The Senior IAM Developer is responsible for engineering, enhancing, and integrating IAM and Customer Identity and Access Management (CIAM) capabilities to enable secure, resilient, and scalable access to applications and digital services. This role delivers secure-by-design IAM, CIAM, and Conditional Access solutions across cloud and on-prem environments, with a strong emphasis on Zero Trust enforcement, customer identity journeys, automation, identity lifecycle management, and access governance. The role works closely with IAM product owners, architects, cybersecurity, application teams, and strategic vendors and is engineering-led, with no primary responsibility for day-to-day operational support.
The core responsibilities for the job include the following:
IAM and CIAM Engineering and Solution Delivery:
- Design, develop, and enhance Workforce IAM and CIAM solutions across Okta, Okta Auth0 Okta Access Gateway, Microsoft Entra ID (Azure AD), and Conditional Access.
- Engineer authentication solutions supporting Zero Trust and CIAM use cases, including MFA, passwordless authentication, adaptive and risk-based access, privileged access, and customer identity flows.
- Design and implement secure authentication, authorization, and federation patterns using SAML 2.0 OAuth 2.0 OpenID Connect, and SCIM.
- Deliver identity lifecycle and access models for workforce users, partners, and customers, including CIAM sign-up, sign-in, profile management, and consent flows.
CIAM (Customer Identity) Enablement - Okta Auth0
- Design and implement CIAM architectures using Okta Auth0 for customer-facing and digital applications.
- Engineer secure and scalable customer authentication flows, including social identity providers, progressive profiling, step-up authentication, and fraud-aware access controls.
- Define CIAM patterns that balance security, regulatory compliance, and customer experience.
- Partner with digital application teams to integrate Auth0 into customer platforms and APIs.
- Ensure CIAM implementations align with privacy, data protection, and regulatory requirements (e. g., consent, minimal data collection).
Conditional Access and Zero Trust Enablement:
- Design, implement, and continuously improve conditional access policies aligned with security standards and Zero Trust architecture.
- Define scalable conditional Access patterns for workforce users, privileged roles, devices, applications, and workload identities.
- Engineer policy automation, validation, and safe deployment mechanisms to reduce risk and configuration drift.
- Partner with security and architecture teams to evolve baseline protections and the Zero Trust strategy.
Platform Engineering and Automation:
- Develop automation using APIs, SDKs, scripting, and configuration as code to improve IAM and CIAM platform reliability and efficiency.
- Support CI/CD pipelines and controlled promotion of IAM, CIAM, and Conditional Access changes across environments.
- Contribute to platform upgrades, new feature adoption, and continuous reduction of technical debt across Okta, Auth0 and Entra ID.
- Proactively implement engineering improvements that enhance security, resilience, and scalability.
Application and Cloud Integration:
- Partner with application teams to design and deliver secure IAM, CIAM, and Conditional Access integrations for SaaS, cloud, custom, API-based, and legacy applications.
- Lead IAM and CIAM technical assessments during application onboarding, migrations, and cloud transformations.
- Validate IAM and CIAM designs to ensure production readiness, security compliance, and user experience.
- Resolve complex federation and access challenges across hybrid and multi-tenant environments.
Security, Risk, and Architecture Alignment:
- Ensure all IAM, CIAM, and Conditional Access solutions comply with
- security policies, architectural standards, and regulatory requirements.
- Implement controls supporting least privilege, strong authentication, continuous access evaluation, and defense in depth.
- Provide technical input to risk assessments, audits, security reviews, and regulatory engagements.
- Contribute to threat modeling and design decisions related to identity compromise, customer fraud, and access abuse scenarios.
Technical Leadership and Collaboration:
- Act as a senior technical authority and mentor for IAM engineers and developers.
- Collaborate with IAM architects and product owners to influence platform roadmaps, CIAM strategy, Conditional Access standards, and solution direction.
- Work with strategic vendors and partners (e. g., Okta/Auth0 Microsoft) to support advanced integrations and feature adoption.
- Provide engineering-level guidance during complex IAM and CIAM incidents and escalations.
Documentation and Continuous Improvement:
- Maintain technical designs, integration standards, CIAM and Conditional Access guidelines, and engineering runbooks.
- Contribute to post-implementation and post-incident reviews from a solution and architecture perspective.
- Continuously evaluate IAM and CIAM technologies to improve security posture, service quality, and developer experience.
Additional Information:
- Operates in a global IAM and CIAM environment with cross-regional collaboration.
- Occasional participation in after-hours releases for IAM, CIAM, or conditional access may be required.
Requirements:
- Bachelor's degree in computer science, information technology, cybersecurity, or equivalent professional experience.
Technical Skills:
- Extensive experience (typically 8+ years) in IAM and/or CIAM engineering within a large enterprise environment.
- Strong hands-on experience with Okta Workforce IAM and Okta Auth0 (CIAM) and/or Microsoft Entra ID Conditional Access.
- Deep understanding of Zero Trust architecture, CIAM patterns, authentication, authorization, and identity lifecycle management.
- Proven experience with SAML, OAuth, OpenID Connect, and SCIM.
- Experience developing integrations using APIs, scripting, or programming languages (Java, . NET, Python, PowerShell, JavaScript).
- Experience supporting cloud-first, SaaS-, API-driven, and hybrid identity architectures.
Soft Skills:
- Strong analytical mindset with a security-first, customer-aware engineering approach.
- Ability to clearly articulate complex IAM, CIAM, and conditional access designs to diverse stakeholders.
- Comfortable operating in a global, regulated, and risk-focused environment.
- Strong collaboration, influencing, and stakeholder management skills.
- High standards of ownership, accountability, and engineering excellence.

