Identity & Access Management (IAM) Engineer
RemoteKyiv, Kyiv City, Ukraine
Job Summary
IAM Engineer needed to design and develop IAM architecture (Okta or equivalent IdP): SSO (SAML/OIDC), SCIM provisioning, groups/RBAC, lifecycle, MFA/passkeys; build and maintain identity governance (least-privilege, quarterly access reviews, joiner/mover/leaver with offboarding); advance Zero Trust (conditional access, device trust, MDM like Mosyle/Jamf); administer corporate SaaS identity (Google Workspace, Slack) including SSO integrations and cross-domain migrations; automate IAM processes via API and scripts (n8n/Make); document processes and act as technical reference for the team. The role requires 3-4+ years in IAM or related IT-security roles, practical IdP experience, SSO/SCIM/RBAC, access governance, Zero Trust, SaaS identity administration, API automation skills, and experience with AI tooling in enterprise environments. Nice-to-have: Okta expertise, tenant migrations experience, certifications (Okta, CompTIA Security+), SOC 2 / ISO 27001, cloud security (AWS IAM), and secrets management (1Password).
Required Qualifications
- 3-4+ років у Identity & Access Management або суміжній IT-security ролі
- Практичний досвід із системами управління доступами / IdP (Okta, Microsoft Entra ID / Azure AD, OneLogin, Ping, Keycloak тощо)
- Глибоке розуміння IAM-практик: SSO (SAML / OIDC), provisioning (SCIM), RBAC, lifecycle, MFA
- Досвід з access governance: least-privilege, access reviews, on/offboarding
- Розуміння Zero Trust і керування пристроями (MDM / device trust)
- Адміністрування корпоративних SaaS на рівні identity / accounts (Google Workspace тощо)
- Досвід роботи з API та автоматизацією (n8n / Make / скрипти)
- Досвід адміністрування AI-інструментів (Claude / LLM) у корпоративному середовищі та використання цих інструментів
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.