IAM Engineer

SubwayShelton, CT

About The Position

The IAM Engineer builds and operates the day-to-day identity and access management capabilities that keep Subway's workforce productive and secure. Subway runs a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This is a hands-on operational and engineering role — owning the daily health of the identity platform while building the automation that steadily retires manual work. The role carries a clear development path toward senior-level identity engineering, including deeper federation and protocol work, access governance, identity threat detection, and security architecture.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field — or equivalent work experience.
  • 3–5 years in IAM, identity operations, systems administration with significant identity scope, or a related security/infrastructure role.
  • Hands-on experience with Okta or a comparable identity provider: user and group administration, application SSO integration, and lifecycle management; Okta strongly preferred.
  • Working knowledge of SSO and federation protocols — SAML 2.0, OIDC, and OAuth 2.0 fundamentals — sufficient to configure and troubleshoot integrations.
  • Working knowledge of SCIM provisioning concepts and troubleshooting: attribute mapping, sync errors, and reconciliation.
  • Active Directory fundamentals (users, groups, OUs, group policy awareness) and familiarity with Microsoft Entra ID and Microsoft 365 administration.
  • Scripting proficiency in PowerShell or Python for operational automation (both, plus bash, preferred).
  • Experience working with REST APIs: authentication, reading API documentation, and basic troubleshooting of API-driven integrations.
  • Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.
  • Comfort working with Git-based source control and participating in CI/CD-based change processes.
  • Hands-on fluency with LLM and generative AI tools in day-to-day technical work.

Nice To Haves

  • Working understanding of how AI agents authenticate and are authorized to enterprise systems — non-human identities, credential scoping, and emerging integration patterns such as the Model Context Protocol (MCP) — including experience building, deploying, or securing MCP servers or agentic AI workflows.
  • Exposure to identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar) or SIEM platforms.
  • Awareness of API security concepts including the OWASP API Security Top 10 and authorization flaws such as BOLA/IDOR.
  • Exposure to endpoint management and device trust as they relate to identity (Jamf, Intune) on Windows or macOS.
  • Experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, UKG, or similar).
  • AWS IAM or AWS IAM Identity Center exposure.
  • Okta Certified Professional/Administrator or Microsoft identity certification (SC-300).

Responsibilities

  • Operate the identity platform day to day: new SSO application setup, access request fulfillment and escalations, MFA management, group and access cleanup, and account lifecycle corrections; troubleshoot provisioning and authentication issues end to end — SCIM sync failures, attribute mismatches, SSO errors — performing root-cause analysis and documenting resolutions as runbooks.
  • Handle complex onboarding, offboarding, and HR-driven downstream changes outside automated lifecycle flows, treating offboarding as security-critical work; manage IAM tickets and service requests in ServiceNow meeting SLA targets; serve as an internal escalation point for complex identity issues from the Technology Support Center and business teams.
  • Build Okta Workflows for identity lifecycle events, application provisioning, and remediation tasks; expand the Okta access catalog to convert recurring ticket categories into governed self-service with owner/manager approval; implement joiner/mover/leaver automation driven by HRIS events; contribute to AWS access self-service through AWS IAM Identity Center permission sets.
  • Script operational automation in PowerShell or Python — reconciliation, reporting, cleanup, and provisioning tasks; participate in upgrades, patching, and change tickets for identity infrastructure, and the team's shared on-call rotation.
  • Operate SCIM 2.0 provisioning between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, Microsoft 365, and AWS IAM Identity Center; support the transition off a legacy custom SCIM connector to broker-native provisioning; configure SSO integrations (SAML 2.0, OIDC) for new applications.
  • Apply least-privilege principles in daily access work — right-sized group and role assignments, time-bound privileged access, and cleanup of dormant or over-privileged accounts; support Okta Identity Governance operations including access certification campaigns; administer non-human identities and service accounts for LLM and agentic AI integrations applying least-privilege credential-scoping patterns.
  • Collaborate with the broader Cybersecurity engineering teams on shared projects; assist investigations of access anomalies alongside senior engineers and the Detect & Respond team; support internal and external audits with access evidence; author and maintain runbooks, knowledge-base articles, and hand-off documentation for new automations.

Benefits

  • Insurance Plans (Medical, Life)
  • Pension/401K/RSP (country specific)
  • Competitive Bonus
  • Mobility Allowance
  • Tuition Reimbursement
  • Company Holidays
  • Volunteering time
  • And More…..
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service