IAM Engineer

Pho Prime, LLC

Shelton (CT)

On-site

USD 120,000 - 160,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Subway is seeking an IAM Engineer to own day-to-day identity and access management, ensuring workforce productivity and security across a modern hybrid estate.

You will build Okta workflows, manage SSO integrations (SAML/OIDC), automate tasks with PowerShell or Python, and collaborate with Cybersecurity teams on audits and governance.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field or equivalent work experience.
  • 3–5 years in IAM, identity operations, or related security/infrastructure role.
  • Hands-on experience with Okta or similar IdP; Okta strongly preferred.
  • Working knowledge of SSO/federation protocols — SAML 2.0, OIDC, and OAuth 2.0 fundamentals.
  • Experience with SCIM provisioning concepts and troubleshooting; AD/Entra ID administration.

Responsibilities

  • Operate the identity platform day-to-day: new SSO application setup, access request fulfillment and escalations, MFA management, group and access cleanup, and account lifecycle corrections; troubleshoot provisioning and authentication issues end to end — SCIM sync failures, attribute mismatches, SSO errors — documenting resolutions as runbooks.
  • Handle complex onboarding, offboarding, and HR-driven downstream changes outside automated lifecycle flows, treating offboarding as security-critical work; manage IAM tickets and service requests in ServiceNow meeting SLA targets; serve as an internal escalation point for complex identity issues.
  • Build Okta Workflows for identity lifecycle events, application provisioning, and remediation tasks; expand the Okta access catalog to convert recurring ticket categories into governed self-service with owner/manager approval; implement joiner/mover/leaver automation driven by HRIS events; contribute to AWS access self-service through AWS IAM Identity Center permission sets.
  • Script operational automation in PowerShell or Python — reconciliation, reporting, cleanup, and provisioning tasks; participate in upgrades, patching, and change tickets for identity infrastructure, and the team's shared on-call rotation.
  • Operate SCIM 2.0 provisioning between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, Microsoft 365, and AWS IAM Identity Center; support the transition off a legacy custom SCIM connector to broker-native provisioning; configure SSO integrations (SAML 2.0, OIDC) for new applications.
  • Apply least-privilege principles in daily access work — right-sized group and role assignments, time-bound privileged access, and cleanup of dormant or over-privileged accounts; support Okta Identity Governance operations including access certification campaigns; administer non-human identities and service accounts for LLM and agentic AI integrations applying least-privilege credential-scoping patterns.
  • Collaborate with the broader Cybersecurity engineering teams on shared projects; assist investigations of access anomalies; support audits with access evidence; author and maintain runbooks and knowledge-base articles.

Skills

Okta administration
SSO integration
Identity governance
SCIM provisioning
PowerShell
Python
ServiceNow
REST APIs
Active Directory
Entra ID / MS 365

Education

Bachelor's degree in Computer Science or related field

Tools

ServiceNow
Git
CI/CD
Jamf
AWS IAM Identity Center
HRIS/HRIS tooling

Job description

At Subway, we are not standing still. We are building.

This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.

You will not just do the work. You will shape it.

We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.

If you bring energy, accountability and a bias for action, you will fit right in.

We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.

This is your chance to be part of what’s next.

Position Overview

The IAM Engineer builds and operates the day-to-day identity and access management capabilities that keep Subway's workforce productive and secure. Subway runs a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This is a hands-on operational and engineering role — owning the daily health of the identity platform while building the automation that steadily retires manual work. The role carries a clear development path toward senior-level identity engineering, including deeper federation and protocol work, access governance, identity threat detection, and security architecture.

