Staff Identity Security Engineer, Identity Governance

2 weeks ago


Toronto, Ontario, Canada Okta Full time $141,000 - $211,000 per year

Get to know Okta

Okta is The World's Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we're looking for lifelong learners and people who can make us better with their unique experiences.

Join our team We're building a world where Identity belongs to you.

About the Role:

Okta is seeking a highly experienced and passionate Staff Identity Security Engineer to join our dynamic Security Identity Governance and Administration (IGA) team at Okta. This pivotal role will focus on implementing, configuring, and managing Okta's Identity Governance (OIG) solution. Candidates are required to ensure that access to applications and resources is secure, compliant, and based on the principles of least privilege, separation of duty and need to know. The primary area of responsibility for this role will be to lead, design, build, and deploy automation and self service capabilities of all IGA processes.

Core responsibilities:

  • Lead with an automation first mindset: Design, build, and deploy automation for all aspects of IGA capabilities leveraging Okta platform features as well as supplementary tooling such as configuration as code management platforms (e.g. Terraform), scripting (e.g. Python).
  • Design and implementation: Work with IT and security teams to design and implement access control solutions using OIG platform.
  • Lifecycle management: Manage the full identity lifecycle for users, including processes for onboarding new employees ("joiners"), updating access for role changes ("movers"), and securely deprovisioning users who leave the organization ("leavers").
  • Workflow development: Build and configure Okta Workflows to automate identity tasks, such as access requests, approvals, and provisioning.
  • Access certifications: Create and manage access certification campaigns to review and audit user access to critical resources, ensuring it aligns with Okta's policy and compliance requirements.
  • Policy enforcement: Configure and enforce policies, including Least Privilege and Separation of Duties (SOD) rules, to prevent overprovisioned access, conflicts of interest to reduce risk.
  • Integrations: Integrate Okta with various enterprise systems, applications, directories, and cloud platforms (AWS, Azure, GCP) using SCIM, APIs or custom connectors methods.
  • Reporting and auditing: Generate reports for compliance and auditing purposes, leveraging the data collected by OIG with specific focus on automation of our reporting capabilities through centralization and enablement of self service through the use of reporting platforms (e.g. Tableau).
  • Collaborative Team Engagement: Participate actively and contribute significantly to team meetings, fostering a collaborative environment, and engage with ongoing efforts to continuously improve ways of working within the IAM engineering team.
  • Tier 3 Support for Internal Issues: Provide expert Level 3 support for complex internal identity-related issues and requests, acting as a critical point of escalation and resolution.

Essential qualifications:

  • Experience: Hands-on experience designing and implementing identity and access management (IAM) solutions on Okta.
  • Automation: Demonstrated experience and expertise in automation of IGA processes, system/platform configuration deployment, and reporting.
  • Platform proficiency: In-depth knowledge of OIG platform, including its various modules like Lifecycle Management, Workflows, and Access Governance.
  • Technical knowledge: Understanding of core identity security concepts such as role-based access control (RBAC), least privilege, and attribute synchronization.
  • Communication skills: Strong communication and problem-solving skills to collaborate with both technical and business stakeholders.
  • SDLC and Agile Knowledge: Possess a demonstrated understanding of working within the Software Development Life Cycle (SDLC) and Agile methodologies, ensuring efficient and structured development processes.
  • Collaboration Tool Proficiency: Possess a good working knowledge of essential ITSM and collaboration tools such as ServiceNow, JIRA, Confluence, and GitHub, facilitating efficient service and project management as well as code collaboration.
  • Security and Compliance Frameworks: Possess working knowledge of relevant security and compliance frameworks to ensure adherence to industry best practices and regulatory requirements.
  • Certifications: Okta Certified Professional, Administrator or Workflow specialist are a plus.
LI-HYBRID

Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit:

The annual base salary range for this position for candidates located in Canada is between:$141,000—$211,000 CAD

What you can look forward to as a Full-Time Okta employee

  • Amazing Benefits
  • Making Social Impact
  • Developing Talent and Fostering Connection + Community at Okta

Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today

Some roles may require travel to one of our office locations for in-person onboarding.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Personnel and Job Candidate Privacy Notice at

Okta

The foundation for secure connections between people and technology

Okta is the leading independent provider of identity for the enterprise. The Okta Identity Cloud enables organizations to securely connect the right people to the right technologies at the right time. With over 7,000 pre-built integrations to applications and infrastructure providers, Okta customers can easily and securely use the best technologies for their business. More than 19,300 organizations, including JetBlue, Nordstrom, Slack, T-Mobile, Takeda, Teach for America, and Twilio, trust Okta to help protect the identities of their workforces and customers.



  • Toronto, Ontario, Canada OMERS Full time US$80,000 - US$180,000 per year

    Choose a workplace that empowers your impact. Join a global workplace where employees thrive. One that embraces diversity of thought, expertise and experience. A place where you can personalize your employee journey to be — and deliver — your best.  We are a purpose-driven, dynamic and sustainable pension plan. An industry leading global investor with...


  • Toronto, Ontario, Canada n2psystems Full time

    We are seeking a skilled IAM Engineer with 3–7 years of experience in Identity and Access Management, including 2–3 years of hands-on experience with SailPoint IdentityNow (Identity Cloud). The ideal candidate will play a key role in designing, implementing, and maintaining our IAM solutions to ensure secure and efficient access to systems across the...

  • Customer Identity

    6 days ago


    Toronto, Ontario, Canada TD Full time $108,800 - $163,200 per year

    Work Location:Toronto, Ontario, CanadaHours37.5Line Of BusinessEnterprise Enabling FunctionsPay Details$108,800 - $163,200 CADTD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices...


  • Toronto, Ontario, Canada BridgeView Full time $120,000 - $180,000 per year

    Position: Senior AWS Security Engineer – Identity FocusThis position is a 6-month contract-to-hire and requires you to work on-site 3 days a week in downtown Toronto.Our team is looking for a DevOps engineer with at least 6 years cloud experience includingspecialization with Identity Our project involves building automations for a greenfield managedservice...


  • Toronto, Ontario, Canada Vanta Full time $120,000 - $180,000 per year

    At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior...


  • Toronto, Ontario, Canada Vanta Full time $120,000 - $180,000 per year

    At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Our Senior...


  • Toronto, Ontario, Canada Toyota Motor Corporation Full time US$80,000 - US$120,000 per year

    Job Description Identity & Access Management AnalystRank P5Scarborough, ON (Hybrid) Deadline: This posting will close by December 12, 2025, at 11:59 PM EST.Toyota Canada Inc. (TCI) currently has an exciting opportunity for an Identity and Access Management Analyst to support our Information Services team. This is a full-time opportunity and will report to...


  • Toronto, Ontario, Canada KPMG Full time

    OverviewAt KPMG, you'll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world.We are seeking an experienced SailPoint IdentityIQ and ISC Developer/Implementer . The ideal candidate will be involved in the development, implementation, and maintenance of...


  • Toronto, Ontario, Canada TD Full time $91,200 - $136,800 per year

    Work Location:Toronto, Ontario, CanadaHours:37.5Line of Business:Technology SolutionsPay Details:$91,200 - $136,800 CADThis role is temporarily eligible for a pay premium above the posted salary range that is reassessed annually. You are encouraged to have an open dialogue with your recruiter who can provide more specific pay details for this role.TD is...


  • Toronto, Ontario, Canada CIBC Full time $120,000 - $200,000 per year

    We're building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what's right for our clients.At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and...