Lead IAM Engineer

Braze

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Chicago, ILNew York City, NY
Salary
$95,000–$150,000 / yr
Posted
19 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $196k
This role $122k
$78k most similar roles pay here $250k

This role pays less than 95% of similar roles. Most pay $158,850–$233,575 — the shaded band above. At the midpoint, this role pays about $122k versus about $196k for comparable roles.

Based on 240 similar postings.

Employer

About Braze

Braze is a leading cloud-based customer engagement platform that enables brands to foster human connection with consumers through interactive, real-time, cross-channel marketing.

Braze currently has 108 open roles on FindRole.

Listed pay typically runs $149,000–$234,000 across 107 roles with salary data.

Most-posted roles

View all roles at Braze

At a glance

TL;DR · Lead IAM Engineer

Lead IAM Engineer will serve as a senior individual contributor responsible for the technical direction and evolution of the enterprise identity and access management strategy. This role involves architecting, building, and improving a secure, automated identity ecosystem centered on Okta to manage lifecycle automation, access governance, and authentication for employees, contractors, and partners. The successful candidate will develop reusable patterns, integrate Okta with systems like Workday, Google Workspace, Slack, and GitHub, and modernize configuration management through infrastructure as code and APIs. Key technical requirements include expertise in SAML, OIDC, OAuth, SCIM, and MFA, alongside proficiency in Python, PowerShell, and Terraform. The role addresses the critical business problem of reducing manual administration while ensuring robust security, reliability, and compliance within a SOX-regulated environment by automating identity workflows and enforcing least-privilege controls across all enterprise applications.

What you'll do

  • Own the technical roadmap and architecture for enterprise Identity & Access Management using Okta as the core platform.
  • Architect and improve Okta capabilities including SSO, authentication, lifecycle automation, and identity governance.
  • Design automated onboarding, role-change, and offboarding processes for employees, contractors, and partners.
  • Build and maintain integrations between Okta and enterprise systems like Workday, Google Workspace, and Slack.
  • Drive identity automation using Okta Workflows, APIs, scripting, and infrastructure as code tools like Terraform.
  • Lead identity governance initiatives including access reviews, role-based access controls, and least-privilege enforcement.
  • Manage identity-related SOX controls, audit evidence, and remediation processes to ensure compliance.
  • Mentor other engineers and establish repeatable engineering standards for identity design, testing, and deployment.

What we're looking for

  • Deep hands-on expertise with Okta in a complex enterprise environment including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance.
  • Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization.
  • Experience automating employee lifecycle processes using an HRIS such as Workday as the authoritative source.
  • Strong experience with identity governance including access reviews, entitlement management, and least privilege controls.
  • Strong scripting and automation skills using Python, PowerShell, or similar languages.
  • Strong API integration experience to connect identity platforms with broader enterprise systems.
  • Experience with Terraform or another infrastructure-as-code framework.
  • Experience supporting IAM controls in a SOX-regulated or similarly controlled environment.
  • Okta certifications such as Administrator, Consultant, Developer, or Identity Governance (preferred).
  • Experience managing Okta configuration through Terraform or similar tooling (preferred).
  • Experience using Git-based workflows or CI/CD practices to manage identity or infrastructure changes (preferred).
  • Familiarity with platforms like Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password (preferred).
  • Experience with partner, reseller, B2B, or external identity architectures (preferred).
  • Experience managing service accounts, machine identities, workload identities, or other non-human access (preferred).
  • Experience automating audit evidence or identity governance controls (preferred).

More like this

Similar roles

Lead IAM Engineer

Braze

New York City, NY 24 days ago $101,000–$158,000
Okta SAML OIDC OAuth 2.0 SCIM Terraform Python PowerShell API CI/CD Identity Governance Infrastructure as Code Workday Google Workspace Slack GitHub Atlassian MFA zero-trust
Hybrid

Lead IAM Engineer

Braze

Austin, TX +1 19 days ago $91,000–$142,000
Okta SAML OIDC OAuth 2.0 SCIM Terraform Python PowerShell API CI/CD Identity Governance Infrastructure as Code Workday Google Workspace Slack GitHub Atlassian MFA zero-trust
Hybrid

Lead Infrastructure Engineer, IAM

T. Rowe Price

Owings Mills, MD 11 days ago $122,000–$209,000
Identity and Access Management Microsoft Entra ID AWS Active Directory Zero Trust PAM PKI SAML OAuth MFA ADFS MIM LDAP Kerberos DNS Certificate Services Access Governance
8+ yrs exp Hybrid

Senior IAM Automation Engineer

Apex

Austin, TX 172 days ago $108,800–$136,000
Okta Entra ID Tines Terraform Python PowerShell Go Active Directory Adaxes AWS IAM GCP Cloud Identity SAML OIDC SCIM CI/CD Ansible Workday ServiceNow Slack Teams M365
7+ yrs exp Hybrid

Senior IAM Engineer

FanDuel

New York, NY 24 days ago $138,000–$173,000
Okta AWS Azure AD Entra ID Terraform Python Go Bash SAML OAuth 2.0 OIDC MFA SSO RBAC ABAC CI/CD infrastructure-as-code LDAP Active Directory FIDO2
5+ yrs exp Hybrid

Senior IAM Engineer

FanDuel

Atlanta, GA 24 days ago $138,000–$173,000
Okta AWS Azure AD Entra ID Terraform Python Go Bash SAML OAuth 2.0 OIDC FIDO2 RBAC ABAC CI/CD MuleSoft LDAP Active Directory Identity Governance infrastructure-as-code
5+ yrs exp Hybrid