GuidePoint Security - IAM Architect - Okta (Remote in the US)
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• Bachelor's degree in Computer Science, Information Security, or related field — or equivalent work experience • 5–7+ years of experience in Identity and Access Management engineering or Consulting • Extensive hands-on experience with Okta including Universal Directory, Lifecycle Management, Workflows, and API Access Management • Proven experience designing and implementing Okta Access Gateway (OAG) solutions • Proven experience designing and implementing Okta Access Gateway (OAG) • Strong experience developing complex Okta Workflows including custom connectors and API integrations • Strong experience developing complex Okta Workflows • Proficiency in API development languages including Python, JavaScript/Node.js, and PowerShell • Proficiency in API development languages • Python, JavaScript/Node.js, and PowerShell • Experience with REST API development and integration • REST API development and integration • Proven track record leading technical architecture on large-scale, complex IAM projects for enterprise organizations • Proven track record leading technical architecture on large-scale, complex IAM projects • Strong understanding of identity governance, SSO protocols (SAML, OIDC, OAuth), MFA, and access certification • Experience with Windows/Linux server administration and Active Directory • Deep knowledge of common security frameworks and access control principles • Demonstrated ability to design and document complex technical architectures • 5-7+ years of IT Professional services and consulting experience • Experience with very large and complex enterprise IAM transformations • Professional certifications such as: • Okta Certified Professional / Okta Certified Administrator / Okta Certified Consultant (highly preferred) • Okta Certified Professional / Okta Certified Administrator / Okta Certified Consultant • CISSP, CISM, Security+, CCSP, or similar • Advanced experience with Okta Workflows including helper flows, error handling, and performance optimization • Experience with additional API development languages such as Java, Go, or Ruby • Experience with additional API development languages • Experience with Microsoft Entra ID (formerly Azure AD) including Conditional Access and Identity Protection (nice-to-have) • Working knowledge of Ping Identity solutions (PingFederate, PingOne, or PingAccess) (nice-to-have) • Exposure to modern IAM capabilities: • Passwordless authentication (FIDO2, WebAuthn, passkeys) • Decentralized identity and verifiable credentials • Identity threat detection and response (ITDR) • API security and OAuth 2.0 / OpenID Connect • Experience with CI/CD pipelines and Infrastructure as Code (Terraform, CloudFormation) • Experience with containerization and orchestration (Docker, Kubernetes) • The Team • Coming to the Access Management team means working on the leading edge in the IAM space. As an Access Management Architect, you will be partnering with other engineers and architects to help some of the largest companies in the US implement their own identity and access management programs. You will lead technical architecture on complex, enterprise-scale Okta implementations, from participating in assessments to full delivery of IAM platforms. Your leadership and expertise are critical to providing our customers with the guidance they need, and the excellence they expect from GuidePoint Security. • We partner with the largest vendors in the space to ensure that the latest training is always available to our team. High level communication and collaboration are the standard. Mentorship at all levels, from Senior Architects to Junior Engineers, is foundational to our culture. We don't just talk about work life balance; we facilitate it with an unlimited PTO benefit. • We understand that in order to retain our talented team, leadership must provide regular feedback and coaching. We recruit new members to the team with the understanding that opportunities for growth are important. Whether your goals include future leadership opportunities, becoming an Architect or even moving to another discipline within security in time, the leadership team is focused on partnering with you to help achieve them. • We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application. • Why GuidePoint?GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.
