SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead IAM Engineer

Braze - Toronto, ON, Canada - Hybrid - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: CAD 104,000 - 164,000 / annual

Braze is seeking a Lead IAM Engineer to own the technical direction and evolution of the company's enterprise identity and access management strategy. In this senior individual contributor role, you will architect, build, and continuously improve a secure, scalable, and automated identity ecosystem centered on Okta, identity lifecycle, access governance, and automation. You will partner across Information Systems, Security, Engineering, Financial, and People Systems to ensure employees, contractors, partners, applications, and services have the right access at the right time while maintaining strong security, governance, reliability, and user experience. Key responsibilities include owning the technical roadmap and architecture for enterprise IAM with Okta as the core platform; architecting and improving Okta capabilities across SSO, authentication, lifecycle automation, Workflows, Identity Governance, and Access Requests; designing reliable onboarding, role-change, and offboarding identity processes; building and improving integrations between Okta and systems such as Workday, Google Workspace, Slack, GitHub, and Atlassian; driving identity automation using Okta Workflows, APIs, scripting, and Terraform; modernizing identity configuration changes through infrastructure as code and automated validation; leading identity governance initiatives including access reviews, access requests, and entitlement management; designing authentication and provisioning solutions using SAML, OIDC, OAuth, SCIM, and MFA; partnering with Security on authentication standards and zero-trust initiatives; supporting SOX controls and audit evidence; designing identity solutions for partners and service accounts; serving as a senior escalation point for complex identity issues; identifying recurring administrative work and creating automation and self-service solutions; establishing repeatable engineering standards; mentoring other engineers; and evaluating emerging identity capabilities. A major focus will be improving onboarding, access-change, and offboarding reliability, reducing manual administration, strengthening access governance, and expanding automation across the identity ecosystem. You will help modernize how identity configuration changes are managed through APIs, infrastructure as code, automated workflows, and repeatable engineering practices. You will also help strengthen the broader Identity & Access capability by developing reusable patterns, improving documentation and operational resilience, mentoring other engineers, and reducing key-person dependencies across critical identity services. Braze is the leading customer engagement platform that empowers brands to deliver great customer experiences. The company is headquartered in New York with offices globally including Toronto, and has been recognized as a Leader in marketing technology by industry analysts. REQUIREMENTS: - Deep hands-on expertise with Okta in a complex enterprise environment, including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance - Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization - Experience automating employee onboarding, role changes, and offboarding using an HRIS such as Workday as the authoritative source for employee data - Strong experience with identity governance including access reviews, entitlement management, access requests, role-based access control, and least privilege - Strong scripting and automation skills using Python, PowerShell, or similar languages - Strong API integration experience and the ability to connect identity platforms with broader enterprise systems - Experience with Terraform or another infrastructure-as-code framework - Experience turning manual identity administration into scalable, automated, and auditable processes - Experience supporting IAM controls in a SOX-regulated or similarly controlled environment - Proven ability to lead complex cross-functional IAM initiatives without requiring formal people-management authority - Strong communication skills with the ability to explain identity architecture, technical decisions, and risk to both technical and non-technical audiences BONUS: - Okta certifications such as Okta Certified Administrator, Consultant, Developer, or Identity Governance credentials - Experience managing Okta configuration through Terraform or similar tooling - Experience using Git-based workflows or CI/CD practices to manage identity or infrastructure changes - Familiarity with adjacent enterprise platforms such as Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password - Experience with partner, reseller, B2B, or external identity architectures - Experience managing service accounts, machine identities, workload identities, or other non-human access - Experience automating audit evidence or identity governance controls

Similar roles