Identity & Access Management Architect
Role details
Job location
Tech stack
Job description
ryWe are seeking a hands-on IAM Architect to lead our enterprise workforce identity migration from Microsoft Entra ID to Okta (~1,800 users), targeting a federation cutover in Q3 2026. You will own the migration architecture end-to-end ? federation design, app integrations, cutover, and stabilization ? working alongside our internal Enterprise Cybersecurity team and an external implementation partner. Beyond the migration, you'll help build and operate our identity ecosystem, with the opportunity to contribute to a custom identity orchestration and governance platform. This is a 6-month contract with strong potential for conversion to a full-time rol
e. Key Responsibilit
iesOkta Migration & IAM Operations (co
re)* Lead technical architecture for the Entra ID to Okta workforce identity migration: federation design, app integration sequencing, cutover planning, rollback strategy, and hyperc
are* Design and build SSO/SAML/OIDC integrations across the enterprise application portfolio; architect multi-tenant deployment (separate US/EU tenants) to meet regional data requireme
nts* Architect lifecycle management and provisioning workflows (HR-driven joiner/mover/leaver), including SCIM integrati
ons* Define and implement MFA, adaptive authentication, and device assurance policies aligned to a zero-trust road
map* Serve as technical counterpart to the implementation partner: review designs, challenge assumptions, hold delivery quality to stand
ard* Maintain and operate the Okta environment post-cutover: policy tuning, integration onboarding, incident support, and operational runbo
oks* Produce audit-ready documentation for an ISO 27001 / TISAX-aligned control environm
entIdentity Orchestration & Governance (seconda
ry)* Contribute to the design and build of a custom identity orchestration layer (Databricks or equivalent): attribute-driven provisioning, ABAC policy models, JIT privileged access, anomaly detection, automated deprovisioning, and audit/recertification capabilit
Requirements
ions* 7+ years in identity and access management, with 3+ years hands-on Okta experience building, deploying, and maintaining Okta Workforce Identity Cloud environm
ents* At least one completed enterprise migration from Entra ID / Azure AD to Okta as architect or technical
lead* Deep expertise in SAML, OIDC, OAuth 2.0, SCIM, and directory integration (AD/Entra ID hybrid scenar
ios)* Experience operating and administering Okta in production: policy management, app integrations, lifecycle workflows, troubleshoo
ting* Experience designing MFA and adaptive access policies at enterprise s
cale* Strong documentation skills; able to produce audit-ready artif
acts* Proven ability to work alongside system integrators while retaining architectural owner
ship Preferred Qualifica
tions* Okta Certified Consultant or Okta Certified Arch
itect* Experience building custom identity automation or governance tooling using Python/SQL, event-driven pipelines, and
APIs* Working knowledge of data platforms (Databricks, Spark, or comparable) for event ingestion and proce
ssing* Experience with ABAC/policy-based authorization models and JIT/ephemeral privileged access patterns i
n AWS* SIEM integration experience (log normalization, detection engineering for identity sig
nals)* Familiarity with IGA platforms, PAM solutions, and enterprise password man
agers* Experience in regulated or automotive environments (TISAX, ISO 27001, NIST 80
Benefits & conditions
We provide a competitive pay and benefits package. This position is offering a pay range of $78.19 - $103.41/hr. however, Belcan considers several factors when extending an offer, including but not limited to education, experience, geographic location, and discipline. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law