About this role
Drive a comprehensive identity and access lifecycle strategy for our global portfolio, such as: Authentication (AuthN): Drive identity security to the next level by enforcing device trust, post-auth detection, and DPoP. Authorization (AuthZ): Enforce least privilege and right-size entitlement that balance security and velocity. Non-Human & AI Agent Identity: Lead secure management for NHIs (e.g., OAuth tokens, service accounts, and API keys) and establish security guardrails for emerging AI agents and MCP connections. Privileged Access Management (PAM) & Just-in-Time (JIT) Access: Modernize privileged access and implement JIT models to reduce standing privileges and secure high-risk administrative actions. Own and harden Cloudflare ZTNA policies and support transitioning from traditional network-based access model. Leverage your experience in broader enterprise security domains to ensure our identity strategy is integrated with our CorpSec efforts—device signals from endpoint posture (Fleet/EDR), SaaS security, and vulnerability management into our access controls to drive a unified security posture. Eliminate manual toil and accelerate delivery by engineering automated solutions—using scripting, no-code tools, or AI—to solve problems at scale rather than manually managing repetitive tasks. 7+ years in security engineering, IT engineering, or infrastructure, with meaningful depth in identity and access Strong hands-on experience with Okta: policy design, device assurance, FastPass, device trust, RBAC Experience with Cloudflare Zero Trust or a comparable platform Strong knowledge of SAML, OIDC, OAuth 2.0, and SCIM Experience with IGA solutions (e.g., Okta Identity Governance, SailPoint), including a deep understanding of identity lifecycles and compliance requirements. Experience securing non-human identities (service accounts, OAuth apps, tokens) and establishing guardrails for AI agents; we value your thought process and perspective on these emerging challenges. Experience with using Terraform or other IaC tools to manage infrastructure changes, with a strong emphasis on GitOps fluency. Practical view of least privilege. You can right-size access without introducing too much friction to the business. Experience building automated solutions (e.g., Okta Workflows, Lambda, Windmill) using Python or similar; you know when to automate for high impact and when to avoid it to prevent over-engineering. Practical use of AI tooling in your own workflow Proven ability to influence cross-functional outcomes, even without direct formal authority. Proactively identify, scope, and drive complex problems to completion.