This role pays less than
95%
of similar roles. Most pay
$158,850–$233,575
— the shaded band above.
At the midpoint, this role pays about
$122k
versus about
$196k
for comparable roles.
Based on 240 similar postings.
Employer
About Braze
Braze is a leading cloud-based customer engagement platform that enables brands to foster human connection with consumers through interactive, real-time, cross-channel marketing.
Braze currently has
108 open roles
on FindRole.
Listed pay typically runs
$149,000–$234,000
across 107 roles with salary data.
Lead IAM Engineer will serve as a senior individual contributor responsible for the technical direction and evolution of the enterprise identity and access management strategy. This role involves architecting, building, and improving a secure, automated identity ecosystem centered on Okta to manage lifecycle automation, access governance, and authentication for employees, contractors, and partners. The successful candidate will develop reusable patterns, integrate Okta with systems like Workday, Google Workspace, Slack, and GitHub, and modernize configuration management through infrastructure as code and APIs. Key technical requirements include expertise in SAML, OIDC, OAuth, SCIM, and MFA, alongside proficiency in Python, PowerShell, and Terraform. The role addresses the critical business problem of reducing manual administration while ensuring robust security, reliability, and compliance within a SOX-regulated environment by automating identity workflows and enforcing least-privilege controls across all enterprise applications.
Own the technical roadmap and architecture for enterprise Identity & Access Management using Okta as the core platform.
Architect and improve Okta capabilities including SSO, authentication, lifecycle automation, and identity governance.
Design automated onboarding, role-change, and offboarding processes for employees, contractors, and partners.
Build and maintain integrations between Okta and enterprise systems like Workday, Google Workspace, and Slack.
Drive identity automation using Okta Workflows, APIs, scripting, and infrastructure as code tools like Terraform.
Lead identity governance initiatives including access reviews, role-based access controls, and least-privilege enforcement.
Manage identity-related SOX controls, audit evidence, and remediation processes to ensure compliance.
Mentor other engineers and establish repeatable engineering standards for identity design, testing, and deployment.
What we're looking for
Deep hands-on expertise with Okta in a complex enterprise environment including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance.
Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization.
Experience automating employee lifecycle processes using an HRIS such as Workday as the authoritative source.
Strong experience with identity governance including access reviews, entitlement management, and least privilege controls.
Strong scripting and automation skills using Python, PowerShell, or similar languages.
Strong API integration experience to connect identity platforms with broader enterprise systems.
Experience with Terraform or another infrastructure-as-code framework.
Experience supporting IAM controls in a SOX-regulated or similarly controlled environment.
Okta certifications such as Administrator, Consultant, Developer, or Identity Governance (preferred).
Experience managing Okta configuration through Terraform or similar tooling (preferred).
Experience using Git-based workflows or CI/CD practices to manage identity or infrastructure changes (preferred).
Familiarity with platforms like Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password (preferred).
Experience with partner, reseller, B2B, or external identity architectures (preferred).
Experience managing service accounts, machine identities, workload identities, or other non-human access (preferred).
Experience automating audit evidence or identity governance controls (preferred).
Identity and Access Management
Microsoft Entra ID
AWS
Active Directory
Zero Trust
PAM
PKI
SAML
OAuth
MFA
ADFS
MIM
LDAP
Kerberos
DNS
Certificate Services
Access Governance