Senior Systems Engineer, IAM Operations

CrusoeSan Francisco, CA
$165,000 - $200,000

About The Position

Crusoe is looking for a Senior Systems Engineer to own day-to-day identity and access management operations. This is a hands-on role focused on keeping the Okta ecosystem running smoothly and securely. The engineer will oversee user lifecycle management, onboard applications to Okta for SSO, manage the governance platform (Lumos), and support the SaaS application stack. This role is the go-to for onboarding, offboarding, and access automation, acting as a Tier 2 escalation point for the Service Desk while building automations to ensure IAM operations are scalable as Crusoe grows.

Requirements

  • 5+ years of experience in Systems Engineering, IT Operations, or Identity & Access Management (IAM), with hands-on Okta administration experience.
  • Hands-on experience with Identity Governance platforms (e.g., Lumos, Okta Identity Governance, or similar governance frameworks) to manage access requests, entitlements, and periodic access reviews.
  • Proven experience managing user lifecycle automation, including onboarding, offboarding, hires, rehires, and contractor conversions.
  • Deep familiarity with Okta security features, such as FastPass multifactor authentication (MFA) and device trust.
  • Familiarity with SCIM provisioning, including building custom solutions when native support is unavailable.
  • Working knowledge of no-code or low-code automation tools, particularly Okta Workflows.
  • Strong troubleshooting skills across authentication issues, REST APIs, and scripting languages (e.g., Python, PowerShell) for bulk operations.
  • Experience supporting multi-platform enterprise environments, including Google Workspace and Slack.
  • Clear communication skills and comfort partnering cross-functionally with API, engineering, and Service Desk teams.

Nice To Haves

  • Exposure to identity governance platforms such as Lumos, Opal, or similar tools
  • Experience with application integrations using OIDC or SAML
  • Terraform or other infrastructure-as-code experience
  • Okta Administrator or Consultant certification

Responsibilities

  • Owning end-to-end user lifecycle management in Okta, including onboarding, offboarding, hires, rehires, and contractor conversions
  • Managing sensitive offboarding scenarios, including closing out lingering user sessions on personal devices across Slack, Google Workspace, and other platforms
  • Managing core SaaS application administration (e.g., Slack, Claude, Port.io, DocuSign), ensuring seamless user provisioning, role-based access control (RBAC), and automated license reclamation to optimize software spend
  • Building access request workflows and approval automations in our governance platform to streamline access delivery and enforce least-privilege principles
  • Building, executing, and supporting periodic user access reviews and entitlement certifications across core SaaS platforms to maintain compliance and audit readiness
  • Administering Okta security features, including FastPass multifactor authentication and device trust, to strengthen access across the environment
  • Building automations for application provisioning and repetitive IAM tasks using Okta Workflows and no-code platforms, including custom SCIM solutions where native support falls short
  • Training and empowering Service Desk team members on new security policies, IAM best practices, and major system changes, actively involving them in projects to ensure smooth operational handoffs
  • Acting as a Tier 2 escalation point for the Service Desk on complex access, authentication, and application integration issues
  • Partnering with the API team to define clear requirements for custom automations, leveraging Okta Workflows knowledge to bridge the gap between IAM and engineering
  • Troubleshooting authentication failures, API errors, and access-related incidents, using REST APIs and scripting to resolve issues or run bulk operations
  • Documenting SOPs and runbooks that keep IAM operations consistent and scalable as the team grows

Benefits

  • Competitive compensation and equity packages
  • Restricted Stock Units
  • Paid time off, paid holidays & leave of absence programs
  • Comprehensive health, dental & vision insurance
  • Employer contributions to HSA account
  • Paid parental leave
  • Paid life insurance, short-term and long-term disability
  • Professional development & tuition reimbursement
  • Mental health & wellness support
  • Commuter benefits (parking & transit)
  • Cell phone stipend
  • 401(k) Retirement plan with company match up to 4% of salary
  • Volunteer time off
  • Global travel insurance & emergency assistance
  • Daily meals allowance
  • Additional perks & programs specific to location
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service