Get more replies from employers
Send a job-specific resume in minutes.
Subway is seeking a Sr. IAM Engineer to own and evolve the enterprise identity platform. You will design, implement, and secure federation, provisioning, and access governance across Okta, Entra ID, AD, and multiple SaaS apps in a hybrid environment.
You will mentor engineers, contribute to IAM roadmaps, and drive CI/CD automation with Terraform and scripting. Strong API security and zero-trust practices are essential to protect sensitive systems and data.
At Subway, we are not standing still. We are building.
This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.
You will not just do the work. You will shape it.
We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.
If you bring energy, accountability and a bias for action, you will fit right in.
We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.
This is your chance to be part of what’s next.
The Sr. IAM Engineer is a hands-on senior technologist responsible for engineering, securing, and evolving Subway's enterprise identity platform. Subway operates a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This role owns complex federation, provisioning, and access-governance problems end to end, treating identity infrastructure as software — version-controlled, tested, deployed through CI/CD pipelines, and observable in production. The Sr. IAM Engineer serves as a senior subject matter expert and co-owner of IAM technical direction, a technical mentor within the IAM team, and a trusted design partner to Cybersecurity, Infrastructure, and HR Technology.
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field — or equivalent work experience.
• 7+ years in identity and access management, identity engineering, or security engineering with substantial IAM scope, including senior or lead-level ownership of identity platforms.
• Deep, protocol-level expertise in OAuth 2.0 and OIDC (grant types, token lifecycles, PKCE, scopes and claims, bearer-token handling) and SAML 2.0 (assertions, metadata exchange, signing and encryption, SP- and IdP-initiated flows).
• Hands-on expertise with Okta as an enterprise identity broker: Universal Directory, lifecycle management, Okta Workflows, SSO application integration, and SCIM provisioning; Okta Identity Governance experience strongly preferred.
• Demonstrated application of zero-trust architecture and least-privilege access design in a production enterprise environment.
• Advanced Active Directory design and administration in a hybrid IDaaS environment: OU and group strategy, GPO design, and tiered administration models; advanced Microsoft Entra ID policy design including Conditional Access, Identity Protection risk policies, and MFA policy.
• Expert, protocol-level SCIM 2.0 knowledge — core and enterprise schemas, custom schema extensions, PATCH semantics, and provisioning error handling.
• Strong grounding in API security: OAuth 2.0-protected API design, token validation and scoping, and the OWASP API Security Top 10 including BOLA/IDOR vulnerabilities.
• Experience securing or governing identity for LLM and agentic AI systems: non-human identity lifecycle, credential scoping for AI agents, and least-privilege controls on machine-to-machine access.
• Proficiency with CrowdStrike Falcon Identity Protection (ITDR, risk-based policy enforcement) or a comparable ITDR platform; experience querying identity telemetry in an enterprise SIEM.
• Experience integrating endpoint security with identity on Windows and macOS: device posture signals in access policy, platform SSO/desktop MFA, and MDM integration (Jamf, Intune, or equivalent).
• Proficient scripting in PowerShell, Python, and bash; DevOps fluency including Git-based source control and CI/CD pipeline authorship (Azure Pipelines or GitHub Actions).
• 1+ year of experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, SuccessFactors, UKG, or similar).
• AWS IAM and AWS IAM Identity Center experience, particularly permission-set-based access management.
• Exposure to dedicated IGA tooling (SailPoint, Saviynt, Omada) at design or implementation level.
• Familiarity with NIST SP 800-63 (digital identity assurance) and NIST SP 800-207 (zero trust architecture).
• Background in regulated, franchise, or multi-entity environments where identity governance crosses organizational boundaries.
• Relevant certifications: Okta Certified Professional/Consultant, CISSP, SC-300, or AWS Security Specialty.
• Mobility Allowance