SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Okta is seeking a Staff Identity Governance and Access Engineer to take deep technical ownership of the company's Identity Governance (OIG), Privileged Access (OPA), and Identity Security Posture Management (ISPM) implementations. This is a senior individual-contributor role where you'll set technical direction for how the team builds on these platforms and raise the bar through review, mentorship, and documentation.
You'll own OIG architecture end-to-end, designing access request workflows, entitlement structures, and certification campaigns that reduce reviewer fatigue. You'll lead lifecycle, birthright, and RBAC strategy—designing automated birthright access rules, RBAC frameworks, and seamless joiner/mover/leaver processes across the enterprise. You'll drive Workday integration architecture, balancing scheduled reconciliation with real-time sync and defining attribute sets that access rules depend on.
You'll design and harden mover/leaver automation, implementing attribute-driven group re-evaluation on role changes and safe decommissioning of stale access. You'll lead OPA, ISPM, and Zero Standing Privilege initiatives—designing privileged session access, Just-In-Time elevation, break-glass emergency access, and identity security vulnerability detection. You'll own PAM and ISPM telemetry and KPIs, establishing metrics around standing-privilege reduction, JIT adoption, and stale access cleanup.
You'll build and maintain Okta Workflows automation to streamline access requests, approvals, and remediation across IGA and PAM processes. As a technical leader, you'll mentor engineers, review designs, and serve as the escalation point for the team's hardest problems, helping junior engineers grow and presenting clear updates and roadmaps to executive stakeholders.
You'll bring 4+ years of direct, advanced experience managing enterprise IGA, PAM/ISPM tools and platforms. You have demonstrated hands-on experience designing and deploying Birthright Provisioning models and RBAC architectures in production. You have production experience with OPA or equivalent PAM tooling, including Zero Standing Privilege and Just-In-Time access models. You're grounded in identity and access standards (SAML, OIDC, OAuth 2.0, SCIM) and role/attribute-based access control concepts.