
Okta/SailPoint Engineer
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in Virginia.
• Act as the primary technical Subject Matter Expert (SME) for the Okta Identity Provider (IdP) platform, encompassing the administration, configuration, and continuous enhancement of Okta Universal Directory, SSO integrations, MFA policies, application integrations, and identity federation services.
• Function as the lead technical SME for SailPoint IdentityIQ (IIQ), which includes the administration, configuration, and ongoing improvement of identity governance workflows, automated provisioning and deprovisioning, entitlement management, access certification campaigns, and Segregation of Duties (SOD) enforcement.
• Design, configure, and deploy application integrations with the Okta IdP using standardized protocols such as SAML, OAuth 2.0, OIDC, and SCIM.
• Design, configure, and implement application integrations with SailPoint IIQ, involving the setup of application connectors, automated provisioning workflows, role and entitlement models, access request processes, and audit reporting capabilities.
• Engineer and develop custom connectors, scripts, APIs, and middleware solutions to enable the integration of legacy applications that do not natively support modern identity protocols or standard SailPoint/Okta connectors.
• Create, implement, and maintain identity protocol connectors and APIs that application owners will utilize to link their systems to the ICAM technical stack.
• Provide extensive technical guidance and platform-specific expertise to migration engineers and application owners throughout the enablement lifecycle.
• Assist in the configuration and management of alternative credential solutions and non-PKI based authentication methods.
• Administer and uphold the Okta Universal Directory as the Authoritative Directory Aggregator.
• Implement and enforce access control models, including Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) configurations.
• Aid in the establishment and ongoing management of Single Sign-On (SSO) integrations and Active Directory connections.
• Monitor platform health, performance, and security across the Okta and SailPoint environments.
• Contribute to the development and upkeep of platform runbooks, integration guides, and standard operating procedures.
• Support the testing program by creating integration test cases and conducting platform-level testing.
• Ensure all platform configurations adhere to applicable DoD security requirements.
• Vet all third-party connectors, scripts, code libraries, and enhancements integrated into the ICAM environment.
• Stay updated on Okta and SailPoint platform modifications, new features, and evolving identity standards.
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited institution.
• At least 5 years of practical experience in information technology, with a minimum of 3 years of direct, production-level experience managing and configuring Okta and/or SailPoint IdentityIQ in an enterprise setting.
• Proven experience in designing and implementing SSO integrations using SAML, OAuth 2.0, and OIDC in a production enterprise environment.
• Demonstrated experience in configuring automated provisioning and deprovisioning workflows, entitlement management, and access certification campaigns within SailPoint IIQ.
• Active Secret clearance. Must meet requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification.
• Extensive, hands-on technical knowledge of the Okta Identity Provider platform.
• In-depth, hands-on technical expertise with SailPoint IdentityIQ (IIQ).
• Strong working knowledge and practical experience with SAML 2.0, OAuth 2.0, OIDC, and SCIM identity and authorization protocols.
• Experience in developing custom integration solutions, including scripts, connectors, REST APIs, and middleware to connect legacy or non-standard applications with modern identity platforms.
• Proficiency in one or more scripting or programming languages commonly used in identity engineering environments, such as Java, Python, JavaScript, PowerShell, or BeanShell.
• Health, dental, and vision insurance
• 401K with company matching
• Flexible spending accounts
• Paid holidays
• Three weeks paid time off
• Extraordinary benefits package
Anduril Industries
Sargent & Lundy
Sargent & Lundy
Get handpicked remote jobs straight to your inbox weekly.