Senior Identity Engineer

Tyler Technologies

United States

On-site

USD 140,000 - 200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Tyler Technologies seeks an experienced IAM Architect to own identity platforms including Okta, Entra ID, and Active Directory. You will architect identity lifecycles, build workflows, and enable secure authentication across enterprise applications.

The role covers SSO strategy, access governance, and automation for Joiner/Mover/Leaver processes. Key duties include designing authentication policies, mentoring engineers, and leading remediation of directory hygiene.

Qualifications

  • Minimum 5 years of IT experience with a meaningful portion in identity and access management in a mid-to-large enterprise.
  • Hands-on experience with Okta Workforce Identity, Universal Directory, Lifecycle Management, Workflows, Access Gateway, Okta Identity Engine.
  • Hands-on experience with Microsoft Entra ID — Conditional Access, app registrations, enterprise apps, PIM, B2B, hybrid join.
  • Active Directory engineering across multi-domain/multi-forest environments, GPO, Sites & Services, ADFS, AD/Entra Connect, PowerShell.
  • Experience with AWS IAM, IAM Identity Center, AWS Managed AD, and federation patterns.
  • Production experience designing and operating SAML 2.0, OIDC/OAuth 2.0, SCIM 2.0, WS-Fed integrations.
  • Experience automating identity lifecycle (Joiner/Mover/Leaver) from HRIS source.
  • Strong scripting/automation: PowerShell (required) and Python/JavaScript/Terraform/JSON.
  • Experience with MFA platforms and modern authenticators (Okta Verify, MS Authenticator, FIDO2).
  • Familiarity with compliance frameworks: NIST CSF, SOC 2, SOX, CJIS, FedRAMP.
  • Excellent written and verbal communication and documentation discipline.
  • Working knowledge of Windows, Linux and macOS.
  • Some travel is required.
  • Fingerprint background check clearance for CJIS requirements.

Responsibilities

  • Serve as the technical owner and SME for Okta, Entra ID, and AD.
  • Architect and operate identity lifecycle pipelines (UKG → Okta → AD).
  • Design and build Okta Workflows for Joiner/Mover/Leaver automation.
  • Engineer bridges for non-native integrations (Lambda, Azure Functions).
  • Own SSO strategy, onboarding standards, and Okta catalog.
  • Design and maintain authentication and access policies (MFA, adaptive risk).
  • Lead AD hygiene: stale accounts, group hygiene, GPO reviews, SPN management.
  • Build identity dashboards across AD/Okta/Entra for visibility.
  • Maintain non-production tenants for testing and rehearsal.
  • Mentor IT Analysts and Engineers across Okta/Entra/AD.
  • Participate in Agile/Scrumban ceremonies using JSM/Jira.
  • Document architecture diagrams, runbooks, SOPs, training paths.
  • Participate in IT projects, changes, incidents and on-call rotation.

Skills

IAM architecture
Okta Workflows
Okta Workforce Identity
Okta Universal Directory
Okta Lifecycle Management
Okta AD Agent write-back
Microsoft Entra ID
Conditional Access
Active Directory engineering
PowerShell
Scripting: Python/JavaScript/TF/JSON
MFA platforms
Compliance frameworks (NIST SOC2 SOX)
Documentation & communication
Cross-platform (Windows/Linux/macOS)
Travel readiness

Education

Okta Certified Professional / Administrator / Architect
Microsoft SC-300 — Identity & Access Administrator Associate
Microsoft AZ-500 — Azure Security Engineer
Microsoft AZ-800 / AZ-801 — Windows Server Hybrid Administrator
AWS Certified Security – Specialty
CISSP / SANS GIAC (GCIA / GCIH / GPCS) or equivalent

