Senior Identity Engineer

Tyler Technologies
Plano, TX, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$102,718.0 - $140,000.0
Working hours
Regular working hours

Tech stack

Microsoft Access JavaScript (Programming Language) Active Directory Active Directory Federation Services Agile Methodology Amazon Web Services Apple Mac Systems JIRA User Authentication Microsoft Azure Linux Multi-Factor Authentication
+18 more
Human Resources Information System (HRIS) Identity and Access Management JSON Python (Programming Language) OAuth OpenID Windows PowerShell Scrum Methodology Azure Active Directory Runbook Security Assertion Markup Language (SAML) Kronos Scripting Okta Build Management Information Technology Terraform Serverless Computing

Job description

Plano, Texas | Yarmouth, Maine | Troy, Michigan | Latham, New York | Remote Travel 0-5% Responsibilities Serve as the technical owner and subject matter expert for Okta (Workforce Identity + Identity Governance), Microsoft Entra ID, and Active Directory. Architect and operate the UKG Okta AD identity lifecycle pipeline, including UKG Pro connector validation, attribute mapping, Universal Directory profile design, and Okta AD Agent write-back. Design and build Okta Workflows for Joiner / Mover / Leaver automation, including SCIM provisioning, HTTP connector flows, and migration of Azure Runbooks into Okta Workflows. Engineer application bridges for downstream targets Okta does not natively integrate, such as with Lambda and Azure Functions. Ownership of SSO strategy (SAML, OIDC, SCIM, Federation), application onboarding standards, and the Okta application catalog. Design and maintain authentication and access policies. Multifactor Authentication, adaptive risk-based authentication, network zones and authenticator enrollment policies. Lead Active Directory hygiene and remediation: stale account cleanup, group rationalization, GPO linkage reviews, SPN management, OU placement standards, and contractor census alignment. Build and operate identity dashboards across AD / Okta / Entra ID for operational visibility and license utilization. Maintain non-production tenants for testing, validation, and change rehearsal prior to production cutover. Mentor IT Analysts and Infrastructure Engineers across Okta, Entra ID, and AD. Participate in Agile/Scrumban ceremonies using JSM/Jira as the system of record. Document and maintain architecture diagrams, configuration baselines, runbooks, SOPs, and training paths. Participate in IT projects, change management, incident response, and on-call rotation for identity platform issues.

Requirements

Minimum 5 years of IT experience with a meaningful portion dedicated to identity and access management in a mid-to-large sized enterprise. Hands-on experience with Okta –Workforce Identity, Universal Directory, Lifecycle Management, Workflows, Access Gateway, Okta Identity Engine. Hands-on experience with Microsoft Entra ID - Conditional Access, app registrations, enterprise apps, PIM, B2B, hybrid join. Active Directory engineering experience - multi-domain/multi-forest, Group Policy, Sites & Services, ADFS, AD/Entra Connect, PowerShell. Working knowledge of AWS IAM, IAM Identity Center, AWS Managed AD, and federation patterns. Production experience designing and operating SAML 2.0, OIDC/OAuth 2.0, SCIM 2.0, and WS-Fed integrations. Experience automating identity lifecycle (Joiner / Mover / Leaver) from an HRIS source. Strong scripting/automation skills: PowerShell (required) and at least one of Python, JavaScript, Terraform, and/or JSON. Experience with MFA platforms and modern authenticators (Okta Verify, Microsoft Authenticator, FIDO2 / hardware-based keys). Familiarity with compliance frameworks: NIST CSF, SOC 2, SOX, CJIS, FedRAMP. Excellent written and verbal communication and documentation discipline. Working knowledge of Windows, Linux and macOS.

About the company

Some travel is required. Will be required to undergo and satisfactorily pass a fingerprint background check (for CJIS requirements). Certifications Okta Certified Professional / Administrator / Consultant / Architect Microsoft SC-300 - Identity & Access Administrator Associate Microsoft AZ-500 - Azure Security Engineer Microsoft AZ-800 / AZ-801 - Windows Server Hybrid Administrator AWS Certified Security - Specialty (SCS-C02) CISSP, SANS GIAC (GCIA / GCIH / GPCS), or equivalent) State-Specific Salary Range Disclosure Requirements Salary will generally fall between $102,718 - $140,000 before adjustment for geographic differences. Recruiter can confirm if position is incentive eligible. Great Place to Work & Grow Your Career Come join us as we transform the public sector! Our mission, vision, and values guide everything we do. We’re also frequently recognized as a great workplace locally and nationally. See our many awards and accolades. Taking Care of You & Your Family Your health and well-being are important to us. That’s why we invest in our team members by offering competitive benefits to support their health and financial wellness. Learn more about how we care for our people.

Tyler is subject to regulations, guidelines, and/or client requirements relating to the qualifications of Tyler personnel performing certain client work. Because of the nature of this position, it is a requirement that the candidate can successfully pass a federal background check at the time an offer is extended and over the course of employment with Tyler.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.mitalent.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

Videos

See all

Related articles

See all