Senior IAM Engineer — Enterprise Identity & Zero-Trust Lead

Pho Prime, LLC

Shelton (CT)

On-site

USD 120,000 - 170,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Mobility Allowance

Job summary

Subway is seeking a Sr. IAM Engineer to own and evolve the enterprise identity platform. You will design, implement, and secure federation, provisioning, and access governance across Okta, Entra ID, AD, and multiple SaaS apps in a hybrid environment.

You will mentor engineers, contribute to IAM roadmaps, and drive CI/CD automation with Terraform and scripting. Strong API security and zero-trust practices are essential to protect sensitive systems and data.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field — or equivalent work experience.
  • 7+ years in identity and access management, identity engineering, or security engineering with substantial IAM scope, including senior or lead-level ownership of identity platforms.
  • Deep, protocol-level expertise in OAuth 2.0 and OIDC (grant types, token lifecycles, PKCE, scopes and claims, bearer-token handling) and SAML 2.0 (assertions, metadata exchange, signing and encryption, SP- and IdP-initiated flows).
  • Hands-on expertise with Okta as an enterprise identity broker: Universal Directory, lifecycle management, Okta Workflows, SSO application integration, and SCIM provisioning; Okta Identity Governance experience strongly preferred.
  • Demonstrated application of zero-trust architecture and least-privilege access design in a production enterprise environment.
  • Advanced Active Directory design and administration in a hybrid IDaaS environment: OU and group strategy, GPO design, and tiered administration models; advanced Microsoft Entra ID policy design including Conditional Access, Identity Protection risk policies, and MFA policy.
  • Expert, protocol-level SCIM 2.0 knowledge — core and enterprise schemas, custom schema extensions, PATCH semantics, and provisioning error handling.
  • Strong grounding in API security: OAuth 2.0-protected API design, token validation and scoping, and the OWASP API Security Top 10 including BOLA/IDOR vulnerabilities.
  • Experience securing or governing identity for LLM and agentic AI systems: non-human identity lifecycle, credential scoping for AI agents, and least-privilege controls on machine-to-machine access.
  • Proficiency with CrowdStrike Falcon Identity Protection (ITDR, risk-based policy enforcement) or a comparable ITDR platform; experience querying identity telemetry in an enterprise SIEM.
  • Experience integrating endpoint security with identity on Windows and macOS: device posture signals in access policy, platform SSO/desktop MFA, and MDM integration (Jamf, Intune, or equivalent).
  • Proficient scripting in PowerShell, Python, and bash; DevOps fluency including Git-based source control and CI/CD pipeline authorship (Azure Pipelines or GitHub Actions).
  • 1+ year of experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, SuccessFactors, UKG, or similar).

Responsibilities

  • Engineer and own federation, provisioning, and access governance end to end across Okta, Entra ID, AD, and downstream SaaS apps.
  • Maintain and enhance SCIM 2.0 provisioning between HRIS systems, Okta, and downstream systems; own hybrid attribute-mastering model.
  • Apply zero-trust principles and enforce least privilege across the estate with MFA, device posture, PAM, and access governance.
  • Secure identity for AI systems with scoped credentials and human-in-the-loop authorization; enforce API security and OAuth 2.0 protections.
  • Integrate endpoint security with identity on Windows and macOS; manage device-bound credentials and MFA.
  • Design joiner/mover/leaver automation driven by HRIS events; expand self-service access via Okta and AWS IAM Identity Center; build automation in PowerShell, Python, and bash; manage identity platform code in Git with CI/CD and Terraform.
  • Own day-to-day identity platform operations: SSO apps, incident response, upgrades, MFA management, and telemetry queries in CrowdStrike Falcon Identity Protection.
  • Serve as senior technical authority for IAM architecture; produce design docs, mentor engineers, and contribute to the IAM roadmap.

Skills

OAuth 2.0
OIDC
SAML 2.0
Okta
SCIM provisioning
Zero-trust
MFA
CI/CD
PowerShell
Python
bash
Terraform
Git

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field

Tools

Okta
Entra ID
Active Directory
ServiceNow
Jamf
AWS IAM Identity Center
Terraform
CrowdStrike Falcon Identity Protection

Job description

Subway is seeking a Sr. IAM Engineer to own and evolve the enterprise identity platform. You will design, implement, and secure federation, provisioning, and access governance across Okta, Entra ID, AD, and multiple SaaS apps in a hybrid environment.

You will mentor engineers, contribute to IAM roadmaps, and drive CI/CD automation with Terraform and scripting. Strong API security and zero-trust practices are essential to protect sensitive systems and data.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IAM Architect: Zero-Trust & SSO Leader
Senior IAM Architect: Zero-Trust & SSO Leader

Subway • Shelton (CT)

Hybrid
USD 140,000 - 190,000
Insurance Plans (Medical, Life)
Pension/401K/RSP
Competitive Bonus
+4
IAM Engineer: Identity & Access Automation Lead
IAM Engineer: Identity & Access Automation Lead

Pho Prime, LLC • Shelton (CT)

On-site
USD 90,000 - 130,000
Mobility Allowance
Sr. IAM Engineer
Sr. IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
Sr. IAM Engineer
Sr. IAM Engineer

Subway • Shelton (CT)

Hybrid
USD 140,000 - 190,000
Insurance Plans (Medical, Life)
Pension/401K/RSP
Competitive Bonus
+4
Senior IAM Engineer — Okta & Zero Trust
Senior IAM Engineer — Okta & Zero Trust

Berkley Technology Services • United States

On-site
USD 110,000 - 190,000
Base salary range: $107,000–$198,000
Comprehensive benefits package
IAM Engineer
IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 90,000 - 130,000
Mobility Allowance
Senior IAM Architect — Zero Trust & Enterprise Identity
Senior IAM Architect — Zero Trust & Enterprise Identity

Jobtailor • Massachusetts

On-site
USD 150,000 - 210,000
Senior IAM Engineer: Identity Architecture & Zero Trust
Senior IAM Engineer: Identity Architecture & Zero Trust

Relativity • Louisiana (MO)

On-site
USD 130,000 - 195,000
Health, dental, and vision plans
Parental leave
Flexible work arrangements
+4
Senior IAM Architect: Zero Trust, MFA & SSO Lead
Senior IAM Architect: Zero Trust, MFA & SSO Lead

Interclypse • Maryland

On-site
USD 110,000 - 140,000
Health Insurance
401K with generous company match
Paid time off
Senior IAM Engineer — Enterprise Identity & Zero Trust
Senior IAM Engineer — Enterprise Identity & Zero Trust

Interclypse, Inc. • Annapolis (MD), Northern (KY)

Hybrid
USD 140,000 - 180,000
PTO
Parental Leave
401K matching
+2