Identity & Access Management Architect Okta Migration

ICONMA, LLC

  • Palo Alto, CA
  • 20 days ago
  • $78.19–$103.41 Per Hour
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Amazon Web Services (AWS)unmatched
  • Application Integrationunmatched
  • Application Programming Interface (API)unmatched
  • Architectural Servicesunmatched
  • Authenticationunmatched
  • Cloud Computingunmatched
  • Consultingunmatched
  • Documentationunmatched
  • Enterprise Application Integration (EAI)unmatched
  • Health Planunmatched
  • Home Automationunmatched
  • ISO (International Organization for Standardization)unmatched
  • Identify Issuesunmatched
  • Identity Data Managementunmatched
  • Identity Federationunmatched
  • Internet Securityunmatched
  • Machine Toolunmatched
  • Manufacturingunmatched
  • Microsoft Windows Azureunmatched
  • OAuthunmatched
  • Onboardingunmatched
  • Operational Supportunmatched
  • Python Programming/Scripting Languageunmatched
  • SQL (Structured Query Language)unmatched
  • Security Assertion Markup Language (SAML)unmatched
  • Security Information and Event Management (SIEM)unmatched
  • Single Sign-On (SSO)unmatched
  • Software Designunmatched
  • System Integration (SI)unmatched
  • Technical Leadershipunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched

Description

Our Client, an EV Manufacturing company, is looking for an Identity & Access Management Architect – Okta Migration for their Palo Alto, CA/Hybrid location.
 
Responsibilities:

  • Okta Migration & IAM Operations (core)
  • Lead technical architecture for the Entra ID to Okta workforce identity migration: federation design, app integration sequencing, cutover planning, rollback strategy, and hypercare
  • Design and build SSO/SAML/OIDC integrations across the enterprise application portfolio; architect multi-tenant deployment (separate US/EU tenants) to meet regional data requirements
  • Architect lifecycle management and provisioning workflows (HR-driven joiner/mover/leaver), including SCIM integrations
  • Define and implement MFA, adaptive authentication, and device assurance policies aligned to a zero-trust roadmap
  • Serve as technical counterpart to the implementation partner: review designs, challenge assumptions, hold delivery quality to standard
  • Maintain and operate the Okta environment post-cutover: policy tuning, integration onboarding, incident support, and operational runbooks
  • Produce audit-ready documentation for an ISO 27001 / TISAX-aligned control environment
  • Contribute to the design and build of a custom identity orchestration layer (Databricks or equivalent): attribute-driven provisioning, ABAC policy models, JIT privileged access, anomaly detection, automated deprovisioning, and audit/recertification capabilities
  • Support integration of identity and authorization event logs into the cybersecurity SIEM
 
Requirements:
  • 7+ years in identity and access management, with 3+ years hands-on Okta experience building, deploying, and maintaining Okta Workforce Identity Cloud environments
  • At least one completed enterprise migration from Entra ID / Azure AD to Okta as architect or technical lead
  • Deep expertise in SAML, OIDC, OAuth 2.0, SCIM, and directory integration (AD/Entra ID hybrid scenarios)
  • Experience operating and administering Okta in production: policy management, app integrations, lifecycle workflows, troubleshooting
  • Experience designing MFA and adaptive access policies at enterprise scale
  • Strong documentation skills; able to produce audit-ready artifacts
  • Proven ability to work alongside system integrators while retaining architectural ownership
  • Preferred Qualifications
  • Okta Certified Consultant or Okta Certified Architect
  • Experience building custom identity automation or governance tooling using Python/SQL, event-driven pipelines, and APIs
  • Working knowledge of data platforms (Databricks, Spark, or comparable) for event ingestion and processing
  • Experience with ABAC/policy-based authorization models and JIT/ephemeral privileged access patterns in AWS
  • SIEM integration experience (log normalization, detection engineering for identity signals)
  • Familiarity with IGA platforms, PAM solutions, and enterprise password managers
  • Experience in regulated or automotive environments (TISAX, ISO 27001, NIST 800-53)
 
Why Should You Apply?

Numbers & Facts

LocationPalo Alto, CA
Salary$78.19–$103.41 Per Hour

Similar Jobs

See more jobs