Job Description
The Okta & IGA Engineer is responsible for driving end-to-end technical onboarding, custom development, and day-to-day tier-2/3 operation of Okta and integrated Identity Governance & Administration (IGA) solutions. The role involves configuring modern federation protocols, implementing agentless SSO patterns for legacy applications, automating lifecycle workflows via code/APIs, and administering governance campaigns to support system security, compliance, and uptime SLAs.
Key Responsibilities
- Application Onboarding: Drive the end-to-end technical onboarding process for SaaS, cloud-native, and custom internal applications into Okta.
- Federation & Protocol Setup: Configure, test, and troubleshoot Single Sign-On (SSO) and Multi-Factor Authentication (MFA) utilizing SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
- Agentless SSO Architecture: Implement and manage Agentless SSO and header-based authentication patterns to bridge legacy infrastructure with cloud architecture without utilizing local agents.
- Custom Development: Write clean code and utilize APIs to build custom validation rules, Okta Inline Hooks, and automated lifecycle workflows.
- Collaboration & Support: Work with application owners through the Software Development Life Cycle (SDLC) to collect requirements and troubleshoot federation errors.
- Active Directory Configuration: Configure Active Directory (AD) Service Accounts, map Service Principal Names (SPNs), and establish secure Kerberos validation workflows with Okta.
- Identity Governance & Campaigns (IGA): Execute end-to-end Access Certification Campaigns within Okta Identity Governance (OIG) or integrated IGA tools. Define campaign scopes, reviewer assignments, remediation workflows, and automated revocation rules to meet audit and compliance requirements.
- BAU Operations & Support: Serve as the tier-2/3 engineering escalation point for the daily operations of the Okta tenant. Troubleshoot day-to-day authentication degradation, directory sync faults, token mismatch errors, and urgent user access anomalies to maintain strict system uptime SLAs.
Requirements
Skills and Knowledge
- Identity & Access Management (IAM): Proven experience building and managing Okta SSO profiles, lifecycle rules, and custom authorization servers.
- Protocols & Standards: Deep technical understanding of OAuth 2.0 frameworks, token customization, OIDC, and SAML.
- Agentless SSO Solutions: Practical experience configuring Agentless SSO solutions (e.g., gateway-based authentication, header-based proxy solutions) for applications that cannot natively use modern protocols.
- Programming & Software Engineering: Proficiency in at least one programming language (e.g., JavaScript/Node.js, Java, Python, C#, or Go) to interact with Okta APIs and configure custom widgets.
- API & Middleware Handling: Experience handling automated API authentication, token validation middleware, and JSON payloads.
Competencies
- Strong troubleshooting skills for day-to-day authentication degradation, directory sync faults, and token mismatch errors.
- Ability to collaborate effectively across application owners and infrastructure teams during the SDLC process.
- Pragmatic approach to defining campaign scopes, remediation workflows, and automated revocation rules to align with compliance standards.
- Strong understanding of network access configurations, including Network Zones, IdP routing rules, and Kerberos validation workflows.
Experience
- Minimum of 5 to 7 years of dedicated experience designing, implementing, and supporting enterprise-grade Identity & Access Management (IAM) systems.
- Hands-on experience with end-to-end Access Certification Campaigns within Okta Identity Governance (OIG) or integrated IGA tools.
- Demonstrated experience serving as a tier-2/3 escalation point for enterprise Okta tenant operational support.
Qualifications
- Education: Degree in IT or equivalent.
- Professional Certifications: Okta Certification (e.g., Okta Certified Professional, Okta Certified Administrator, Okta Certified Consultant, or Okta Certified Developer).