Sr. IAM Engineer

Franchise World Headquarters, LLC

Shelton (CT)

On-site

USD 130,000 - 170,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Insurance Plans (Medical, Life)
Pension/401K/RSP
Competitive Bonus
Mobility Allowance
Tuition Reimbursement
Company Holidays
Volunteering time

Job summary

Franchise World Headquarters, LLC in Shelton, CT is seeking a Sr. IAM Engineer to own and evolve the enterprise identity platform.

You will implement Okta as the identity broker, manage SCIM provisioning, and enforce zero-trust controls across a hybrid environment including AD/Entra ID and SaaS apps. The role demands senior expertise in IAM design, CI/CD automation, and collaboration with Cybersecurity, HR Tech, and Infrastructure teams.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent work experience.
  • 7+ years in identity and access management with senior ownership of identity platforms.
  • Deep, protocol-level expertise in OAuth 2.0 and OIDC, and SAML 2.0.
  • Hands-on experience with Okta as an enterprise identity broker and SCIM provisioning.
  • Zero-trust architecture and least-privilege design in a production enterprise environment.
  • Active Directory/Entra ID expertise in a hybrid IDaaS environment.
  • Experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, etc.).

Responsibilities

  • Engineer and operate Okta as the enterprise identity broker and perform SSO integrations.
  • Maintain SCIM 2.0 provisioning between HRIS systems, Okta, and downstream systems.
  • Apply zero-trust and least-privilege across the estate with MFA, PAM, and access governance.
  • Secure identity for AI systems with scoped credentials and agent access controls.
  • Integrate endpoint security with identity on Windows and macOS including device posture signals.
  • Design joiner/mover/leaver automation driven by HRIS events and expand self-service access.
  • Own day-to-day IAM operations, incident response, audits support, and telemetry queries.
  • Mentor IAM engineers and contribute to strategic IAM roadmap.

Skills

OAuth 2.0
OIDC
SAML 2.0
Okta
SCIM provisioning
Zero-trust
MFA
PAM
API security
PowerShell
Python
Bash
CI/CD
Git
Terraform
HRIS integration
Active Directory
Entra ID
CrowdStrike Identity Protection

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field

Tools

Okta
Git
Terraform
PowerShell
Python
Bash

Job description

Sr. IAM Engineer

Franchise World Headquarters, LLC

Shelton, CT

Why Join Subway?

At Subway, we are not standing still. We are building.

This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.

You will not just do the work. You will shape it.

We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.

If you bring energy, accountability and a bias for action, you will fit right in.

We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.

This is your chance to be part of what's next.

Position Overview

The Sr. IAM Engineer is a hands‑on senior technologist responsible for engineering, securing, and evolving Subway's enterprise identity platform. Subway operates a modern, broker‑centered identity architecture: an HRIS‑driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This role owns complex federation, provisioning, and access‑governance problems end to end, treating identity infrastructure as software - version‑controlled, tested, deployed through CI/CD pipelines, and observable in production. The Sr. IAM Engineer serves as a senior subject matter expert and co‑owner of IAM technical direction, a technical mentor within the IAM team, and a trusted design partner to Cybersecurity, Infrastructure, and HR Technology.

Responsibilities
  • Engineer and operate Okta as the enterprise identity broker - Universal Directory, lifecycle management, SSO integrations (SAML 2.0, OIDC, WS‑Federation to Microsoft 365), and Okta Workflows; design and troubleshoot federation end to end including assertion and token contents, claim/attribute mapping, signing and encryption, and session behavior across Okta, Entra ID, Active Directory, and downstream SaaS applications.
  • Maintain and enhance SCIM 2.0 provisioning at the protocol level - schemas, custom extensions, PATCH semantics, error handling, and reconciliation - between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, AWS IAM Identity Center, and Microsoft 365; own the hybrid attribute‑mastering model and drive architectural changes that consolidate source‑of‑truth authority.
  • Apply zero‑trust principles and enforce least privilege across the estate: phishing‑resistant MFA and passwordless authentication, continuous evaluation of session and device context, privileged access management (PAM) with time‑bound and just‑in‑time elevation, separation of duties, and access‑governance controls via Okta Identity Governance including access certification campaigns and self‑service access requests.
  • Secure identity for LLM and agentic AI systems - govern non‑human identities, enforce scoped and short‑lived credentials for agent access, apply human‑in‑the‑loop authorization for sensitive actions; apply API security best practices including OAuth 2.0‑protected API design, token validation and scoping, and defense against OWASP API Security Top 10 risks including BOLA/IDOR.
  • Integrate endpoint security with identity on Windows and macOS: device trust and posture signals in authentication policy, Okta FastPass/Device Trust, Entra device compliance, EDR posture, platform SSO, desktop MFA, and device‑bound phishing‑resistant credentials.
  • Design and implement joiner/mover/leaver automation driven by HRIS events; expand self‑service access through the Okta access catalog and AWS IAM Identity Center permission‑set‑based self‑service; build operational automation in PowerShell, Python, and bash; manage identity platform code in Git with peer‑reviewed CI/CD pipelines and Terraform for identity‑bearing cloud resources.
  • Own day‑to‑day identity platform operations: SSO application setup, IAM incident resolution and root‑cause analysis, upgrades, patching, MFA management, and access cleanup; query identity telemetry in CrowdStrike Falcon Next‑Gen SIEM and operate identity threat detection and response with CrowdStrike Falcon Identity Protection; support internal and external audits with access evidence.
  • Serve as a senior technical authority for IAM architecture and engineering decisions; develop and maintain identity architecture diagrams and configuration baselines; author technical design documents for significant automations and integrations prior to build; mentor IAM engineers and operations analysts; contribute to the strategic IAM roadmap and program maturity assessments.
Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field - or equivalent work experience.
  • 7+ years in identity and access management, identity engineering, or security engineering with substantial IAM scope, including senior or lead‑level ownership of identity platforms.
  • Deep, protocol‑level expertise in OAuth 2.0 and OIDC (grant types, token lifecycles, PKCE, scopes and claims, bearer‑token handling) and SAML 2.0 (assertions, metadata exchange, signing and encryption, SP- and IdP‑initiated flows).
  • Hands‑on expertise with Okta as an enterprise identity broker: Universal Directory, lifecycle management, Okta Workflows, SSO application integration, and SCIM provisioning; Okta Identity Governance experience strongly preferred.
  • Demonstrated application of zero‑trust architecture and least‑privilege access design in a production enterprise environment.
  • Advanced Active Directory design and administration in a hybrid IDaaS environment: OU and group strategy, GPO design, and tiered administration models; advanced Microsoft Entra ID policy design including Conditional Access, Identity Protection risk policies, and MFA policy.
  • Expert, protocol‑level SCIM 2.0 knowledge - core and enterprise schemas, custom schema extensions, PATCH semantics, and provisioning error handling.
  • Strong grounding in API security: OAuth 2.0‑protected API design, token validation and scoping, and the OWASP API Security Top 10 including BOLA/IDOR vulnerabilities.
  • Experience securing or governing identity for LLM and agentic AI systems: non‑human identity lifecycle, credential scoping for AI agents, and least‑privilege controls on machine‑to‑machine access.
  • Proficiency with CrowdStrike Falcon Identity Protection (ITDR, risk‑based policy enforcement) or a comparable ITDR platform; experience querying identity telemetry in an enterprise SIEM.
  • Experience integrating endpoint security with identity on Windows and macOS: device posture signals in access policy, platform SSO/desktop MFA, and MDM integration (Jamf, Intune, or equivalent).
  • Proficient scripting in PowerShell, Python, and bash; DevOps fluency including Git‑based source control and CI/CD pipeline authorship (Azure Pipelines or GitHub Actions).
  • 1+ year of experience with HRIS‑driven identity automation (Ceridian Dayforce, Workday, SuccessFactors, UKG, or similar).
Preferred Qualifications
  • Direct Ceridian Dayforce REST API experience (XRefCode addressing, position management, employment‑status events).
  • AWS IAM and AWS IAM Identity Center experience, particularly permission‑set‑based access management.
  • Exposure to dedicated IGA tooling (SailPoint, Saviynt, Omada) at design or implementation level.
  • Familiarity with NIST SP 800‑63 (digital identity assurance) and NIST SP 800‑207 (zero trust architecture).
  • Background in regulated, franchise, or multi‑entity environments where identity governance crosses organizational boundaries.
  • Relevant certifications: Okta Certified Professional/Consultant, CISSP, SC‑300, or AWS Security Specialty.
What do we offer?
  • Insurance Plans (Medical, Life)
  • Pension/401K/RSP (country specific)
  • Competitive Bonus
  • Mobility Allowance
  • Tuition Reimbursement
  • Company Holidays
  • Volunteering time
  • And More.....
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. IAM Engineer
Sr. IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
IAM Engineer
IAM Engineer

Subway • Shelton (CT)

On-site
USD 110,000 - 140,000
Insurance Plans (Medical) and Life
Pension/401K
Competitive Bonus
+5
IAM Engineer
IAM Engineer

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 110,000 - 150,000
Medical & Life Insurance
401K / Pension
Competitive Bonus
+4
IAM Engineer
IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 160,000
Security Operations Analyst
Security Operations Analyst

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 85,000 - 115,000
Medical & Life Insurance
Pension/401K
Bonus
+4
Security Operations Analyst
Security Operations Analyst

Subway • Shelton (CT)

On-site
USD 80,000 - 120,000
Insurance Plans (Medical Life)
Pension/401K/RSP
Competitive Bonus
+5
Senior IAM Engineer — Enterprise Identity & Zero-Trust Lead
Senior IAM Engineer — Enterprise Identity & Zero-Trust Lead

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
Senior Identity Engineer
Senior Identity Engineer

Tyler Technologies • United States

On-site
USD 140,000 - 200,000
Senior Identity Engineer
Senior Identity Engineer

Tyler-Technologies-29572f8 • Troy (MI)

On-site
USD 110,000 - 140,000
Senior Systems Engineer - IAM
Senior Systems Engineer - IAM

Berkley Technology Services • Chicago (IL)

On-site
USD 121,000 - 137,000
Health insurance
Dental insurance
Vision insurance
+2