Responsibilities
• Code Development & Web Services (25% of role) • Develop custom web services including Secure Token Service (STS) capabilities for authentication and authorization workflows • Build custom integrations and automation using API development languages including Python, JavaScript/Node.js, PowerShell, Java, and REST APIs • Develop complex Okta Workflows including custom connectors, helper flows, and API integrations • Create Auth0 Action Scripts for custom authentication and authorization logic • Develop PingFederate custom adapters and integration kits • Build custom connectors and integrations for Okta, Auth0, Ping Identity, and Microsoft Entra ID platforms • Develop API gateways, middleware solutions, and identity federation components • Create automation scripts for identity lifecycle management, provisioning, and access governance • Code Operationalization & Repository Management (25% of role) • Establish and maintain a sanitized internal code repository for Access Management practice assets • Develop standards and procedures for code sanitization, ensuring all client-specific information is removed before code is stored internally • Create reusable code libraries, templates, and frameworks from client engagement deliverables • Build and maintain a catalog of reusable code assets including: • Okta Workflows templates and custom connectors • Auth0 Action Scripts libraries • PingOne DaVinci automation libraries • PingFederate custom adapters • API integration patterns and middleware components • Automation scripts and helper utilities • Implement version control best practices using Git and establish branching strategies • Develop documentation standards for all code assets including usage guides, API documentation, and implementation examples • Create code review processes and quality assurance standards for internal code contributions • IAM Platform Administration & Implementation (50% of role) • Deploy, configure, and manage Auth0 tenants including user stores, connections, APIs, and applications for client CIAM implementations • Implement Auth0 Universal Login experiences with custom branding, MFA, and passwordless authentication flows • Configure Auth0 Organizations for B2B CIAM scenarios including multi-tenant architectures and organization-level policies • Design and implement customer identity and access management (CIAM) solutions using Auth0 for consumer-facing applications and digital experiences • Build and configure Auth0 Actions pipelines for custom authentication and authorization logic in login, registration, and post-login flows • Implement social identity providers (Google, Facebook, Apple, etc.) and enterprise connections for customer authentication • Configure Auth0 APIs and Machine-to-Machine (M2M) authentication for secure API access management • Deploy and manage Okta environments including Universal Directory, Lifecycle Management, Workflows, and API Access Management for client implementations • Implement and configure Okta Access Gateway (OAG) solutions for header-based authentication and legacy application integration • Deploy and configure Ping Identity solutions including PingFederate, PingOne, and PingAccess for client environments • Implement and manage Microsoft Entra ID (formerly Azure AD) including Conditional Access, Identity Protection, and application integrations • Configure Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Adaptive Authentication across client application portfolios • Implement progressive profiling, user consent management, and privacy controls for CIAM use cases • Design and implement customer registration and onboarding flows with email verification, social sign-up, and self-service account management • Configure Auth0 user migration strategies including bulk imports, trickle migration, and automatic migration from legacy identity systems • Implement user lifecycle governance including provisioning, deprovisioning, and access certification workflows • Configure authentication policies, authorization rules, and security controls for client deployments • Integrate IAM platforms with AD/LDAP, cloud directories, SCIM provisioning, SAML/OIDC applications, and cloud services (AWS/Azure/GCP) • Implement customer data synchronization between Auth0 and CRM systems, marketing platforms, and customer data platforms (CDPs) • Configure Auth0 log streaming to SIEM solutions and analytics platforms for customer behavior monitoring • Perform platform administration tasks including user management, group management, policy configuration, and troubleshooting • Support client implementations by configuring applications, testing integrations, and resolving technical issues • Provide technical support during client onboarding and post-implementation phases • Project Oversight & Client Success • Lead technical architecture on very large and complex IAM transformation projects • Provide both strategic and tactical oversight on either a single large client engagement or multiple smaller projects concurrently • Provide technical guidance and mentorship to delivery team members • Identify and mitigate technical and project risks, escalating issues when necessary • Develop and refine standard operating procedures (SOPs) and templates to improve consistency and quality across engagements • Create and maintain technical architecture documentation, implementation guides, and best practice frameworks
Benefits
• We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application. • Why GuidePoint?GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers. • Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity. • This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.Some added perks…. • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions) • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options) • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans • 12 corporate holidays and a Flexible Time Off (FTO) program • Healthy mobile phone and home internet allowance • Eligibility for retirement plan after 2 months at open enrollment • Pet Benefit Option
No credit card. Takes 10 seconds.