Okta IAM Engineer / Consultant
Summary
Designs and implements Okta-based IAM solutions, focusing on authentication, authorization, and identity lifecycle management for enterprise clients. Core technologies include Okta Identity Engine, SAML/OIDC, and scripting in Java/Python.
Experience: 5 - 7 years
Job Description:
• Minimum 5+ years of professional experience in Identity and Access Management (IAM).
• Minimum 4+ years of hands-on experience with Okta, including implementation, configuration, integration, and support.
• Minimum 2+ years of development or scripting experience using Java, JavaScript, Node.js, Python, PowerShell, or similar technologies.
• Experience managing Okta implementations across the complete SDLC, including requirements gathering, solution design, configuration, testing, deployment, and production support.
• Experience working in client-facing environments and participating in technical design and architecture discussions.
Okta / IAM Technical Skills:
• Strong hands-on experience with Okta Identity Engine, Universal Directory, Lifecycle Management, SSO, MFA, and API Access Management.
• Good understanding of IAM concepts including Authentication, Authorization, Federation, Provisioning, Reconciliation, RBAC, and Directory Services.
• Strong knowledge of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, and Just-in-Time (JIT) provisioning.
• Experience configuring Okta applications, authentication policies, sign-on policies, MFA, password policies, groups, group rules, and profile mappings.
• Experience implementing SSO integrations with SaaS, custom, and enterprise applications using SAML and OIDC.
• Hands-on experience with Okta Lifecycle Management, including user provisioning, deprovisioning, attribute mapping, and Joiner-Mover-Leaver processes.
• Experience integrating Okta with Active Directory, LDAP, HR systems, SaaS applications, and custom applications.
• Experience configuring authorization servers, scopes, claims, access policies, and OAuth2/OIDC flows , using Okta API Access Management.
• Experience using Okta REST APIs for user, group, application, and identity lifecycle operations.
• Knowledge of Okta Workflows, Event Hooks, Inline Hooks, and custom integrations is preferred.
• Experience with Okta Access Gateway for integrating legacy or on-premises applications is desirable.
• Experience troubleshooting authentication, federation, provisioning, directory synchronization, and application access issues.
• Good understanding of SSL/TLS, certificates, PKI, DNS, HTTP/HTTPS, reverse proxy, and load-balancing concepts.
Development & Tools:
• Experience with Java, JavaScript, Python, PowerShell, Node.js, or similar programming/scripting languages.
• Familiarity with REST APIs, JSON, web services, and API-based integrations.
• Experience with Git, Jira, CI/CD, Agile, and software development lifecycle practices.
• Knowledge of tools such as SonarQube, OpenSSL, and Keytool is preferred.
• Ability to design secure, scalable, and highly available Okta solutions based on business and technical requirements.
Preferred Qualifications:
• Relevant Okta certification is preferred.
• Experience integrating Okta with multiple enterprise applications and identity sources.
• Knowledge of Zero Trust, passwordless authentication, FIDO2/WebAuthn, and modern identity security practices is a plus.
People Skills:
• Strong analytical, troubleshooting, and problem-solving skills.
• Excellent written and verbal communication skills.
• Ability to communicate directly with clients through meetings, workshops, and email.
• Ability to translate business requirements into technical IAM solutions.
• Experience leading or mentoring team members and coordinating with application, security, and infrastructure teams.
Mandatory Skill: Okta Identity Engine, Universal Directory, Lifecycle Management, SSO, MFA, and API Access Management., SAML 2.0, OAuth 2.0, Okta API’s, SDLC, Java, Rest Api, JavaScript.