Responsibilities

  • Operate the identity platform day to day: new SSO application setup, access request fulfillment and escalations, MFA management, group and access cleanup, and account lifecycle corrections; troubleshoot provisioning and authentication issues end to end — SCIM sync failures, attribute mismatches, SSO errors — performing root-cause analysis and documenting resolutions as runbooks.
  • Handle complex onboarding, offboarding, and HR-driven downstream changes outside automated lifecycle flows, treating offboarding as security-critical work; manage IAM tickets and service requests in ServiceNow meeting SLA targets; serve as an internal escalation point for complex identity issues from the Technology Support Center and business teams.
  • Build Okta Workflows for identity lifecycle events, application provisioning, and remediation tasks; expand the Okta access catalog to convert recurring ticket categories into governed self-service with owner/manager approval; implement joiner/mover/leaver automation driven by HRIS events; contribute to AWS access self-service through AWS IAM Identity Center permission sets.
  • Script operational automation in PowerShell or Python — reconciliation, reporting, cleanup, and provisioning tasks; participate in upgrades, patching, and change tickets for identity infrastructure, and the team's shared on-call rotation.
  • Operate SCIM 2.0 provisioning between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, Microsoft 365, and AWS IAM Identity Center; support the transition off a legacy custom SCIM connector to broker-native provisioning; configure SSO integrations (SAML 2.0, OIDC) for new applications.
  • Apply least-privilege principles in daily access work — right-sized group and role assignments, time-bound privileged access, and cleanup of dormant or over-privileged accounts; support Okta Identity Governance operations including access certification campaigns; administer non-human identities and service accounts for LLM and agentic AI integrations applying least-privilege credential-scoping patterns.
  • Collaborate with the broader Cybersecurity engineering teams on shared projects; assist investigations of access anomalies alongside senior engineers and the Detect & Respond team; support internal and external audits with access evidence; author and maintain runbooks, knowledge-base articles, and hand-off documentation for new automations.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field — or equivalent work experience.
  • 3–5 years in IAM, identity operations, systems administration with significant identity scope, or a related security/infrastructure role.
  • Hands-on experience with Okta or a comparable identity provider: user and group administration, application SSO integration, and lifecycle management; Okta strongly preferred.
  • Working knowledge of SSO and federation protocols — SAML 2.0, OIDC, and OAuth 2.0 fundamentals — sufficient to configure and troubleshoot integrations.
  • Working knowledge of SCIM provisioning concepts and troubleshooting: attribute mapping, sync errors, and reconciliation.
  • Active Directory fundamentals (users, groups, OUs, group policy awareness) and familiarity with Microsoft Entra ID and Microsoft 365 administration.
  • Scripting proficiency in PowerShell or Python for operational automation (both, plus bash, preferred).
  • Experience working with REST APIs: authentication, reading API documentation, and basic troubleshooting of API-driven integrations.
  • Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.
  • Comfort working with Git-based source control and participating in CI/CD-based change processes.
  • Hands-on fluency with LLM and generative AI tools in day-to-day technical work.

Preferred Qualifications

  • Working understanding of how AI agents authenticate and are authorized to enterprise systems — non-human identities, credential scoping, and emerging integration patterns such as the Model Context Protocol (MCP) — including experience building, deploying, or securing MCP servers or agentic AI workflows.
  • Exposure to identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar) or SIEM platforms.
  • Awareness of API security concepts including the OWASP API Security Top 10 and authorization flaws such as BOLA/IDOR.
  • Exposure to endpoint management and device trust as they relate to identity (Jamf, Intune) on Windows or macOS.
  • Experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, UKG, or similar).
  • AWS IAM or AWS IAM Identity Center exposure.
  • Okta Certified Professional/Administrator or Microsoft identity certification (SC-300).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. IAM Engineer
Sr. IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
IAM Engineer
IAM Engineer

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 110,000 - 150,000
Medical & Life Insurance
401K / Pension
Competitive Bonus
+4
IAM Engineer
IAM Engineer

Subway • Shelton (CT)

On-site
USD 110,000 - 140,000
Insurance Plans (Medical) and Life
Pension/401K
Competitive Bonus
+5
Sr. IAM Engineer
Sr. IAM Engineer

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 130,000 - 170,000
Insurance Plans (Medical, Life)
Pension/401K/RSP
Competitive Bonus
+4
Senior Identity Engineer
Senior Identity Engineer

Tyler Technologies • United States

On-site
USD 140,000 - 200,000
Senior Identity Engineer
Senior Identity Engineer

Tyler-Technologies-29572f8 • Troy (MI)

On-site
USD 110,000 - 140,000
IAM Engineer
IAM Engineer

The Clearing House • North Carolina

Hybrid
USD 90,000 - 130,000
Security Operations Analyst
Security Operations Analyst

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 85,000 - 115,000
Medical & Life Insurance
Pension/401K
Bonus
+4
IAM Engineer-
IAM Engineer-

Associates Systems LLC • Irving (TX)

On-site
USD 120,000 - 160,000
Identity and Access Management (IAM) Engineer
Identity and Access Management (IAM) Engineer

Universal Technologies • United States

Hybrid
USD 120,000 - 180,000
Competitive Compensation
Health, Dental, Vision Benefits
401k Retirement Plan
+2