> Markdown version of [/jobs/ext/3570758-senior-systems-engineer](https://www.wearedevelopers.com/jobs/ext/3570758-senior-systems-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Systems Engineer - **Company:** IBM - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Systems Engineering, Audit Trail, Authentication Protocols, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Engineering, Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Virtual Desktops, OAuth, OpenID, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Systems Integration, Google Cloud, Okta, Software Security, Zapier, Multi-Cloud, Amazon Virtual Private Cloud (VPC), Microsoft InTune, Github Enterprise, Palo Alto Networks, Casper Suite, Gsuite, Virtual Agents, SailPoint - **Published:** October 3, 2026 - **Apply:** https://dejobs.org/x/x/D8371517263B4D70BC5861CF514A9D1F/job/ ## About the Role * 5+ years of experience in systems, identity, or cloud engineering, ideally at a fast-moving tech or SaaS company * Enterprise IdP administration: hands-on, at-scale experience with Okta and/or Microsoft Entra ID (Azure AD) * Authentication protocols: solid working knowledge of SAML 2.0, OAuth 2.0 / OIDC (including Authorization Code with PKCE and Client Credentials / 2-legged flows), and SCIM provisioning * Identity governance: experience with SailPoint (IdentityIQ/IdentityNow), Saviynt or a comparable IGA tool, including account correlation and access reviews * Multi-cloud: working experience across AWS, Azure, and GCP - IAM/RBAC, service accounts, subscription/project provisioning, and network security controls (e.g., VPC Service Controls) * Zero Trust & Network Security: Experience administering Palo Alto Networks enterprise VPN and SASE solutions (GlobalProtect, Panorama, and Prisma Access)-including HIP policy management, gateway troubleshooting, egress NAT management, and network-level access controls. * SaaS administration: experience administering Google Workspace or Microsoft 365 at an organizational level, including domain-wide delegation and API security controls * Compliance exposure: experience supporting audits or controls for frameworks such as FedRAMP, SOC 2, or ISO 27001 * Automation mindset: comfort with GitOps/IaC workflows and scripting (Python, shell, or similar) to replace manual, repetitive work * Excellent written and verbal communication; able to explain technical tradeoffs clearly to engineers, auditors, and non-technical stakeholders alike * Strong troubleshooting instincts and comfort owning ambiguous, cross-system problems through to root cause Preferred technical and professional experience * Experience with GitHub Enterprise administration (SSO mapping, team synchronization, repo access governance, audit logging) * Experience with Azure Virtual Desktop (AVD) or other VDI environments * Familiarity with Jamf or Intune for device lifecycle and endpoint management * Experience integrating enterprise AI tools or agents (e.g., Glean) with existing identity and SaaS systems * Relevant certifications (AWS/Azure/GCP, Okta Certified Professional, CISSP, or similar) * Exposure to additional compliance frameworks such as IRAP ## Description We're looking for a Senior Systems Engineer who can own systems end-to-end: designing, hardening, and running the identity, infrastructure, automations, and zero trust systems that every employee depends on. You're as comfortable untangling an OAuth scope issue in Okta as you are architecting a Global Protect rollout or leading a FedRAMP access review. You default to automation and documentation over one-off fixes, and you know how to partner with security, infrastructure, and compliance teams to keep a fast-moving company both productive and audit-ready. * Identity & Access Management: administer and evolve enterprise IdP infrastructure across Okta (SAML/OIDC, SCIM, group rules, Auth Policies) * Identity Governance: own identity governance processes in SailPoint (account aggregation, flatfile integrations, manual account correlation) and lead quarterly User Access Reviews (UARs) * Multi-Cloud Administration: administer and govern AWS, Microsoft Azure, and GCP environments, including RBAC roles, subscription provisioning, VPC Service Controls, service accounts, and IAM policy resets * Zero Trust & Network Security: Architect and administer Palo Alto Networks security platforms (GlobalProtect/Prisma Access), including Host Information Profile (HIP) check rules, connector configuration, split-tunneling/resource routing, URL/IP allowlisting, and egress IP management across standard and FedRAMP environments. * SaaS, AI & Developer Platforms: administer Google Workspace (Domain-Wide Delegation, service accounts, API controls), GitHub Enterprise IAM, Azure Virtual Desktop (AVD), Glean AI agent connectors, and Workato integrations * Security Audits & Compliance: lead technical evidence collection and remediation for UARs and other access reviews, enforcing least-privilege and Just-in-Time (JIT) access patterns * Automation: identify recurring manual work across identity, cloud, and access processes and build scripts or integrations (Okta Workflows, Python/shell, Workato) to eliminate it * Escalate and partner with security, infrastructure, and network engineering on complex or cross-system issues, with clear, well-documented context * Author and maintain runbooks and architecture documentation so the systems you own don't depend on tribal knowledge ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)