Senior ICAM Engineer, Full Time, Remote

Socket.dev

Oregon (WI)

Hybrid

USD 130,000 - 170,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health plan
401k with employer match
Paid time off (PTO)
Training & development

Job summary

Mount Airey Group (MAG), a Technologist Inc. subsidiary, seeks a Senior ICAM Engineer for a full-time remote role.

You will engineer, automate, administer, and support enterprise ICAM services across cloud and on-prem environments, focusing on Okta, SSO, MFA, and Zero Trust initiatives. You will develop automation via PowerShell and Okta REST APIs, evaluate new automation technologies, and collaborate with cybersecurity, infrastructure, and application teams to improve security and efficiency.

Qualifications

  • Experience implementing and supporting SSO (SAML 2.0, OAuth 2.0, OIDC)
  • Experience configuring and maintaining MFA and identity federation
  • Experience with user lifecycle provisioning/deprovisioning and attribute transformations
  • Experience with Active Directory/LDAP
  • Experience integrating REST APIs and JSON payloads
  • Experience automating identity tasks using PowerShell
  • Ability to obtain Secret clearance
  • Bachelor's degree or equivalent professional experience
  • 2+ years with Okta Identity Cloud or 3+ years with IAM platforms such as Entra ID, Ping Identity, ForgeRock

Responsibilities

  • Administer, configure, and maintain Okta Identity Cloud environments
  • Design and troubleshoot SSO integrations (SAML 2.0, OAuth 2.0, OIDC)
  • Configure authentication policies and adaptive MFA
  • Develop user lifecycle automation and provisioning workflows
  • Design and support identity federation with IdPs
  • Develop profile mappings and identity schemas
  • Integrate applications with Okta and ensure compliance
  • Troubleshoot identity auth, provisioning, and sync issues
  • Develop PowerShell automation and REST API scripts
  • Create automated batch processes for identity management
  • Develop automation tools to improve efficiency
  • Collaborate with security and IT teams on Zero Trust initiatives
  • Conduct testing, deployments, and Tier III support
  • Evaluate new identity technologies and automation solutions

Skills

SSO
MFA
Identity Federation
User Lifecycle Management
REST API integrations
Automation
JSON payloads
PowerShell
Okta REST APIs

Education

Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field

Tools

Okta Identity Cloud
Microsoft Entra ID
Ping Identity
PowerShell
Okta REST APIs
REST APIs
JSON

Job description

Mount Airey Group (MAG), a wholly owned subsidiary of Technologist Inc., is seeking a Senior Identity, Credential and Access Management (ICAM) Engineer to join our team. This is a full-time telework opportunity offering a competitive salary coupled with a stellar benefits package effective your first day of employment.
The Senior ICAM Engineer is responsible for the engineering, implementation, automation, administration, and operational support of enterprise Identity, Credential, and Access Management (ICAM) services. This role designs and implements secure identity solutions supporting authentication, authorization, identity lifecycle management, and Zero Trust initiatives. The engineer develops automation using PowerShell and the Okta REST APIs to improve operational efficiency, reduce manual administration, and support enterprise identity operations across cloud and on-premises environments. The engineer will also evaluate and adopt emerging automation technologies, including Python, to enhance future automation capabilities.
Primary Responsibilities
Administer, configure, and maintain enterprise Okta Identity Cloud environments supporting workforce identity and access management.
Design, implement, and troubleshoot Single Sign-On (SSO) integrations using SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
Configure and maintain authentication policies, adaptive Multi-Factor Authentication (MFA), phishing-resistant authentication, and application sign‑on policies.
Develop and maintain user lifecycle automation, including provisioning, deprovisioning, profile mappings, attribute transformations, group rules, and application assignments.
Design, configure, and support inbound and outbound identity federation with internal and external Identity Providers (IdPs).
Develop and maintain custom user profile attributes, application profile mappings, and identity schemas to support business and partner requirements.
Integrate enterprise applications with Okta while ensuring compliance with organizational security policies and Federal ICAM standards.
Troubleshoot complex authentication, federation, provisioning, authorization, and identity synchronization issues across cloud and on-premises environments.
Develop and maintain PowerShell automation utilizing the Okta REST APIs to perform administrative functions, user lifecycle management, reporting, and large‑scale user profile updates.
Design and execute automated batch processes for creating, modifying, and updating user identities while ensuring data integrity, consistency, and auditability.
Develop reusable automation scripts and tools that improve operational efficiency and reduce manual administrative effort.
Integrate enterprise systems using REST APIs to automate identity management workflows and improve data consistency across identity repositories.
Evaluate and develop future automation capabilities using Python to support API integrations, reporting, and enterprise automation initiatives.
Support Public Key Infrastructure (PKI), PIV/CAC authentication, certificate-based authentication, and smart card integrations.
Develop technical architecture documentation, implementation guides, standard operating procedures, workflow diagrams, and engineering documentation.
Participate in Zero Trust initiatives by implementing modern identity‑centric security controls and authentication mechanisms.
Analyze identity‑related security events and assist with audit, compliance, and forensic investigations.
Collaborate with cybersecurity, infrastructure, networking, and application teams to implement secure identity solutions.
Perform testing, change management, production deployments, and Tier III engineering support for enterprise identity services.
Research, evaluate, and recommend new identity technologies and automation solutions that improve security, reliability, and operational efficiency.

