Identity Governance Engineer
$176,000–$183,500 year
On-siteNew York City, New York, United States
Job Summary
Manage identity governance and access management in a production environment, including Okta lifecycle management, SAML/OIDC integrations, and group rules. Own access certification campaigns covering joiner/mover/leaver processes and periodic access reviews while supporting SOX IT General Controls audits. Document IAM policies, procedures, and control narratives for external auditor consumption. Leverage scripting or automation with Python or PowerShell to streamline identity workflows and entitlement data extraction. Engage application owners and business stakeholders to complete access reviews and follow up on deadlines. Maintain detailed documentation of role-based access control, least privilege, and segregation of duties concepts.
Required Qualifications
- 3–5 years of experience in identity and access management, information security, or GRC with a direct focus on identity governance
- Demonstrated experience administering Okta in a production environment, including lifecycle management, SAML/OIDC app integrations, group rules, and access policies
- Hands-on experience owning or contributing to access certification campaigns (joiner/mover/leaver processes, periodic access reviews)
- Experience supporting or directly responding to SOX IT General Controls (ITGCs) audits, including access controls and user access review (UAR) evidence
- Proven ability to document IAM policies, procedures, and control narratives suitable for external auditor consumption
- Working knowledge of SAML 2.0, OIDC, OAuth 2.0, and SCIM provisioning
- Familiarity with IAM governance across at least one major cloud platform (AWS IAM, Azure Entra ID / PIM, or GCP Cloud IAM)
- Scripting or automation experience — Python or PowerShell applied to identity workflows (access reporting, entitlement data extraction, lifecycle automation)
- Proficiency with spreadsheet tools for managing entitlement inventories, access review tracking, and audit evidence preparation
- Understanding of role-based access control (RBAC), least privilege, and segregation of duties (SoD) concepts
- Able to work independently with minimal supervision on concurrent workstreams
- Strong written communication skills — can produce clear policy documents, control narratives, and audit evidence packages without significant editing
- Comfortable engaging application owners and business stakeholders to complete access reviews, including following up to meet deadlines
- Detail-oriented with a documentation-first mindset appropriate for a SOX-controlled environment
- Judgment to escalate appropriately when access anomalies or control gaps are identified
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.