Security Engineer II – IAM & SaaS Governance
Design and automate Okta workflows for secure user lifecycle management
As a Security Engineer II focused on IAM and SaaS Governance, you will design and maintain automated joiner-mover-leaver workflows using Okta Workflows, SCIM, or custom API scripts. You will act as the primary engineer for Okta, managing advanced configurations including custom authorization servers, adaptive MFA, and conditional access policies. You will also design, audit, and refine RBAC and ABAC models across enterprise SaaS platforms like...
Why This Role?
Own the Okta environment and drive data governance strategies across core SaaS applications
Key Responsibilities
- Design and maintain automated joiner-mover-leaver (JML) workflows using Okta Workflows, SCIM, or custom API scripts
- Manage advanced Okta configurations including custom authorization servers, adaptive MFA, and conditional access policies
- Standardize and implement SSO integrations using SAML 2.0, OIDC, and OAuth 2.0 for secure token exchange
- Design, audit, and refine Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models across SaaS platforms
- Monitor and remediate unauthorized data sharing, public file exposure, and shadow IT API integrations
- Lead quarterly user access reviews (UARs) and provide evidentiary support for security compliance
Requirements
- Experience with Okta administration and advanced configurations
- Knowledge of SCIM, SAML 2.0, OIDC, and OAuth 2.0 protocols
- Experience designing and maintaining automated provisioning workflows (JML)
- Understanding of RBAC and ABAC models in enterprise SaaS environments
- Experience with data exposure monitoring and remediation in SaaS ecosystems
- Familiarity with conducting user access reviews (UARs) and compliance reporting
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
Keywords
View Original Description from WeWorkRemotely
Original description from WeWorkRemotely
Headquarters: Argentina URL: http://solvd.com Solvd Inc. is a rapidly growing AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence . We work with industry-leading organizations to design, build, and operationalize technology solutions that drive measurable business outcomes. Following the acquisition of Tooploox , a premier AI and product development company, Solvd now offers true end-to-end delivery —from strategic advisory and solution design to custom AI development and enterprise-scale implementation. Our capability centers combine deep technical expertise, proven delivery methodologies, and sector-specific knowledge to address complex business challenges quickly and effectively. We are looking for a Mid-Tier Security Engineer specializing in Identity and Access Management (IAM) and Data Governance to join our Cyber Security team. In this role, you won't just be managing user tickets; you will be the engineer designing, implementing, and securing our identity perimeter and SaaS ecosystem. You will own our Okta environment and drive data governance strategies across our core SaaS applications (e.g., Google Workspace, Microsoft 365, Slack, Salesforce, GitHub). Your goal is to ensure seamless user lifecycle management while aggressively enforcing the principle of least privilege and monitoring data exposure. What you'll do Identity & Access Management (IAM) Engineering Okta Architecture & Admin: Act as the primary engineer for Okta, managing advanced configurations including custom authorization servers, adaptive MFA, and conditional access policies. Lifecycle Automation: Design and maintain automated joiner-mover-leaver (JML) workflows using Okta Workflows, SCIM, or custom API scripts to eliminate manual provisioning errors. Federation & Protocols: Standardize and implement SSO integrations utilizing SAML 2.0, OIDC, and OAuth 2.0, ensuring secure token exchange and scoping. Data Governance & SaaS Security Least Privilege Enforcement: Design, audit, and refine Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models across all enterprise SaaS platforms. Data Exposure Mitigation: Monitor and remediate unauthorized data sharing, public file exposure, and "shadow IT" API integrations within our SaaS ecosystem. Access Reviews & Compliance: Lead quarterly user access reviews (UARs) and provide evidentiary support for security frameworks such as SOC 2 Type II, ISO 27001, and GDPR. SaaS Security Posture Management (SSPM): Leverage SSPM tools or native security centers to continuously audit and harden SaaS application configurations. Monitoring & Incident Response Threat Detection: Analyze Okta System Logs and SaaS audit logs to detect anomalous behavior (e.g., impossible travel, credential stuffing, unauthorized data exfiltration). SIEM Integration: Collaborate with the SOC team to ensure critical IAM and SaaS logs are correctly ingested into our SIEM for real-time alerting. What you bring Experience: 3–5 years of dedicated experience in a Security Engineering, IAM, or Systems Engineering role with a heavy security focus. Okta Mastery: Strong engineering-level knowledge of Okta (Okta Certified Administrator or Certified Consultant preferred). Security Mindset: Proven track record of implementing data governance principles, data loss prevention (DLP), and zero-trust access models. Core Protocols: Deep understanding of networking and identity protocols: TCP/IP, HTTP, SAML, OAuth, OIDC, and SCIM. Scripting: Proficiency in Python, PowerShell, or Bash to interact with REST APIs for custom security tooling and automation. Log Analysis: Experience querying logs (Splunk, ELK, SQL, or cloud-native SIEMs) to investigate identity-related security incidents. When you join Solvd, you'll… Shape real-world AI-driven projects across key industries, working with clients from startup innovation to enterprise transformation.
Salary Context
Similar Engineering roles on LokerDollar pay around $160k/yr (range $1.8k–999.999k/yr, n=514 active listings).
Openness not stated by employer — check the listing
Frequently asked questions
- Is Security Engineer II – IAM & SaaS Governance at Solvd a remote job?
- Yes. Security Engineer II – IAM & SaaS Governance at Solvd is a fully remote role open to candidates worldwide.
- What type of employment is Security Engineer II – IAM & SaaS Governance at Solvd?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at Solvd.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- Remote AI Hiring: Skill vs Degree? AI mengubah cara perusahaan merekrut IT. Cari tahu skill yang dicari, plus lowongan remote USD terbaru di 2026.
- Low GPA to Microsoft? Your Remote USD JobA complete guide for professionals with lower GPAs aiming for USD-paying remote jobs at top tech companies like Microsoft.
- Data Product Manager vs. DevOps vs. AIConfused about remote tech careers? Compare Data PM, DevOps Engineer, and Staff AI Engineer salaries, skills, and prospects for August 2026.