Skip to main content
Back to Jobs

Security Engineer II – IAM & SaaS Governance

Design and automate Okta workflows for secure user lifecycle management

As a Security Engineer II focused on IAM and SaaS Governance, you will design and maintain automated joiner-mover-leaver workflows using Okta Workflows, SCIM, or custom API scripts. You will act as the primary engineer for Okta, managing advanced configurations including custom authorization servers, adaptive MFA, and conditional access policies. You will also design, audit, and refine RBAC and ABAC models across enterprise SaaS platforms like...

Why This Role?

Own the Okta environment and drive data governance strategies across core SaaS applications

Key Responsibilities

  • Design and maintain automated joiner-mover-leaver (JML) workflows using Okta Workflows, SCIM, or custom API scripts
  • Manage advanced Okta configurations including custom authorization servers, adaptive MFA, and conditional access policies
  • Standardize and implement SSO integrations using SAML 2.0, OIDC, and OAuth 2.0 for secure token exchange
  • Design, audit, and refine Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models across SaaS platforms
  • Monitor and remediate unauthorized data sharing, public file exposure, and shadow IT API integrations
  • Lead quarterly user access reviews (UARs) and provide evidentiary support for security compliance

Requirements

  • Experience with Okta administration and advanced configurations
  • Knowledge of SCIM, SAML 2.0, OIDC, and OAuth 2.0 protocols
  • Experience designing and maintaining automated provisioning workflows (JML)
  • Understanding of RBAC and ABAC models in enterprise SaaS environments
  • Experience with data exposure monitoring and remediation in SaaS ecosystems
  • Familiarity with conducting user access reviews (UARs) and compliance reporting

Required Skills

oktaiamssorbacdata-governanceSaaS GovernanceABACSCIM

Indonesia Context

Working Hours Overlap:
Flexible — work your own hours
See remote (USD) vs local pay →

Keywords

Identity and Access ManagementOkta administrationSaaS securityuser lifecycle automationleast privilege enforcementdata exposure mitigation
View Original Description from WeWorkRemotely

Original description from WeWorkRemotely

Headquarters: Argentina URL: http://solvd.com Solvd Inc. is a rapidly growing AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence . We work with industry-leading organizations to design, build, and operationalize technology solutions that drive measurable business outcomes. Following the acquisition of Tooploox , a premier AI and product development company, Solvd now offers true end-to-end delivery —from strategic advisory and solution design to custom AI development and enterprise-scale implementation. Our capability centers combine deep technical expertise, proven delivery methodologies, and sector-specific knowledge to address complex business challenges quickly and effectively. We are looking for a Mid-Tier Security Engineer specializing in Identity and Access Management (IAM) and Data Governance to join our Cyber Security team. In this role, you won't just be managing user tickets; you will be the engineer designing, implementing, and securing our identity perimeter and SaaS ecosystem. You will own our Okta environment and drive data governance strategies across our core SaaS applications (e.g., Google Workspace, Microsoft 365, Slack, Salesforce, GitHub). Your goal is to ensure seamless user lifecycle management while aggressively enforcing the principle of least privilege and monitoring data exposure. What you'll do Identity & Access Management (IAM) Engineering Okta Architecture & Admin: Act as the primary engineer for Okta, managing advanced configurations including custom authorization servers, adaptive MFA, and conditional access policies. Lifecycle Automation: Design and maintain automated joiner-mover-leaver (JML) workflows using Okta Workflows, SCIM, or custom API scripts to eliminate manual provisioning errors. Federation & Protocols: Standardize and implement SSO integrations utilizing SAML 2.0, OIDC, and OAuth 2.0, ensuring secure token exchange and scoping. Data Governance & SaaS Security Least Privilege Enforcement: Design, audit, and refine Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models across all enterprise SaaS platforms. Data Exposure Mitigation: Monitor and remediate unauthorized data sharing, public file exposure, and "shadow IT" API integrations within our SaaS ecosystem. Access Reviews & Compliance: Lead quarterly user access reviews (UARs) and provide evidentiary support for security frameworks such as SOC 2 Type II, ISO 27001, and GDPR. SaaS Security Posture Management (SSPM): Leverage SSPM tools or native security centers to continuously audit and harden SaaS application configurations. Monitoring & Incident Response Threat Detection: Analyze Okta System Logs and SaaS audit logs to detect anomalous behavior (e.g., impossible travel, credential stuffing, unauthorized data exfiltration). SIEM Integration: Collaborate with the SOC team to ensure critical IAM and SaaS logs are correctly ingested into our SIEM for real-time alerting. What you bring Experience: 3–5 years of dedicated experience in a Security Engineering, IAM, or Systems Engineering role with a heavy security focus. Okta Mastery: Strong engineering-level knowledge of Okta (Okta Certified Administrator or Certified Consultant preferred). Security Mindset: Proven track record of implementing data governance principles, data loss prevention (DLP), and zero-trust access models. Core Protocols: Deep understanding of networking and identity protocols: TCP/IP, HTTP, SAML, OAuth, OIDC, and SCIM. Scripting: Proficiency in Python, PowerShell, or Bash to interact with REST APIs for custom security tooling and automation. Log Analysis: Experience querying logs (Splunk, ELK, SQL, or cloud-native SIEMs) to investigate identity-related security incidents. When you join Solvd, you'll… Shape real-world AI-driven projects across key industries, working with clients from startup innovation to enterprise transformation.

Salary Context

Similar Engineering roles on LokerDollar pay around $160k/yr (range $1.8k–999.999k/yr, n=514 active listings).

Openness not stated by employer — check the listing

Company
Solvd
Source
WeWorkRemotely
Job Type
full time
Location
Remote · Open worldwide
Category
Seniority
mid
PostedNew
Aug 4, 2026

Share this job

Help a friend find their next remote role.

Frequently asked questions

Is Security Engineer II – IAM & SaaS Governance at Solvd a remote job?
Yes. Security Engineer II – IAM & SaaS Governance at Solvd is a fully remote role open to candidates worldwide.
What type of employment is Security Engineer II – IAM & SaaS Governance at Solvd?
This is a full time position.
How do I apply?
Click the "Apply" button on this page to go to the official application at Solvd.

Explore related

Market data & reports

Salary & skill-demand research built from our own listings data.

From the blog