Tools

AD/Entra Connect
AWS IAM Identity Center

Job description

Description
  • Serve as the technical owner and subject matter expert for Okta (Workforce Identity + Identity Governance), Microsoft Entra ID, and Active Directory.
  • Architect and operate the UKG → Okta → AD identity lifecycle pipeline, including UKG Pro connector validation, attribute mapping, Universal Directory profile design, and Okta AD Agent write-back.
  • Design and build Okta Workflows for Joiner / Mover / Leaver automation, including SCIM provisioning, HTTP connector flows, and migration of Azure Runbooks into Okta Workflows.
  • Engineer application bridges for downstream targets Okta does not natively integrate, such as with Lambda and Azure Functions.
  • Ownership of SSO strategy (SAML, OIDC, SCIM, Federation), application onboarding standards, and the Okta application catalog.
  • Design and maintain authentication and access policies. Multifactor Authentication, adaptive risk-based authentication, network zones and authenticator enrollment policies.
  • Lead Active Directory hygiene and remediation: stale account cleanup, group rationalization, GPO linkage reviews, SPN management, OU placement standards, and contractor census alignment.
  • Build and operate identity dashboards across AD / Okta / Entra ID for operational visibility and license utilization.
  • Maintain non-production tenants for testing, validation, and change rehearsal prior to production cutover.
  • Mentor IT Analysts and Infrastructure Engineers across Okta, Entra ID, and AD.
  • Participate in Agile/Scrumban ceremonies using JSM/Jira as the system of record.
  • Document and maintain architecture diagrams, configuration baselines, runbooks, SOPs, and training paths.
  • Participate in IT projects, change management, incident response, and on-call rotation for identity platform issues.
Responsibilities
  • Serve as the technical owner and subject matter expert for Okta (Workforce Identity + Identity Governance), Microsoft Entra ID, and Active Directory.
  • Architect and operate the UKG → Okta → AD identity lifecycle pipeline, including UKG Pro connector validation, attribute mapping, Universal Directory profile design, and Okta AD Agent write-back.
  • Design and build Okta Workflows for Joiner / Mover / Leaver automation, including SCIM provisioning, HTTP connector flows, and migration of Azure Runbooks into Okta Workflows.
  • Engineer application bridges for downstream targets Okta does not natively integrate, such as with Lambda and Azure Functions.
  • Ownership of SSO strategy (SAML, OIDC, SCIM, Federation), application onboarding standards, and the Okta application catalog.
  • Design and maintain authentication and access policies. Multifactor Authentication, adaptive risk-based authentication, network zones and authenticator enrollment policies.
  • Lead Active Directory hygiene and remediation: stale account cleanup, group rationalization, GPO linkage reviews, SPN management, OU placement standards, and contractor census alignment.
  • Build and operate identity dashboards across AD / Okta / Entra ID for operational visibility and license utilization.
  • Maintain non-production tenants for testing, validation, and change rehearsal prior to production cutover.
  • Mentor IT Analysts and Infrastructure Engineers across Okta, Entra ID, and AD.
  • Participate in Agile/Scrumban ceremonies using JSM/Jira as the system of record.
  • Document and maintain architecture diagrams, configuration baselines, runbooks, SOPs, and training paths.
  • Participate in IT projects, change management, incident response, and on-call rotation for identity platform issues.
Qualifications
  • Minimum 5 years of IT experience with a meaningful portion dedicated to identity and access management in a mid-to-large sized enterprise.
  • Hands-on experience with Okta --Workforce Identity, Universal Directory, Lifecycle Management, Workflows, Access Gateway, Okta Identity Engine.
  • Hands-on experience with Microsoft Entra ID — Conditional Access, app registrations, enterprise apps, PIM, B2B, hybrid join.
  • Active Directory engineering experience — multi-domain/multi-forest, Group Policy, Sites & Services, ADFS, AD/Entra Connect, PowerShell.
  • Working knowledge of AWS IAM, IAM Identity Center, AWS Managed AD, and federation patterns.
  • Production experience designing and operating SAML 2.0, OIDC/OAuth 2.0, SCIM 2.0, and WS-Fed integrations.
  • Experience automating identity lifecycle (Joiner / Mover / Leaver) from an HRIS source.
  • Strong scripting/automation skills: PowerShell (required) and at least one of Python, JavaScript, Terraform, and/or JSON.
  • Experience with MFA platforms and modern authenticators (Okta Verify, Microsoft Authenticator, FIDO2 / hardware-based keys).
  • Familiarity with compliance frameworks: NIST CSF, SOC 2, SOX, CJIS, FedRAMP.
  • Excellent written and verbal communication and documentation discipline.
  • Working knowledge of Windows, Linux and macOS.
  • Some travel is required.
  • Will be required to undergo and satisfactorily pass a fingerprint background check (for CJIS requirements).
Certifications
  • Okta Certified Professional / Administrator / Consultant / Architect
  • Microsoft SC-300 — Identity & Access Administrator Associate
  • Microsoft AZ-500 — Azure Security Engineer
  • Microsoft AZ-800 / AZ-801 — Windows Server Hybrid Administrator
  • AWS Certified Security – Specialty (SCS-C02)
  • CISSP, SANS GIAC (GCIA / GCIH / GPCS), or equivalent)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity Engineer
Senior Identity Engineer

Tyler-Technologies-29572f8 • Plano (TX)

On-site
USD 110,000 - 140,000
Identity Management Consultant
Identity Management Consultant

HireTalent - Staffing & Recruiting Firm • Louisville (KY)

Remote
USD 80,000 - 100,000
Sr. IAM Engineer
Sr. IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
Sr. IAM Engineer, Infrastructure Services
Sr. IAM Engineer, Infrastructure Services

Scorpion Therapeutics • Bridgewater (MA)

On-site
USD 120,000 - 180,000
Cybersecurity Staff Engineer
Cybersecurity Staff Engineer

srsdistribution • United States

Hybrid
USD 180,000 - 240,000
Senior Identity and Access Engineer
Senior Identity and Access Engineer

EXOS • Indianapolis (IN)

On-site
USD 75,000 - 100,000
IT Systems Administrator (62996)
IT Systems Administrator (62996)

Union Community Care • Lancaster

On-site
USD 90,000 - 120,000
Senior Specialist, Lead Zero Trust Identity Security Engineering
Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard • Dallas (TX)

On-site
USD 190,000 - 230,000
Senior Identity and Access Management Analyst
Senior Identity and Access Management Analyst

Baptist Memorial Health Care Corporation • Memphis (TN)

On-site
USD 110,000 - 140,000
Senior Technical Architect, Okta
Senior Technical Architect, Okta

Okta • Washington

On-site
USD 90,000 - 130,000