> Markdown version of [/jobs/ext/1315296-msp-identity-engineer](https://www.wearedevelopers.com/jobs/ext/1315296-msp-identity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # MSP Identity Engineer - **Company:** Tiger Advisory - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $100,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Application Integration Architecture, Confluence, Github, Identity and Access Management, Python (Programming Language), OAuth, OpenID, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, User Provisioning Software, Pulumi, Scripting, Okta, Git, Microsoft InTune, HR Software, Ws-federation, Slack, Ripple (payment Protocol), Cloudflare, Casper Suite, Gsuite, Terraform, Software Version Control - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=89e4e4f235820cc6 ## About the Role Required * 3 to 5+ years of hands-on experience administering identity platforms in an MSP, consulting, or multi-tenant environment. MSP experience is strongly preferred. In its absence, demonstrable experience operating across more than three concurrent identity environments or tenants is required. * Demonstrated comfort working directly with clients and cross-functional internal stakeholders. Discovery calls, technical briefings, project standups, and ongoing relationships are part of the job, not the exception. * Deep working knowledge of Okta: authentication policies, lifecycle management, Workflows, Okta Identity Governance, federation, and SAML, OIDC, and SCIM application integration. * Strong working knowledge of Entra ID: Conditional Access, Privileged Identity Management, entitlement management, and hybrid identity. * Working proficiency with Infrastructure as Code applied to identity. Terraform with the Okta and Microsoft Graph providers is preferred; equivalent experience with Pulumi or another declarative tool is acceptable. * Solid understanding of the underlying identity protocols: SAML 2.0, OIDC, OAuth 2.0, SCIM, and WS-Federation. * Excellent written and verbal communication skills, with the ability to adapt to both technical and non-technical audiences. Preferred * Okta Certified Administrator on hire; Okta Certified Consultant strongly preferred. * Microsoft Certified: Identity and Access Administrator Associate (SC-300). * Familiarity with version control workflows (Git, GitHub, peer-reviewed pull requests) applied to identity configuration. * Experience integrating identity with broader security tooling: SIEM, CASB, DLP (e.g., Nightfall AI), or zero-trust access platforms (e.g., Cloudflare One). * Scripting fluency in Python for identity automation., * How many years of experience do you have administering Okta? * How many concurrent Okta/EntraID environments have you managed in the last two years? * Do you have hands-on experience using Terraform or equivalent IaC to manage identity platforms specifically? * Have you ever worked in an MSP? * Do you hold an active Okta Certified Administrator credential or higher? ## Description This is a client-facing and stakeholder-facing engineering role. You will own the technical relationship with clients across their identity environments, serving as a trusted advisor on discovery calls, kickoffs, QBRs, and any engagement that requires an identity engineering presence. You will be embedded in active projects from day one, not brought in afterward. Identity is rarely the work in front of a client. It is the work behind everything else they do. New hires cannot start work without it. Executives cannot authenticate without it. Auditors cannot pass an access review without it. That is why we believe the best identity solutions come from engineers who are close to the problem: present in client conversations, fluent with internal partners across Sales, Customer Success, Project Management, and Service Delivery, and genuinely invested in the experience of the people who depend on the access you design. You will build and maintain identity environments across our client portfolio with a primary focus on Okta and a strong foundation in Entra ID. You will design lifecycle automation, drive Infrastructure as Code adoption, integrate identity governance into the client's broader security posture, and serve as the primary escalation point for the service desk on identity matters. You will also be a core contributor on identity infrastructure projects that come in through the door., Client Engagement * Participate in discovery, kickoff, and project scoping calls as the engineering voice on identity; ask good questions and translate client context into technical decisions. * Where necessary, attend ongoing client check-ins when engineering presence is warranted; build familiarity with each client's directory, authentication posture, application catalog, and identity governance maturity. * Partner with Customer Success Managers and Project Managers to ensure clients feel supported and informed, especially during complex migrations, access reviews, audits, or identity incidents. * Communicate trade-offs clearly to both technical and non-technical stakeholders; know when to escalate and when to ask for research time. * Build new identity tenants and onboarding workflows as new clients are brought on, owning the technical side of that process end-to-end. Internal Stakeholder Engagement * Partner with Sales during pre-sales and scoping to size identity work accurately and surface risk before contracts are signed. * Coordinate closely with Project Management on identity project execution: timelines, dependencies, credential handoffs, and structured cutovers. * Brief Customer Success and the Service Desk on every client's identity environment so the broader team can support clients without single points of failure. * Work fluidly with the endpoint and automation functions; identity decisions ripple through Jamf, Intune, and the rest of the toolstack, and the team needs you to flag that proactively. * Contribute to internal weekly L10 meetings and quarterly Rock planning on identity initiatives that affect the practice as a whole. Identity Platform Management * Manage and maintain Okta tenants across multiple client environments, including authentication policies, lifecycle management, federation (inbound and outbound), SAML, OIDC, and SCIM integrations, and Okta Identity Governance. * Design and maintain Entra ID configurations: Conditional Access, Privileged Identity Management, entitlement management, and hybrid identity. * Build and harden Okta Workflows for lifecycle automation, access provisioning, and integration with downstream systems, including HRIS platforms, Google Workspace, Microsoft 365, Slack, and client-specific apps. * Maintain awareness of adjacent identity platforms across the client portfolio (Google Workspace as IdP and 1Password) and advise on their configuration as needed. * Run periodic identity hygiene reviews: stale accounts, dormant sessions, MFA coverage, privileged role assignments, and lifecycle drift. Automation & Solution Development * Drive Infrastructure as Code adoption across client identity environments using Terraform (Okta and Microsoft Graph providers preferred) so configuration is repeatable, peer-reviewable, and auditable. * Design, test, and deploy joiner, mover, and leaver workflows, access request flows, and certification campaigns; incorporate scripting (Python) where Workflows and native tooling fall short. * Research and evaluate new identity tools, frameworks, and approaches; present findings and proposals to engineering leadership and client stakeholders. * Ensure all changes are validated in a staging or sandbox tenant before production rollout. Internal Escalation & Mentorship * Serve as the go-to escalation point for the service desk and other team members on identity issues; be accessible, not just available. * Lead on identity incidents with a wide impact (an authentication outage, a misconfigured policy, a compromised credential): triage, communicate, contain, and drive the postmortem and structural fix. * Partner with the Director of Engineering to monitor industry trends and develop proactive strategies for the identity practice. * Share knowledge actively to raise the identity literacy of the broader team. Transfer the reasoning, not just the fix. Documentation * Maintain comprehensive runbooks, configuration records, and procedures in Confluence. * Create and update internal and external-facing documentation for each client environment, including authentication policy decision frameworks and reusable identity standards. ## Related Videos - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Stack Overflow: Community and AI](https://www.wearedevelopers.com/videos/600-stack-overflow-community-and-ai) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Cloud as the new mainframe: why the cloud hype does not reflect the dev reality](https://www.wearedevelopers.com/videos/797-cloud-as-the-new-mainframe-why-the-cloud-hype-does-not-reflect-the-dev-reality) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How to Answer the “Why Should We Hire You” Interview Question](https://www.wearedevelopers.com/magazine/321-how-to-answer-the-why-should-we-hire-you-interview-question)