Technical Requirements
  • Okta Identity Cloud
  • Microsoft Entra ID
  • Ping Identity
  • PowerShell
  • Okta REST APIs
REST APIs
JSON

Identity Lifecycle Management
SAML 2.0
OAuth 2.0
OpenID Connect (OIDC)
Multi‑Factor Authentication
Identity Federation
Active Directory

LDAP
PKI

PIV/CAC Authentication
Zero Trust Architecture
Technical Documentation
Enterprise Identity Troubleshooting

Expected Experience
Experience implementing and supporting
  • Single Sign‑On (SAML 2.0, OAuth 2.0, OpenID Connect)
  • Multi‑Factor Authentication (MFA)
  • Identity Federation
  • User Lifecycle Management
  • Active Directory and LDAP
  • REST API integrations
  • Experience developing automation using PowerShell.
  • Experience consuming and integrating REST APIs.
  • Experience working with JSON and API payloads.
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent professional experience.
  • Minimum of 2 (two) years of daily hands‑on experience administering and engineering solutions using Okta Identity Cloud, including application integrations, identity lifecycle management, automation, and REST API development.
  • OR — Minimum of 3 (three) years of hands‑on experience administering an enterprise Identity and Access Management platform such as Microsoft Entra ID, Ping Identity, ForgeRock, or a comparable IAM solution.
  • Ability to obtain Secret level clearance.
  • Ability to travel to Washington, DC for important meetings.
  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, with employer match)
  • Paid Time Off (Vacation, Sick & Federal Holidays)
  • Short Term & Long Term Disability
  • Training & Development
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity Engineer
Senior Identity Engineer

Tyler-Technologies-29572f8 • Plano (TX)

On-site
USD 110,000 - 140,000
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • United States

On-site
USD 110,000 - 190,000
Base salary range: $107,000–$198,000
Comprehensive benefits package
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • Urbandale (IA)

On-site
USD 121,000 - 137,000
Health insurance
Dental insurance
Vision insurance
+5
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • Wilmington (DE)

On-site
USD 121,000 - 137,000
Health benefits
401(k)
Profit-sharing plans
Senior ICAM Engineer
Senior ICAM Engineer

Easy Dynamics Corp. • United States

On-site
USD 160,000 - 200,000
IAM Architect / Okta Migration / Contract-to-Hire / Hybrid / Palo Alto, CA
IAM Architect / Okta Migration / Contract-to-Hire / Hybrid / Palo Alto, CA

Motion Recruitment • Palo Alto (CA)

Hybrid
USD 150,000 - 230,000
Senior ICAM Engineer: Okta Automation & Zero Trust
Senior ICAM Engineer: Okta Automation & Zero Trust

Socket.dev • Oregon (WI)

Hybrid
USD 130,000 - 170,000
Health plan
401k with employer match
Paid time off (PTO)
+1
IAM Engineer-
IAM Engineer-

Associates Systems LLC • Irving (TX)

On-site
USD 120,000 - 160,000
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • Chicago (IL)

On-site
USD 121,000 - 137,000
Health insurance
Dental insurance
Vision insurance
+2
Specialist, Technical Account Manager - Federal
Specialist, Technical Account Manager - Federal

Okta • Washington

On-site
USD 90,000 - 120,000
Supporting Your Well-Being
Driving Social Impact
Developing Talent and Fostering Connection