IAM Engineer II

Tempus Inc
Chicago, IL, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$140,000.0 - $190,000.0
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Active Directory Application Programming Interfaces (APIs) Software as a Service Computer Programming Domain Name System (DNS) Multi-Factor Authentication Human Resources Information System (HRIS) Identity and Access Management Python (Programming Language) Kerberos (Protocol) OAuth
+14 more
OpenID Windows PowerShell Zero Trust Network Access Security Assertion Markup Language (SAML) User Provisioning Software Extensible Markup Language (XML) Scripting Event Processing Language Okta System Availability 3-tier Architectures Restful APIs Terraform Api Management

Job description

  • As a Senior IAM Engineer II, you will be the primary architect and guardian of our identity perimeter. You will design, implement, and maintain scalable identity solutions that secure our workforce. Your focus will be on transitioning away from manual provisioning toward a fully automated “Identity-as-Code” model using Okta Workflows and API integrations., + Architectural Leadership: Design and scale our Okta tenant, ensuring high availability and global best practices for SAML, OIDC, and OAuth 2.0 integrations.
  • Automation & Orchestration: Build complex lifecycle management (LCM) flows using Okta Workflows to automate joiner/mover/leaver processes across HRIS, AD, and downstream SaaS apps.
  • Hybrid Identity Management: Manage and optimize the synchronization between Active Directory (AD) and cloud identity providers.
  • API Integration: Develop custom integrations using REST APIs to connect homegrown or niche applications that lack out-of-the-box support.
  • Security & Compliance: Implement Adaptive Multi-Factor Authentication (MFA), Passwordless strategies, and regular access certifications to meet SOC2/ISO 27001/SOX requirements.
  • Escalation Support: Serve as the Tier 3 expert for complex authentication issues and identity-related security incidents.

Requirements

  • Okta Mastery: 5+ years of experience managing Okta at an enterprise scale, including advanced Workflows and Okta Expression Language.
  • Protocol Expertise: Deep understanding of the “Identity Trinity”:SAML 2.0: XML-based assertions and troubleshooting.OIDC/OAuth 2.0: Scopes, claims, and grant types (Authorization Code vs. Client Credentials).SCIM: Automating user provisioning and deprovisioning.
  • Directory Services: Strong background in Active Directory (Group Policy, Kerberos, DNS) and how it interfaces with modern cloud tenants.
  • Programming/Scripting: Proficiency in Python, PowerShell, or JavaScript for interacting with APIs and automating repetitive tasks.
  • Modern Security: Familiarity with Zero Trust Architecture (ZTA) and Least Privilege principles.
  • Soft Skills
  • Problem Solver: You don’t just fix the symptom; you find the root cause in the protocol trace.
  • Communicator: Ability to explain complex authentication flows to non-technical stakeholders (e.g., HR or Legal).
  • Continuous Learner: The identity landscape shifts weekly; you enjoy staying ahead of new standards like FIDO2 or Passkeys.
  • Bonus Points
  • Okta Certified Professional/Administrator/Consultant.
  • Experience with Infrastructure as Code (Terraform) for managing Okta resources.
  • Experience with Privileged Access Management (PAM) tools.
  • Experience with Identity Governance and Administration (IGA) tools.

Benefits & conditions

CHI - $140,000-$190,000

NYC - $150,000 - $200,000

The expected salary range above is applicable if the role is performed from Illinois and may vary for other locations (California, Colorado, New York). Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all