Okta Engineer
We are seeking a highly skilled Okta Engineer to join our Identity and Access Management (IAM) team in support of a key project. In this role, you will be responsible for designing, implementing, and maintaining identity and access management solutions using Okta. You will work closely with cross-functional teams to ensure seamless integration of Okta services, provide expertise in authentication and authorization, and contribute to the overall security and efficiency of the identity platform.
The ideal candidate will have a solid background in Okta administration, Terraform, GitOps pipelines, and experience operating Identity as a Service (IDaaS) platforms. This role also involves application integration engineering, operational platform support, and continuous improvement of Okta configurations to meet business needs.
Key Responsibilities
- Design, deploy, and enhance Okta Workforce Identity Cloud and/or Customer Identity (CIAM) solutions.
- Design and configure SSO, MFA, Universal Directory, and lifecycle management for cloud, SaaS, and on-premises applications.
- Implement Okta Authenticators and Authentication Policies with phishing-resistant MFA (e.g., FIDO2, Okta FastPass) and passwordless authentication.
- Develop and manage identity governance, user lifecycle processes, and access workflows using Okta Workflows and Universal Directory.
- Integrate external Identity Providers (IdPs) into Okta for federated authentication and step-up authentication scenarios.
- Configure and manage identity synchronization between Active Directory (AD) and other identity sources.
- Build and maintain SCIM integrations and API-based provisioning for seamless user and application management.
- Collaborate with application stakeholders to implement new SSO and provisioning integrations using SAML, OIDC, OAuth, Web Access Gateway, and SCIM.
- Design and manage Role-Based Access Control (RBAC) using Okta groups, group rules, and application assignments.
- Implement Attribute-Based Access Control (ABAC) using Universal Directory attributes, expression language, and dynamic group membership.
- Ensure compliance with federal security standards, including NIST SP 800-63 (IAL/AAL/FAL), FedRAMP, and FISMA.
- Align Okta solutions with Zero Trust Architecture (ZTA) principles, including continuous authentication, session management, and risk-based access policies.
- Provide day-to-day operational support for the Okta platform and its integrations with third-party and internal applications.
- Support audit, logging, monitoring, and compliance reporting using Okta System Logs and event data.
- Assist security operations and IT teams during incident response and troubleshooting.
- Develop and maintain application onboarding guides and questionnaires to streamline SSO implementation for application stakeholders.
Basic Qualifications:
- 3+ years of hands-on experience designing, operating, and enhancing Okta Workforce Identity Cloud or CIAM solutions.
- Strong understanding of authentication and federation protocols, including OAuth 2.0, OIDC, SAML 2.0, and WS-Federation.
- Experience with RBAC and ABAC, leveraging Okta attributes and dynamic group membership.
- Proven ability to integrate cloud-based and on-premises applications using SAML/OIDC.
- Proficiency in configuring SCIM integrations, API-based provisioning, and identity synchronization with Active Directory (AD).
- Experience with Terraform, GitOps pipelines, and other CI/CD tools for Okta automation.
- Knowledge of phishing-resistant MFA technologies, passwordless authentication, and advanced security measures.
Preferred Qualifications
- Familiarity with FedRAMP, FISMA, and government security control frameworks as they relate to identity and access management.
- Experience implementing continuous authentication and risk-based access policies.
- Advanced understanding of logging, monitoring, and compliance reporting using Okta System Logs and event data.
- Familiarity with NIST SP 800-63 assurance levels and federal compliance requirements.
- Ability to gather requirements and implement secure integrations in collaboration with stakeholders.
- Strong documentation skills, including creating onboarding guides and technical questionnaires
As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.
The pay range for the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland is:
$91,300 - $184,900 USD
Apply for this job
*
indicates a required field