IAM Architect – Okta Migration (Contract-to-Hire)
Why This Role Stands Out
This contract-to-hire role offers a significant opportunity to lead a high-impact Okta migration, shaping the future of identity management for a growing company. You'll thrive here if you possess strong architectural skills in IAM, particularly with Okta, and enjoy end-to-end project ownership and collaborative problem-solving. Apply now to gain exposure to cutting-edge identity solutions and a potential full-time career path.
Quick Overview
Job Description
Job Title: Identity & Access Management Architect – Okta Migration (Contract-to-Hire)
Job Summary
Seeking a hands-on IAM Architect to lead our enterprise workforce identity migration from Microsoft Entra ID to Okta (~1,800 users), targeting a federation cutover in Q3 2026. You will own the migration architecture end-to-end — federation design, app integrations, cutover, and stabilization — working alongside our internal Enterprise Cybersecurity team and an external implementation partner. Beyond the migration, you''ll help build and operate our identity ecosystem, with the opportunity to contribute to a custom identity orchestration and governance platform. This is a 6-month contract with strong potential for conversion to a full-time role.
Location: Palo Alto, CA (hybrid preferred; remote considered for exceptional candidates)
Duration: 6 months initial term, with conversion to full-time employment possible based on performance
Key Responsibilities
Okta Migration & IAM Operations (core)
- Lead technical architecture for the Entra ID to Okta workforce identity migration: federation design, app integration sequencing, cutover planning, rollback strategy, and hypercare
- Design and build SSO/SAML/OIDC integrations across the enterprise application portfolio; architect multi-tenant deployment (separate EU tenants) to meet regional data requirements
- Architect lifecycle management and provisioning workflows (HR-driven joiner/mover/leaver), including SCIM integrations
- Define and implement MFA, adaptive authentication, and device assurance policies aligned to a zero-trust roadmap
- Serve as technical counterpart to the implementation partner: review designs, challenge assumptions, hold delivery quality to standard
- Maintain and operate the Okta environment post-cutover: policy tuning, integration onboarding, incident support, and operational runbooks
- Produce audit-ready documentation for an ISO 27001 / TISAX-aligned control environment
Identity Orchestration & Governance (secondary)
- Contribute to the design and build of a custom identity orchestration layer (Databricks or equivalent): attribute-driven provisioning, ABAC policy models, JIT privileged access, anomaly detection, automated deprovisioning, and audit/recertification capabilities
- Support integration of identity and authorization event logs into the cybersecurity SIEM
Required Qualifications
- 7+ years in identity and access management, with 3+ years hands-on Okta experience building, deploying, and maintaining Okta Workforce Identity Cloud environments
- At least one completed enterprise migration from Entra ID / Azure AD to Okta as architect or technical lead
- Deep expertise in SAML, OIDC, OAuth 2.0, SCIM, and directory integration (AD/Entra ID hybrid scenarios)
- Experience operating and administering Okta in production: policy management, app integrations, lifecycle workflows, troubleshooting
- Experience designing MFA and adaptive access policies at enterprise scale
- Strong documentation skills; able to produce audit-ready artifacts
- Proven ability to work alongside system integrators while retaining architectural ownership
Preferred Qualifications
- Okta Certified Consultant or Okta Certified Architect
- Experience building custom identity automation or governance tooling using Python/SQL, event-driven pipelines, and APIs
- Working knowledge of data platforms (Databricks, Spark, or comparable) for event ingestion and processing
- Experience with ABAC/policy-based authorization models and JIT/ephemeral privileged access patterns in AWS
- SIEM integration experience (log normalization, detection engineering for identity signals)
- Familiarity with IGA platforms, PAM solutions, and enterprise password managers
- Experience in regulated or automotive environments (TISAX, ISO 27001, NIST 800-53)
Engagement Details
- Start date: ASAP; interviews conducted on a rolling basis
- Reports to: Senior Manager, Enterprise Cybersecurity
- Contract-to-hire: strong performers will be considered for a full-time Identity Engineering role at the conclusion of the initial term
Skills
Similar jobs
Accounts Payable Team Lead
Manpower · San Antonio, United States
Just now$27/hrCompliance Coordinator - Leave of Absence
bp · Westlake, United States
1 minute ago£10 - £55/hrRetail Reset Merchandiser
SAS Retail Services · Oneonta, United States
1 minute ago$16/hrTalent Acquisition Coordinator
Software Guidance & Assistance · Sleepy Hollow, United States
1 hour agoSystems Administrator – Microsoft 365 (M365)/Remote
Apetan Consulting · United States
1 hour agoOperations and Registration Support Coordinator
Software Guidance & Assistance · Chicago, United States
1 hour ago