Lead IAM Engineer

Braze · Toronto · Engineering

Posted 2026-09-16

Apply for this role →

WHAT YOU'LL DO

We’re seeking a Lead IAM Engineer to own the technical direction and evolution of our enterprise identity and access management strategy. In this senior individual contributor role, you’ll architect, build, and continuously improve a secure, scalable, and automated identity ecosystem centered on Okta, identity lifecycle, access governance, and automation.

You’ll partner across Information Systems, Security, Engineering, Financial, and People Systems to ensure employees, contractors, partners, applications, and services have the right access at the right time while maintaining strong security, governance, reliability, and user experience.

A major focus of this role will be improving onboarding, access-change, and offboarding reliability, reducing manual administration, strengthening access governance, and expanding automation across our identity ecosystem. You’ll help modernize how identity configuration changes are managed through APIs, infrastructure as code, automated workflows, and repeatable engineering practices.

You’ll also help strengthen the broader Identity & Access capability by developing reusable patterns, improving documentation and operational resilience, mentoring other engineers, and reducing key-person dependencies across critical identity services.

If you’re an experienced IAM engineer with deep Okta expertise who enjoys both defining architecture and getting hands-on with automation, integrations, governance, and platform engineering, we’d love to meet you.

Main responsibilities:

Own the technical roadmap and architecture for enterprise Identity & Access Management, with Okta as a core identity platform

Architect and continuously improve Okta capabilities across SSO, authentication, lifecycle automation, Workflows, Identity Governance, and Access Requests

Design reliable onboarding, role-change, and offboarding identity processes for employees, contractors, partners, and other user populations

Build and improve integrations between Okta and systems such as Workday, Google Workspace, Slack, GitHub, Atlassian, MDM, and other enterprise applications

Drive identity automation using Okta Workflows, APIs, scripting, Terraform, and other engineering tools

Modernize how identity configuration changes are made through infrastructure as code, automated validation, peer review, and controlled deployment where appropriate

Lead identity governance initiatives including access reviews, access requests, role-based access, approval workflows, entitlement management, and least-privilege controls

Design and implement authentication, federation, and provisioning solutions using SAML, OIDC, OAuth, SCIM, MFA, and related identity standards

Partner with Security on authentication standards, privileged access, identity risk, and zero-trust initiatives

Support and continuously improve identity-related SOX controls, audit evidence, access reviews, and remediation processes

Design identity solutions for partners, resellers, service accounts, machine identities, and other non-standard access needs

Serve as a senior escalation point for complex identity issues and lead root cause analysis when identity or lifecycle processes fail

Identify recurring administrative or support work and create automation, self-service, runbooks, or delegated workflows to reduce manual intervention

Establish repeatable engineering standards for how identity changes are designed, tested, deployed, and documented

Mentor other engineers and help build broader IAM expertise and independent backup coverage across the team

Evaluate emerging identity capabilities and recommend where they can improve security, reliability, scalability, or user experience

WHO YOU ARE

Deep hands-on expertise with Okta in a complex enterprise environment, including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance

Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization

Experience automating employee onboarding, role changes, and offboarding using an HRIS such as Workday as the authoritative source for employee data

Strong experience with identity governance including access reviews, entitlement management, access requests, role-based access control, and least privilege

Strong scripting and automation skills using Python, PowerShell, or similar languages

Strong API integration experience and the ability to connect identity platforms with broader enterprise systems

Experience with Terraform or another infrastructure-as-code framework

Experience turning manual identity administration into scalable, automated, and auditable processes

Experience supporting IAM controls in a SOX-regulated or similarly controlled environment

Proven ability to lead complex cross-functional IAM initiatives without requiring formal people-management authority

Strong communication skills with the ability to explain identity architecture, technical decisions, and risk to both technical and non-technical audiences

Bonus Points:

Okta certifications such as Okta Certified Administrator, Consultant, Developer, or Identity Governance credentials

Experience managing Okta configuration through Terraform or similar tooling

Experience using Git-based workflows or CI/CD practices to manage identity or infrastructure changes

Familiarity with adjacent enterprise platforms such as Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password

Experience with partner, reseller, B2B, or external identity architectures

Experience managing service accounts, machine identities, workload identities, or other non-human access

Experience automating audit evidence or identity governance controls

For candidates based in Canada, the pay range for this position at the start of employment is expected to be between CA$104,000 and CA$164,000/year, with an expected On Target Earnings (OTE) between CA$115,000 and CA$182,000/year (including bonus or commission). Your exact offer may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition to cash compensation, this role qualifies for a comprehensive Total Rewards package that includes equity grants of restricted stock (RSUs) so that you will own a piece of our company.

#LI-Hybrid

Apply for this role →

← Back to all jobs