Tempus

Associate IAM Engineer

Tempus$70K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 1-3 years in IT, Security, or Systems Administration, with 1 year focused on Okta administration.
  • Strong understanding of identity protocols: SAML 2.0 and OpenID Connect (OIDC).
  • Familiarity with automated provisioning using SCIM.
  • Experience in managing Universal Directory for user and group oversight.
  • Basic knowledge of RESTful APIs and interaction with Okta Workflows.

Responsibilities

  • Configure, test, and deploy SSO integrations for new SaaS apps using SAML 2.0 and OIDC.
  • Provide Tier 2/3 operational support for identity-related issues, analyzing logs for deep troubleshooting.
  • Oversee automated user provisioning processes following Joiner/Mover/Leaver protocols.
  • Monitor and configure device assurance policies to secure endpoint access.
  • Assist in user access reviews and entitlement certifications to ensure compliance with security frameworks.

Benefits

  • Full range of medical benefits.
  • Incentive compensation opportunities.
  • Access to restricted stock units.
  • Flexible hybrid work environment.
Full Job Description
As an Associate IAM Engineer, you will be the frontline defender and administrator of our identity perimeter. You will focus on day-to-day identity operations, single sign-on (SSO) integrations, device assurance, and troubleshooting authentication issues. This role is perfect for someone with a strong foundational understanding of identity protocols (SAML, OIDC) who wants to grow their hands-on skills in enterprise automation, identity governance, and cloud identity management using Okta.

Key Responsibilities
  • SSO & App Integration: Configure, test, and deploy standard SAML 2.0 and OIDC/OAuth 2.0 integrations for onboarding new SaaS applications.
  • Operational Support & Troubleshooting: Serve as the Tier 2/3 point of contact for identity-related tickets. Deep-dive into system logs and protocol traces to resolve authentication, MFA, and provisioning failures.
  • Lifecycle Management (LCM): Monitor and maintain automated user provisioning (Joiner/Mover/Leaver processes) across HRIS, Active Directory, and downstream applications. Help triage Okta Workflow errors.
  • Device Assurance & Endpoint Security: Assist in configuring and monitoring Okta Device Assurance policies to ensure only secure, compliant devices can access corporate resources.
  • Identity Governance & Compliance: Support user access reviews and regular entitlement certifications using Okta Identity Governance (OIG) to ensure alignment with SOC2, ISO 27001, and SOX frameworks.


Technical Qualifications
  • Experience: 1-3 years of experience in an IT, Security, or Systems Administration role, with at least 1 year of dedicated hands-on exposure to Okta administration.
  • Protocol Fundamentals: A solid conceptual understanding of the "Identity Trinity":
    • SAML 2.0: Understanding assertions, entity IDs, and ACS URLs.
    • OpenID Connect: Basic understanding of tokens (ID, Access, Refresh), scopes, and authorization flows.
    • SCIM: Familiarity with how automated provisioning works.
  • Directory Services: Comfortable navigating and managing Universal Directory (managing users, groups, and basic OU structures).
  • RESTful APIs: Foundational understanding of REST API concepts (HTTP methods like GET, POST, PUT, DELETE, and status codes) and comfort using OKTA Workflows.
  • Security Mindset: Understanding of basic security principles like Multi-Factor Authentication (MFA), Least Privilege, and Zero Trust.


Soft Skills
  • The "Log Detective": You enjoy digging into event logs and browser developer tools (SAML tracers) to find out exactly why a login failed.
  • Clear Communicator: Ability to guide non-technical employees (or partners in HR) through password resets, MFA setups, or access requests with patience and clarity.
  • Hungry to Learn: The identity space moves fast. You are excited to learn advanced tools like Okta Workflows, Terraform, or API management on the job.


Bonus Points
  • Okta Device Assurance: Prior exposure to configuring Okta Device Assurance policies and a basic understanding of how they interface with MDM tools (e.g., Jamf, Intune) to check device posture.
  • Identity Governance (IGA): Hands-on exposure to Okta Identity Governance (OIG) for managing access requests, approvals, and access certification campaigns.
  • Okta Workflows & Automation: Foundational knowledge or exposure to Okta Workflows (or similar low-code automation platforms) used to orchestrate lifecycle management.
  • Certifications: Okta Certified Professional or Okta Certified Administrator.


#LI-Hybrid

#LI-HR1

CHI - $70,000 - $95,000

The expected salary range above is applicable if the role is performed from Illinois and may vary for other locations (California, Colorado, New York). Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.

About Tempus

Tempus is a technology company that has built an operating system to battle cancer. The company enables physicians to deliver personalized cancer care for patients through its interactive analytical and machine learning platform. Tempus provides genomic sequencing services and analyzes molecular and therapeutic data to empower physicians to make real-time, data-driven decisions. The company also offers research services to enable discovery of new therapeutic targets and clinical services that support clinical trial design and monitoring. Tempus was founded in 2015 by Eric Lefkofsky and has raised over $8 billion in funding to date.
Learn more about Tempus
Size
1,001 employees
Industry
Founded
2015

Similar Jobs

More Jobs at Tempus

More Information Technology Jobs

Find similar Associate IAM Engineer jobs: