HHiring Reality
← Okta

Staff Identity Governance and Access Engineer

Okta
Location
Bellevue, Washington; Chicago, Illinois; Washington, DC
Posted
15 days ago
Department
Sec - IAM-185
What they actually want (must-haves)
  • Minimum 4+ years of direct, advanced experience managing and administering enterprise IGA, PAM/ISPM tools and platforms.
  • Demonstrated hands-on experience designing and deploying Birthright Provisioning models and RBAC architectures in production environments.
  • Production experience with OPA or equivalent PAM tooling, including Zero Standing Privilege, Just-In-Time access models, break-glass design, and admin tiering.
  • Production experience with ISPM tools (such as Okta ISPM) that integrate with EDR solutions like Crowdstrike Falcon.
  • Solid grounding in identity and access standards (SAML, OIDC, OAuth 2.0, SCIM) and role/attribute-based access control concepts.
  • Track record of owning technical designs for identity lifecycle problems (joiner/mover/leaver) end-to-end, from design doc through production rollout.
Nice to have
  • Experience governing non-human identities (service accounts, API tokens, secrets, AI agents/workload identities) and scaling access certification programs.
  • Familiarity with ServiceNow and JIRA-based service request intake for IGA/PAM/ISPM operations.
  • Okta certifications — Okta Certified Administrator, Okta Certified Consultant, or Okta Workflows Specialist.
  • Technical integration experience with REST APIs, JSON parsing, webhooks, and Workday-to-IdP patterns (real-time event delivery vs. scheduled reconciliation tradeoffs).
  • Experience supporting compliance audits across multiple frameworks beyond SOX (SOC 2, ISO 27001, HIPAA, GDPR).
What the job really is

The Staff Identity Governance and Access Engineer will take ownership of Okta's Identity Governance, Privileged Access, and Identity Security Posture Management implementations. The role involves designing access workflows, leading lifecycle strategies, and automating processes related to identity management. Additionally, the engineer will mentor team members and communicate technical updates to leadership, ensuring the integrity and security of identity systems.

Benefits
  • Equity (where applicable)
  • Bonus
  • Health, dental and vision insurance
  • 401(k)
  • Flexible spending account
  • Paid leave (including PTO and parental leave)
Things to weigh
  • No specific mention of team size or structure, which could impact collaboration dynamics.
  • The role requires a high degree of autonomy, which may not suit everyone.
  • The salary range is provided but is location-dependent and may vary based on individual qualifications.
  • The posting emphasizes a strong focus on compliance and security, which may involve rigorous processes.
Job score3.2/5
Benefits3/5
Freshness4/5
Career value4/5
Role clarity5/5
Pay transparency0/5

Applying to Okta?

See how your résumé matches this role — and tailor it from what actually gets interviews.