SmithRx - Senior Identity Engineer
Requirements
• Cloud Proficiency: Strong hands-on background in AWS IAM, OPA, Rego, and designing zero-trust cloud architectures. • Cloud Proficiency: • NHI & Automation Expertise: Proven track record discovering, managing, and rotating machine identities, combined with a forward-looking approach to securing programmatic AI workflows. • NHI & Automation Expertise: • Platform Integration Skills: Advanced experience integrating core HRIS platforms (Workday) with Identity Providers, alongside managing complex fleet authentication (macOS/Windows). • Regulated Environment Acumen: Solid understanding of access control principles required in highly regulated sectors (e.g., PBM, Healthcare, HIPAA, Privacy), including continuous access reviews and audit logging capabilities. • Regulated Environment Acumen: • Operational Excellence: A demonstrated passion for maintaining detailed documentation and translating complex identity concepts into scalable, automated solutions. • Operational Excellence: • Certifications: Okta, AWS or SANS relevant Identity certifications. • Certifications: • Advanced Compliance: Deep experience mapping identity controls directly to ISO, SOC2, HITRUST, and specific privacy regulation frameworks. • Advanced Compliance: • What SmithRx Offers You: • Highly competitive wellness benefits including Medical, Pharmacy, Dental, Vision, and Life Insurance and AD&D Insurance • Flexible Spending Benefits • 401(k) Retirement Savings Program • Short-term and long-term disability • Discretionary Paid Time Off • Paid Company Holidays • Wellness Benefits • Commuter Benefits • Paid Parental Leave benefits • Employee Assistance Program (EAP) • Well-stocked kitchen in office locations • Professional development and training opportunities • Location: US - Remote
Responsibilities
• Core IAM & Lifecycle Automation: Architect and manage HR-driven provisioning by integrating Okta with Workday (Workday-as-a-Master) to automate complex attribute mapping and secure JML (Joiner/Mover/Leaver) lifecycles. • Core IAM & Lifecycle Automation: • SaaS Ecosystem Security: Engineer and deploy robust SSO (SAML 2.0, OIDC, OAuth 2.0) and SCIM provisioning for major enterprise applications, particularly Salesforce and Google Workspace. • SaaS Ecosystem Security: • Cloud Identity Architecture: Design least-privilege policies and manage AWS Identity Security, including cross-account role assumption, identity federation via Okta, and AWS SSO (Identity Center). • Cloud Identity Architecture: • Policy-Based Access Control (PBAC): Implement decoupled authorization for cloud-native applications utilizing Open Policy Agent (OPA) and authoring strict access policies in Rego. • Policy-Based Access Control (PBAC): • AI Agent Governance: Secure autonomous AI workflows by assigning distinct identities to AI models, governing their API access, and applying strict sandboxing to prevent unauthorized data retrieval. • AI Agent Governance: • Machine Identity Management: Own the lifecycle for traditional non-human identities (service accounts, OAuth tokens, API keys, X.509 certificates) to actively prevent secret sprawl across our cloud environment. • Machine Identity Management: • Contextual Access & Device Trust: Implement zero-trust device posture checks by integrating MDM telemetry and device certificates with Okta to enforce contextual, frictionless access for a mixed fleet of macOS and Windows endpoints. • Contextual Access & Device Trust: • Engineering Culture & Leadership: Mentor junior engineers, conduct rigorous architecture reviews, write clear documentation/runbooks, and elevate the overall identity security maturity of the team. • Engineering Culture & Leadership: • Experience: 5+ years of hands-on experience engineering, deploying, and managing enterprise IAM environments with deep Okta expertise.
Benefits
• Base Salary: The range listed above reflects our standard pay scale and actual pay will vary based on work location, job level, job-related knowledge, skills, and experience. • Total Rewards: In addition to base pay, this role may be eligible for bonuses, commissions, or equity. SmithRx offers a variety of benefits to help you live well, including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance and 401(k). • Individual offers are tailored to your geography, experience, skills, and education. Your recruiter can share more specific details during the hiring process. In the meantime, feel free to explore our comprehensive benefits here.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT