Principal IAM Lead
$155,000–$175,000 year
On-siteNew York, United States
Job Summary
Own and evolve the enterprise identity and access management ecosystem as the subject matter expert for Okta and Auth0 environments. Design group rules, access policies, and authentication workflows to support least-privilege and lifecycle management while managing licensing and capacity planning. Configure and troubleshoot Identity Provider connections, resolve federation issues across integrated applications, and leverage APIs to automate identity workflows and reporting. Manage SSO onboarding for external clients and enterprise customers, acting as the primary technical point of contact for partner IT teams. Secure access to AI/ML platforms and apply IAM governance principles to non-human identities and AI agents. Act as a trusted advisor to security and application teams on identity best practices, map IAM controls to compliance frameworks, and mentor junior engineers.
Required Qualifications
- Extensive hands-on experience administering Okta at an enterprise level, including SSO/SCIM, Okta Workflows, and Okta Identity Governance
- Strong, demonstrable experience with Auth0, including IdP connection creation and troubleshooting across major identity providers
- Solid understanding of authentication and authorization concepts (SAML, OIDC, OAuth 2.0, MFA, adaptive/risk-based policies)
- Working knowledge of identity and security logging practices to support monitoring and investigation
- Practical experience consuming and integrating with REST APIs for automation and troubleshooting
- Working knowledge of AWS, including AWS Identity Center
- Familiarity with directory services (Active Directory, Entra ID) and how they integrate with Okta/Auth0
- Strong troubleshooting skills and comfort making high-impact changes to production authentication systems
- Excellent communication skills, with the ability to translate technical identity concepts for both technical and non-technical stakeholders
- Applicants must be authorized to work for any employer in the U.S.
- Applicants must be currently authorized to work in the United States on a full-time basis without the need for current or future visa sponsorship
- This role is open to candidates in the following locations: New York, NY
- This role is expected to come into the office on a cadence set by the Hiring Manager/Team.
Desired Qualifications
- Relevant certifications (Okta Certified Consultant/Administrator, AWS certifications, CISSP, etc.)
- Experience mapping IAM controls to compliance frameworks (SOC 2, ISO 27001, NIST)
- Understanding of privileged access management (PAM) and non-human identity governance (service accounts, API keys, secrets rotation)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.