Senior Identity Engineer

Tyler-Technologies-29572f8

Plano (TX)

On-site

USD 110,000 - 140,000

Full time

34 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tyler Technologies is seeking an experienced IAM engineer to own Okta, Entra ID, and Active Directory in Plano, TX. You will architect identity pipelines, develop workflows, and implement MFA and SSO strategies across multiple applications. The role requires 5+ years of IAM in enterprise, hands-on with Okta, Entra ID, AD, and AWS IAM, plus strong documentation and collaboration skills. Travel may be required; background check may be needed.

Qualifications

  • 5+ years of IT experience in identity and access management.
  • Hands-on experience with Okta and Entra ID.
  • Active Directory engineering; GPOs, sites, services, ADFS.
  • Experience with SAML, OIDC, SCIM, WS-Fed integrations.
  • Familiarity with MFA platforms and modern authenticators.
  • Excellent written and verbal communication and documentation.

Responsibilities

  • Serve as the technical owner and SME for Okta, Entra ID, and AD identity platforms.
  • Architect and operate identity lifecycles and pipelines across systems.
  • Design and build Okta Workflows for Joiner/Mover/Leaver automation.

Skills

Identity & Access
Okta Workflows
Entra ID
Active Directory
PowerShell
SAML
OIDC

Education

Okta Certification
Microsoft SC-300
Microsoft AZ-500
AZ-800/AZ-801
AWS Security Specialty
CISSP / GIAC

Tools

Okta
Microsoft Entra ID
ADFS
Entra Connect
AWS IAM
Lambda
Azure Functions
Jira

Job description

ITPlano,TexasYarmouth,MaineTroy,MichiganLatham,New YorkUnited States
Salary: USD 110000 - 140000 Annually

  • Serve as the technical owner and subject matter expert for Okta (Workforce Identity + Identity Governance), Microsoft Entra ID, and Active Directory.
  • Architect and operate the UKG → Okta → AD identity lifecycle pipeline, including UKG Pro connector validation, attribute mapping, Universal Directory profile design, and Okta AD Agent write-back.
  • Design and build Okta Workflows for Joiner / Mover / Leaver automation, including SCIM provisioning, HTTP connector flows, and migration of Azure Runbooks into Okta Workflows.
  • Engineer application bridges for downstream targets Okta does not natively integrate, such as with Lambda and Azure Functions.
  • Ownership of SSO strategy (SAML, OIDC, SCIM, Federation), application onboarding standards, and the Okta application catalog.
  • Design and maintain authentication and access policies. Multifactor Authentication, adaptive risk-based authentication, network zones and authenticator enrollment policies.
  • Lead Active Directory hygiene and remediation: stale account cleanup, group rationalization, GPO linkage reviews, SPN management, OU placement standards, and contractor census alignment.
  • Build and operate identity dashboards across AD / Okta / Entra ID for operational visibility and license utilization.
  • Maintain non-production tenants for testing, validation, and change rehearsal prior to production cutover.
  • Mentor IT Analysts and Infrastructure Engineers across Okta, Entra ID, and AD.
  • Participate in Agile/Scrumban ceremonies using JSM/Jira as the system of record.
  • Document and maintain architecture diagrams, configuration baselines, runbooks, SOPs, and training paths.
  • Participate in IT projects, change management, incident response, and on-call rotation for identity platform issues.
Qualifications
  • Minimum 5 years of IT experience with a meaningful portion dedicated to identity and access management in a mid-to-large sized enterprise.
  • Hands‑on experience with Okta --Workforce Identity, Universal Directory, Lifecycle Management, Workflows, Access Gateway, Okta Identity Engine.
  • Hands‑on experience with Microsoft Entra ID — Conditional Access, app registrations, enterprise apps, PIM, B2B, hybrid join.
  • Active Directory engineering experience — multi‑domain/multi‑forest, Group Policy, Sites & Services, ADFS, AD/Entra Connect, PowerShell.
  • Working knowledge of AWS IAM, IAM Identity Center, AWS Managed AD, and federation patterns.
  • Production experience designing and operating SAML 2.0, OIDC/OAuth 2.0, SCIM 2.0, and WS‑Fed integrations.
  • Experience automating identity lifecycle (Joiner / Mover / Leaver) from an HRIS source.
  • Experience with MFA platforms and modern authenticators (Okta Verify, Microsoft Authenticator, FIDO2 / hardware‑based keys).
  • Familiarity with compliance frameworks: NIST CSF, SOC 2, SOX, CJIS, FedRAMP.
  • Excellent written and verbal communication and documentation discipline.
  • Working knowledge of Windows, Linux and macOS.
  • Some travel is required.
  • Will be required to undergo and satisfactorily pass a fingerprint background check (for CJIS requirements).

Certifications

  • Okta Certified Professional / Administrator / Consultant / Architect
  • Microsoft SC-300 — Identity & Access Administrator Associate
  • Microsoft AZ-500 — Azure Security Engineer
  • Microsoft AZ-800 / AZ-801 — Windows Server Hybrid Administrator
  • AWS Certified Security – Specialty (SCS-C02)
  • CISSP, SANS GIAC (GCIA / GCIH / GPCS), or equivalent)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity Engineer
Senior Identity Engineer

Tyler Technologies • United States

On-site
USD 140,000 - 200,000
Identity Management Consultant
Identity Management Consultant

HireTalent - Staffing & Recruiting Firm • Louisville (KY)

Remote
USD 80,000 - 100,000
Senior Identity Engineer (MSP)
Senior Identity Engineer (MSP)

Advisory Solutions • United States

On-site
USD 100,000 - 115,000
Health insurance
401(k) with employer match
Senior ICAM Engineer, Full Time, Remote
Senior ICAM Engineer, Full Time, Remote

Socket.dev • Oregon (WI)

Hybrid
USD 130,000 - 170,000
Health plan
401k with employer match
Paid time off (PTO)
+1
IAM Architect / Okta Migration / Contract-to-Hire / Hybrid / Palo Alto, CA
IAM Architect / Okta Migration / Contract-to-Hire / Hybrid / Palo Alto, CA

Motion Recruitment • Palo Alto (CA)

Hybrid
USD 150,000 - 230,000
Senior Identity and Access Engineer
Senior Identity and Access Engineer

Jobtailor • Town of Florida (NY)

Hybrid
USD 120,000 - 180,000
None
Sr. Identity Security Engineer Active Directory & Entra ID
Sr. Identity Security Engineer Active Directory & Entra ID

MathWorks • Natick (MA)

On-site
USD 122,000 - 190,000
System Engineer
System Engineer

Franklin Fitch • Houston (TX)

On-site
USD 120,000 - 180,000
Senior Identity Specialist
Senior Identity Specialist

Okta • United States

On-site
USD 200,000 - 275,000
Health insurance
401(k)
Flexible spending account
+1
Technical Architect
Technical Architect

Segment (Twilio) • Chicago (IL), New York (NY), Bellevue (WA)

On-site
USD 200,000 - 275,000
Health, dental, and vision insurance
401(k)
Paid leave including PTO and parental leave