
  • Zero Trust Architecture
  • Least Privilege

Nice to have

  • Okta Certified Professional/Administrator/Consultant
  • Terraform
  • Privileged Access Management (PAM)
  • Identity Governance and Administration (IGA)

What the JD emphasized

  • SOC2/ISO 27001/SOX requirements