
Senior Systems Engineer, IAM Operations
Job description
About the role
You will own the day-to-day operations of identity and access management across Crusoe, ensuring that Okta remains the reliable and secure foundation for workforce and application access. This is a hands-on operational role where you will manage the full user lifecycle inside Okta, from onboarding to offboarding, including complex contractor conversions and sensitive exit scenarios. You will act as the central expert for our SaaS application stack, administering critical tools such as Slack, Claude, Port.io, DocuSign, and others to maintain tight RBAC and optimized license usage. You will design and execute access request workflows and approval automations in our governance platform to enforce least-privilege and streamline secure access delivery. You will run and support periodic user access reviews and certification programs that keep our environment compliant and audit-ready. You will configure and maintain Okta security capabilities, including FastPass multifactor authentication and device trust, to harden access across all identities. You will build scalable automations using Okta Workflows and no-code tools, filling gaps where native SCIM and integration features fall short. You will serve as a Tier 2 escalation resource for the Service Desk, guiding them through complex authentication, authorization, and application integration issues. You will partner closely with the API team to translate IAM requirements into clear specifications for custom automations and integrations. You will create and maintain SOPs and runbooks that document every step of IAM operations so the team can scale without losing consistency.
Key facts
What you'll do
- Own end-to-end user lifecycle management in Okta, including onboarding, offboarding, hires, rehires, and contractor conversions.
- Manage sensitive offboarding scenarios, including closing out lingering user sessions on personal devices across Slack, Google Workspace, and other platforms.
- Administer core SaaS application operations such as Slack, Claude, Port.io, DocuSign, ensuring seamless provisioning, role-based access control, and automated license reclamation.
- Build access request workflows and approval automations in the governance platform to streamline access delivery and enforce least-privilege principles.
- Execute periodic user access reviews and entitlement certifications across core SaaS platforms to maintain compliance and audit readiness.
- Administer Okta security features, including FastPass multifactor authentication and device trust, to strengthen access across the environment.
- Develop automations for application provisioning and repetitive IAM tasks using Okta Workflows and no-code platforms, including custom SCIM solutions where native support is insufficient.
- Train and empower Service Desk team members on new security policies, IAM best practices, and major system changes to ensure smooth operational transitions.
- Act as a Tier 2 escalation point for the Service Desk on complex access, authentication, and application integration issues.
- Collaborate with the API team to define requirements for custom automations, leveraging Okta Workflows expertise to connect IAM needs with engineering solutions.
- Troubleshoot authentication failures, API errors, and access-related incidents, using REST APIs and scripting to resolve issues or run bulk operations.
- Document standard operating procedures and runbooks that keep IAM operations consistent and scalable as the team expands.
- Monitor identity and access operations to detect anomalies, support audit activities, and recommend improvements to security posture.
- Coordinate with infrastructure and cloud teams to align IAM configurations with network, compute, and security controls.
Requirements
- Bring 5+ years of professional experience in Systems Engineering, IT Operations, or Identity and Access Management.
- Demonstrate hands-on administration of Okta, including user management, security settings, and integration scenarios.
- Show a track record of managing user lifecycle automation, including onboarding, offboarding, rehires, and contractor workflows.
- Highlight proven ability with Identity Governance platforms such as Lumos or similar frameworks for access governance and certification.
- Exhibit deep familiarity with Okta security capabilities, including FastPass MFA and device trust configurations.
- Have direct experience with SCIM provisioning and custom solutions when native integrations do not meet requirements.
- Apply working knowledge of no-code or low-code automation tools, especially Okta Workflows, to solve operational challenges.
- Display strong troubleshooting skills for authentication issues, REST APIs, and scripting in languages such as Python or PowerShell.
- Have background supporting multi-platform enterprise environments, including Google Workspace and Slack.
- Communicate clearly and collaborate effectively with cross-functional teams such as API, engineering, and Service Desk.