Lead IAM Engineer

Braze

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Austin, TXNew York City, NY
Salary
$91,000–$142,000 / yr
Posted
19 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $196k
This role $116k
$74k most similar roles pay here $251k

This role pays less than 98% of similar roles. Most pay $158,850–$233,575 — the shaded band above. At the midpoint, this role pays about $116k versus about $196k for comparable roles.

Based on 240 similar postings.

Employer

About Braze

Braze is a leading cloud-based customer engagement platform that enables brands to foster human connection with consumers through interactive, real-time, cross-channel marketing.

Braze currently has 108 open roles on FindRole.

Listed pay typically runs $149,000–$234,000 across 107 roles with salary data.

Most-posted roles

View all roles at Braze

At a glance

TL;DR · Lead IAM Engineer

Lead IAM Engineer serves as a senior individual contributor responsible for the technical direction and evolution of the enterprise identity and access management strategy. Working within the Information Systems, Security, Engineering, Financial, and People Systems teams, this role focuses on building a secure, scalable, and automated identity ecosystem centered on Okta. The position involves architecting lifecycle automation, improving onboarding and offboarding reliability, and managing access governance for employees, contractors, and partners. Key responsibilities include developing infrastructure as code, integrating systems like Workday, Google Workspace, Slack, and GitHub, and implementing protocols such as SAML, OIDC, OAuth, and SCIM. The role requires proficiency in Python, PowerShell, and Terraform to automate identity configuration changes while ensuring compliance with SOX controls. This position solves the challenge of reducing manual administration through automated workflows and robust engineering practices.

What you'll do

  • Own the technical roadmap and architecture for enterprise Identity & Access Management using Okta as the core platform.
  • Architect and improve Okta capabilities including SSO, authentication, lifecycle automation, and identity governance.
  • Design automated onboarding, role-change, and offboarding processes for employees, contractors, and partners.
  • Build and maintain integrations between Okta and enterprise systems like Workday, Google Workspace, and Slack.
  • Drive identity automation using Okta Workflows, APIs, scripting, and infrastructure as code tools like Terraform.
  • Lead identity governance initiatives including access reviews, role-based access controls, and least-privilege management.
  • Implement authentication and provisioning solutions using standards such as SAML, OIDC, OAuth, and SCIM.
  • Serve as a senior escalation point for complex identity issues and lead root cause analysis investigations.

What we're looking for

  • Deep hands-on expertise with Okta in a complex enterprise environment including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance.
  • Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization.
  • Experience automating employee onboarding, role changes, and offboarding using an HRIS such as Workday.
  • Strong experience with identity governance including access reviews, entitlement management, access requests, RBAC, and least privilege.
  • Strong scripting and automation skills using Python, PowerShell, or similar languages.
  • Strong API integration experience to connect identity platforms with broader enterprise systems.
  • Experience with Terraform or another infrastructure-as-code framework.
  • Experience supporting IAM controls in a SOX-regulated or similarly controlled environment.
  • Okta certifications such as Administrator, Consultant, Developer, or Identity Governance (preferred).
  • Experience managing Okta configuration through Terraform or similar tooling (preferred).
  • Experience using Git-based workflows or CI/CD practices to manage identity or infrastructure changes (preferred).
  • Familiarity with adjacent enterprise platforms like Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password (preferred).
  • Experience with partner, reseller, B2B, or external identity architectures (preferred).
  • Experience managing service accounts, machine identities, workload identities, or other non-human access (preferred).
  • Experience automating audit evidence or identity governance controls (preferred).

More like this

Similar roles

Lead IAM Engineer

Braze

New York City, NY 24 days ago $101,000–$158,000
Okta SAML OIDC OAuth 2.0 SCIM Terraform Python PowerShell API CI/CD Identity Governance Infrastructure as Code Workday Google Workspace Slack GitHub Atlassian MFA zero-trust
Hybrid

Lead IAM Engineer

Braze

Chicago, IL +1 19 days ago $95,000–$150,000
Okta SAML OIDC OAuth 2.0 SCIM Terraform Python PowerShell API CI/CD Infrastructure as Code Identity Governance MFA Workday Google Workspace Slack GitHub Atlassian zero-trust
Hybrid

Lead Infrastructure Engineer, IAM

T. Rowe Price

Owings Mills, MD 11 days ago $122,000–$209,000
Identity and Access Management Microsoft Entra ID AWS Active Directory Zero Trust PAM PKI SAML OAuth MFA ADFS MIM LDAP Kerberos DNS Certificate Services Access Governance
8+ yrs exp Hybrid

Senior IAM Automation Engineer

Apex

Austin, TX 172 days ago $108,800–$136,000
Okta Entra ID Tines Terraform Python PowerShell Go Active Directory Adaxes AWS IAM GCP Cloud Identity SAML OIDC SCIM CI/CD Ansible Workday ServiceNow Slack Teams M365
7+ yrs exp Hybrid

Senior IAM Engineer

FanDuel

New York, NY 24 days ago $138,000–$173,000
Okta AWS Azure AD Entra ID Terraform Python Go Bash SAML OAuth 2.0 OIDC MFA SSO RBAC ABAC CI/CD infrastructure-as-code LDAP Active Directory FIDO2
5+ yrs exp Hybrid

ICAM Engineer

Booz Allen Hamilton

Scott AFB, IL 26 days ago $61,900–$141,000
Ping Federate Entra ID ADFS SAML 2.0 OAuth 2.0 OpenID Connect SSO RBAC ABAC Active Directory LDAP Zero Trust MFA SCIM Okta Workflows Python PowerShell Bash AWS Azure