Sr Identity & Access Engineer

OEConnection LLC
United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Artificial Intelligence Multi-Factor Authentication Federated Identity Management Identity and Access Management Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) OAuth OpenID Windows PowerShell Role-Based Access Control Azure Active Directory
+10 more
Security Assertion Markup Language (SAML) Security Information and Event Management Single Sign-On Systems Integration Scripting Okta Cyberark Information Technology SailPoint Splunk

Job description

You’ll own and evolve OEC’s enterprise identity platform-the core security control plane that protects everything we do. This role goes beyond administration: you’ll shape architecture, strengthen our security posture, and drive scalable identity solutions across Active Directory, Microsoft Entra ID, and Okta.

You’ll operate in a distributed U.S./India environment where autonomy, strong documentation, and thoughtful engineering are key. If you enjoy balancing security with user experience and want true ownership of a critical platform, this is that role.

What You’ll Do

  • Own the identity platform end-to-end: availability, performance, and security across AD, Entra ID, and Okta
  • Design modern access controls: MFA, passwordless, Conditional Access, and adaptive authentication
  • Enforce least privilege at scale using RBAC/ABAC and automate Joiner/Mover/Leaver (JML) processes
  • Lead cloud identity strategy across Entra ID and AWS IAM, including federation and workload identities
  • Secure privileged access with PIM/PAM and resilient break-glass patterns
  • Detect and respond to threats using SIEM/log platforms; lead identity-related incident investigations
  • Own SOC 2 identity controls including access reviews, certifications, and audit readiness
  • Act as a subject matter expert: build architecture diagrams, runbooks, and integration standards
  • Collaborate and mentor through peer reviews, knowledge sharing, and team upskilling
  • Participate in an on-call rotation supporting a critical security platform

Requirements

  • 7+ years of hands-on IAM experience in enterprise environments
  • Deep expertise across Active Directory, Entra ID, and Okta
  • Experience designing hybrid identity architectures and modern access strategies
  • Strong background in identity security, incident response, and compliance frameworks (SOC 2, NIST, ISO)
  • Proven ability to own and evolve platforms, not just support them

Technical Skills

You don’t need everything, but strong experience in most of the below:

  • Active Directory: domains, forests, GPOs, Kerberos, LDAP
  • Microsoft Entra ID: Conditional Access, MFA, Identity Protection, PIM, Entra Connect
  • Okta: SSO, lifecycle management, integrations, federation, Workflows
  • Protocols: SAML, OAuth 2.0, OIDC
  • Access Models: RBAC/ABAC, entitlement design, JML automation
  • Privileged Access: PIM, PAM, break-glass strategies
  • Cloud IAM: AWS IAM, federated identity, cross-platform trust
  • Security Monitoring: SIEM tools (Sentinel, Splunk), Entra & Okta logs
  • IGA Tools: SailPoint, Saviynt, or Entra ID Governance
  • PAM Tools: CyberArk, BeyondTrust, or Delinea
  • Automation: SCIM provisioning, scripting (PowerShell required)
  • Familiarity with AI-assisted scripting/tools (e.g., Copilot, Claude) is a plus
  • External identity (B2B): guest access, federation, Entra External ID

How You Work

  • Communicate clearly and constructively-even in high-pressure situations
  • Adapt quickly as priorities shift in a fast-moving environment
  • Thrive in a remote-first, highly autonomous team

Requirements

  • Bachelor’s degree in Computer Science, IT, or related field (or equivalent experience)
  • Relevant certifications preferred: SC-300, AZ-500, Okta Certified Professional/Admin

Benefits & conditions

  • Remote role (U.S.-based) with collaboration across global teams
  • Occasional travel (potentially international)
  • Camera-on participation expected for key meetings

Why This Role

This is a high-impact, high-ownership position where you’ll directly influence the security and scalability of a growing enterprise platform. You won’t just maintain systems-you’ll design, improve, and lead.

What We Offer:

  • Full benefits starting Day 1: Medical, Dental, and Vision
  • 401(k) with company match
  • Unlimited Flex Time Off plus 10 company-paid holidays
  • Professional development programs, tuition assistance, and quarterly book program
  • Free wellness coaching and pet insurance
  • Home office equipment stipend
  • Employee resource groups and exclusive employee discounts

What makes working at OEC awesome? It varies from employee to employee. For some, it’s the flexibility - whether it’s remote work or a hybrid or in-person role, OEC takes our teams across multiple time zones and international communities. For others, it’s the strong sense of camaraderie and community that celebrates both individuals and team-driven contributions. Or it could be the empowerment and how the team is encouraged to take risks, learn, and grow within a dynamic and supportive environment. But no matter what gets us out of bed in the morning, our whole global community is inspired to be forward thinking and drive innovative solutions for the automotive parts and repair industry.

About the company

OEC provides software solutions to those who work in the automotive parts and repair industry. Our solutions make it easier for automotive industry professionals to buy and sell parts, conduct repair research & planning, optimize estimates, improve the parts supply chain, and more. OEC partners with many of the world’s largest manufacturers, dealers and suppliers, shops and repairers, and service providers, giving our customers access to a comprehensive network and a streamlined workflow.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all