Staff Identity Governance and Access Engineer

Okta Inc

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Bellevue, WAChicago, ILWashington, DC
Salary
$161,000–$221,000 / yr
Posted
6 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $197k
This role $191k
$141k most similar roles pay here $248k

This role pays less than 55% of similar roles. Most pay $170,000–$224,850 — the shaded band above. At the midpoint, this role pays about $191k versus about $197k for comparable roles.

Based on 240 similar postings.

Employer

About Okta Inc

Okta, Inc. is an American identity and access management company based in San Francisco. It provides cloud software that helps companies manage and secure user authentication into applications, and for developers to build identity controls into applications, websites, web services, and devices.[

Okta Inc currently has 137 open roles on FindRole.

Listed pay typically runs $174,000–$239,000 across 137 roles with salary data.

Most-posted roles

View all roles at Okta Inc

At a glance

TL;DR · Staff Identity Governance and Access Engineer

The Staff Identity Governance and Access Engineer joins the Identity Governance and Access Security team as a senior individual contributor responsible for managing internal identity lifecycle processes. This role involves taking deep technical ownership of Okta Identity Governance, Okta Privileged Access, and Identity Security Posture Management implementations to serve as the reference architecture for customers. Key responsibilities include designing access request workflows, leading RBAC strategy, managing Workday integration architectures, and automating mover/leaver processes. The candidate will utilize Okta Workflows, REST APIs, JSON parsing, and webhooks while ensuring compliance in SOX-critical environments. Required expertise includes advanced experience with IGA, PAM, and ISPM tools, along with a solid grounding in SAML, OIDC, OAuth 2.0, and SCIM standards to solve complex identity security challenges for the workforce.

What you'll do

  • Own the end-to-end architecture for Okta Identity Governance (OIG) including access workflows and certification campaigns.
  • Design and deploy automated birthright access rules and RBAC frameworks across the enterprise.
  • Manage Workday integration architecture to balance real-time synchronization with scheduled attribute reconciliation.
  • Automate mover/leaver processes by implementing attribute-driven group re-evaluation and decommissioning stale access.
  • Lead initiatives for Privileged Access Management (PAM), Just-In-Time elevation, and Zero Standing Privilege models.
  • Develop and track telemetry and KPIs for privileged access reduction and identity security vulnerability detection.
  • Build and maintain automated workflows using the Okta Workflows engine to streamline request approvals.
  • Provide technical leadership by mentoring engineers, reviewing designs, and presenting roadmaps to executive stakeholders.

What we're looking for

  • Minimum 4 years of experience managing and administering enterprise IGA, PAM, and ISPM tools.
  • Experience designing and deploying Birthright Provisioning models and RBAC architectures in production environments.
  • Production experience with OPA or equivalent PAM tooling including Zero Standing Privilege and Just-In-Time access.
  • Production experience with ISPM tools that integrate with EDR solutions like Crowdstrike Falcon.
  • Solid grounding in identity standards such as SAML, OIDC, OAuth 2.0, and SCIM.
  • Experience operating in SOX and compliance-critical environments with an understanding of audit requirements.
  • Ability to work independently and communicate technical risks and roadmaps to executive leadership.
  • U.S. citizen as defined in 42 U.S. Code § 9102.

More like this

Similar roles

Staff Identity Governance and Access Engineer

Okta Inc

Bellevue, WA +2 6 days ago $161,000$221,000
Okta IGA PAM ISPM RBAC SAML OIDC OAuth 2.0 SCIM Workday Okta Workflows REST APIs JSON Crowdstrike Falcon Jira ServiceNow SOX SOC 2 ISO 27001 HIPAA GDPR
4+ yrs exp

Staff Identity Engineer

Okta Inc

Bellevue, WA +2 7 days ago $161,000$221,000
Okta OIDC OAuth 2.0 SAML 2.0 FIDO2 WebAuthn Terraform AWS GCP Azure API SOC 2 ISO 27001 FedRAMP
4+ yrs exp

Staff Identity Engineer

Okta Inc

Bellevue, WA +2 7 days ago $161,000$221,000
Okta OIDC OAuth 2.0 SAML 2.0 FIDO2 WebAuthn Terraform AWS GCP Azure API SOC 2 ISO 27001 FedRAMP
4+ yrs exp

Identity Engineer

Elastic

44 days ago $94,300$149,200
Okta SAML 2.0 OAuth SSO MFA Okta Workflows Terraform REST APIs JSON SCIM JIT IDaaS Infrastructure as Code Agile Identity and Access Management
5+ yrs exp

Principal Forward Deployed Engineer, AI Agents

Okta Inc

Remote (Bellevue, WA) +3 43 days ago $269,000$369,000
OAuth 2.0 OIDC SAML SCIM RFC 8693 ReBAC ABAC OPA Cedar OpenFGA Distributed Systems MCP OWASP Top 10 NIST AI RMF MITRE ATLAS ISO/IEC 42001 HIPAA FedRAMP SOC 2
10+ yrs exp Remote

ICAM Architect

Booz Allen Hamilton

McLean, VA 64 days ago $86,800$198,000
Okta Entra ID SAML 2.0 OAuth 2.0 OpenID Connect Java JavaScript Python PowerShell Groovy RESTful APIs Active Directory LDAP Zero Trust MFA Saviynt Sailpoint Omada Oracle IAM CI/CD AWS Cognito Azure AD B2C Keycloak Google Cloud Identity