Location: Hybrid 3 days a week in-office (NYC, Denver, CO or Charlotte, NC)
Position SummaryThe IT Engineer II is a mid-level technical contributor responsible for independently delivering complex IT solutions and leading medium-scale initiatives that improve reliability, security, and user experience. This role serves as a key escalation point for IT Engineer I staff, drives cross-functional projects, and applies advanced technical expertise across identity and access management, endpoint management, SaaS platforms, and cloud-integrated systems.
The IT Engineer II is expected to influence standards, mentor junior engineers, and proactively identify opportunities for automation, access governance, and process improvement. This role serves as a subject matter expert for identity lifecycle management, role-based access controls, and Okta platform administration.
Position Responsibilities: - Serve as a senior escalation point for complex or high-impact end-user and systems issues beyond Helpdesk and IT Engineer I scope
- Lead and deliver medium-to-large IT projects involving identity management, endpoint management, security controls, and SaaS platforms
- Design, implement, and maintain scalable onboarding, offboarding, and identity lifecycle management processes
- Administer and enhance Okta Identity Cloud, including authentication, authorization, application integrations, and access policies
- Design and maintain role-based access control (RBAC) frameworks to ensure appropriate access governance and least-privilege security models
- Develop and maintain Okta Workflows to automate provisioning, deprovisioning, approval processes, and operational tasks
- Configure and support Okta Identity Governance processes, including access requests, certifications, entitlement reviews, and lifecycle governance controls
- Partner with Security, Compliance, Engineering, and Business stakeholders to implement access governance and security best practices
- Evaluate, test, and deploy new software solutions, acting as the technical owner throughout rollout and adoption
- Develop and maintain technical documentation, runbooks, knowledge articles, and access governance procedures
- Identify recurring operational issues and implement systemic and automated solutions to improve efficiency and reduce risk
- Mentor IT Engineer I team members and provide technical guidance across identity and access management disciplines
- Contribute scripts and automation using Bash, PowerShell, Python, or similar languages
- Participate in on-call or off-hours support rotations as required
Required Qualifications: - 4-6+ years of experience in IT engineering, systems administration, identity and access management, or equivalent roles
- Proven ability to independently resolve complex technical issues and deliver end-to-end solutions
- Advanced experience administering and supporting Okta Identity Cloud
- Hands-on experience designing and implementing role-based access control (RBAC) models and access governance processes
- Experience developing and maintaining Okta Workflows for identity automation and lifecycle management
- Experience implementing and administering Okta Identity Governance, including access requests, certifications, entitlement management, and lifecycle governance
- Strong experience managing:
- Identity and access management platforms
- User provisioning and deprovisioning processes
- Endpoint management and device lifecycle operations
- SaaS application deployment and governance
- Demonstrated experience leading medium-scale IT projects involving multiple systems or business stakeholders
- Ability to partner effectively with Security, Engineering, Compliance, and Business teams
- Proficiency administering Office 365 and supporting macOS in a remote-first environment
- Experience deploying, evaluating, and operationalizing new software solutions
- Working knowledge of at least one major cloud platform (AWS, Azure, or Google Cloud preferred)
- Strong scripting and automation skills using Bash, PowerShell, Python, or similar languages
- Experience mentoring junior engineers or providing technical guidance to peers
- Comfortable participating in on-call or off-hours support rotations
Preferred Qualifications: - Okta Certified Professional, Administrator, or Identity Governance certifications
- Experience with SCIM provisioning, SAML, OIDC, OAuth, and modern identity standards
- Experience performing access reviews, audit support, and compliance-focused identity governance activities
- Experience integrating identity platforms with HRIS, MDM, ticketing, and security systems
- Experience supporting healthcare, financial services, or other regulated environments
New York, NY Salary Range
$92,000-$115,000 USD
Denver, CO Salary Range
$84,400-$105,500 USD
Charlotte, NC Salary Range
$76,800-$96,000 USD
All employees are responsible for adherence to the Judi Health Code of Conduct including the reporting of non-compliance. This position description is designed to be flexible, allowing management the opportunity to assign or reassign duties and responsibilities as needed to best meet organizational goals.