Sr. IAM Engineer

SubwayShelton, CT
Onsite

About The Position

The Sr. IAM Engineer is a hands-on senior technologist responsible for engineering, securing, and evolving Subway's enterprise identity platform. Subway operates a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This role owns complex federation, provisioning, and access-governance problems end to end, treating identity infrastructure as software — version-controlled, tested, deployed through CI/CD pipelines, and observable in production. The Sr. IAM Engineer serves as a senior subject matter expert and co-owner of IAM technical direction, a technical mentor within the IAM team, and a trusted design partner to Cybersecurity, Infrastructure, and HR Technology.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field — or equivalent work experience.
  • 7+ years in identity and access management, identity engineering, or security engineering with substantial IAM scope, including senior or lead-level ownership of identity platforms.
  • Deep, protocol-level expertise in OAuth 2.0 and OIDC (grant types, token lifecycles, PKCE, scopes and claims, bearer-token handling) and SAML 2.0 (assertions, metadata exchange, signing and encryption, SP- and IdP-initiated flows).
  • Hands-on expertise with Okta as an enterprise identity broker: Universal Directory, lifecycle management, Okta Workflows, SSO application integration, and SCIM provisioning; Okta Identity Governance experience strongly preferred.
  • Demonstrated application of zero-trust architecture and least-privilege access design in a production enterprise environment.
  • Advanced Active Directory design and administration in a hybrid IDaaS environment: OU and group strategy, GPO design, and tiered administration models; advanced Microsoft Entra ID policy design including Conditional Access, Identity Protection risk policies, and MFA policy.
  • Expert, protocol-level SCIM 2.0 knowledge — core and enterprise schemas, custom schema extensions, PATCH semantics, and provisioning error handling.
  • Strong grounding in API security: OAuth 2.0-protected API design, token validation and scoping, and the OWASP API Security Top 10 including BOLA/IDOR vulnerabilities.
  • Experience securing or governing identity for LLM and agentic AI systems: non-human identity lifecycle, credential scoping for AI agents, and least-privilege controls on machine-to-machine access.
  • Proficiency with CrowdStrike Falcon Identity Protection (ITDR, risk-based policy enforcement) or a comparable ITDR platform; experience querying identity telemetry in an enterprise SIEM.
  • Experience integrating endpoint security with identity on Windows and macOS: device posture signals in access policy, platform SSO/desktop MFA, and MDM integration (Jamf, Intune, or equivalent).
  • Proficient scripting in PowerShell, Python, and bash; DevOps fluency including Git-based source control and CI/CD pipeline authorship (Azure Pipelines or GitHub Actions).
  • 1+ year of experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, SuccessFactors, UKG, or similar).

Nice To Haves

  • Direct Ceridian Dayforce REST API experience (XRefCode addressing, position management, employment-status events).
  • AWS IAM and AWS IAM Identity Center experience, particularly permission-set-based access management.
  • Exposure to dedicated IGA tooling (SailPoint, Saviynt, Omada) at design or implementation level.
  • Familiarity with NIST SP 800-63 (digital identity assurance) and NIST SP 800-207 (zero trust architecture).
  • Background in regulated, franchise, or multi-entity environments where identity governance crosses organizational boundaries.
  • Relevant certifications: Okta Certified Professional/Consultant, CISSP, SC-300, or AWS Security Specialty.

Responsibilities

  • Engineer and operate Okta as the enterprise identity broker — Universal Directory, lifecycle management, SSO integrations (SAML 2.0, OIDC, WS-Federation to Microsoft 365), and Okta Workflows; design and troubleshoot federation end to end including assertion and token contents, claim/attribute mapping, signing and encryption, and session behavior across Okta, Entra ID, Active Directory, and downstream SaaS applications.
  • Maintain and enhance SCIM 2.0 provisioning at the protocol level — schemas, custom extensions, PATCH semantics, error handling, and reconciliation — between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, AWS IAM Identity Center, and Microsoft 365; own the hybrid attribute-mastering model and drive architectural changes that consolidate source-of-truth authority.
  • Apply zero-trust principles and enforce least privilege across the estate: phishing-resistant MFA and passwordless authentication, continuous evaluation of session and device context, privileged access management (PAM) with time-bound and just-in-time elevation, separation of duties, and access-governance controls via Okta Identity Governance including access certification campaigns and self-service access requests.
  • Secure identity for LLM and agentic AI systems — govern non-human identities, enforce scoped and short-lived credentials for agent access, apply human-in-the-loop authorization for sensitive actions; apply API security best practices including OAuth 2.0-protected API design, token validation and scoping, and defense against OWASP API Security Top 10 risks including BOLA/IDOR.
  • Integrate endpoint security with identity on Windows and macOS: device trust and posture signals in authentication policy, Okta FastPass/Device Trust, Entra device compliance, EDR posture, platform SSO, desktop MFA, and device-bound phishing-resistant credentials.
  • Design and implement joiner/mover/leaver automation driven by HRIS events; expand self-service access through the Okta access catalog and AWS IAM Identity Center permission-set-based self-service; build operational automation in PowerShell, Python, and bash; manage identity platform code in Git with peer-reviewed CI/CD pipelines and Terraform for identity-bearing cloud resources.
  • Own day-to-day identity platform operations: SSO application setup, IAM incident resolution and root-cause analysis, upgrades, patching, MFA management, and access cleanup; query identity telemetry in CrowdStrike Falcon Next-Gen SIEM and operate identity threat detection and response with CrowdStrike Falcon Identity Protection; support internal and external audits with access evidence.
  • Serve as a senior technical authority for IAM architecture and engineering decisions; develop and maintain identity architecture diagrams and configuration baselines; author technical design documents for significant automations and integrations prior to build; mentor IAM engineers and operations analysts; contribute to the strategic IAM roadmap and program maturity assessments.

Benefits

  • Insurance Plans (Medical, Life)
  • Pension/401K/RSP (country specific)
  • Competitive Bonus
  • Mobility Allowance
  • Tuition Reimbursement
  • Company Holidays
  • Volunteering time
  • And More…..
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service