Senior Identity and Access Management Engineer

State of Washington$113K — $148K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in Customer Identity and Access Management (CIAM) with focus on PingOne Identity Cloud.
  • Hands-on experience with Okta for SSO, MFA, and lifecycle management.
  • Proven experience in IAM migration projects and authentication protocols (OAuth, OIDC, SAML).
  • Familiarity integrating web and API applications with IAM platforms using token-based authentication.
  • Background in Agile/Scrum environments collaborating with product and development teams.

Responsibilities

  • Design and implement IAM solutions using PingOne IdentityCloud; support transition to Okta.
  • Automate user lifecycle processes including provisioning and role-based access.
  • Develop custom workflows and APIs for IAM system integration across applications.
  • Implement adaptive authentication and enhance security via SSO and MFA.
  • Troubleshoot authentication flows and ensure compliance with data protection regulations.

Benefits

  • Flexible remote and in-office work schedule.
  • Core business hours from 8:00 a.m. to 5:00 p.m., Monday through Friday.
  • Opportunities for professional development and training.
  • Participation in a supportive collaborative team environment.
Full Job Description
Salary : $113,668.00 - $148,263.00 Annually
Location : Thurston County - Olympia, WA
Job Type: Full Time - Permanent
Job Number: 1467
Department: Health Benefits Exchange
Opening Date: 06/03/2026

Description
SUMMARY
The Senior Identity and Access Management Engineer position focuses on designing, developing, and supporting customer IAM solutions using PingOne IdentityCloud to provide secure and seamless digital experiences to customers. Key responsibilities include managing user lifecycle automation, implementing access controls, integrating applications with IAM systems through industry-standard protocols, and enhancing security via Single Sign-On (SSO), Multi-Factor Authentication (MFA), and risk-based policies. The position also involves troubleshooting authentication flows, ensuring regulatory compliance, and collaborating with Information Technology (IT), security, and product teams to deliver robust IAM integrations across cloud platforms.
Duties
• Design, develop, implement, and support customer IAM solutions utilizing PingOne IdentityCloud, and support transition to Okta where applicable.
• Build and maintain automated processes for user lifecycle management, including provisioning, deprovisioning, and role- or attribute-based access controls.
• Develop and maintain custom connectors, workflows, APIs, and scripts to integrate IAM systems with enterprise applications.
• Integrate web, mobile, and API-based cloud applications with IAM platforms using protocols such as SAML, OAuth, and OIDC.
• Implement SSO, adaptive authentication, MFA, and risk-based policies to enhance security and user experience.
• Configure and troubleshoot federation and OAuth/OIDC flows, and ensure secure session handling across systems.
• Implement and manage workflows for customer registration, login, account recovery, and profile management.
• Support migration of CIAM capabilities from PingOne Identity Cloud to Okta, including configuration, testing, validation, troubleshooting, deployment.
• Assist with migration planning, architecture design, and implementation of access and identity flows in Okta.
• Ensure IAM architecture and solutions adhere to security, privacy, regulatory, and consumer data protection requirements.
• Work closely with IT, Security, and Delivery teams to ensure secure IAM solutions across all cloud systems.
• Collaborate with delivery teams, product owners, and scrum masters to integrate IAM features into application releases.
• Participate in sprint planning, backlog refinement, and technical design discussions to ensure identity requirements are considered early in development.
• Support IAM changes during sprint release cycles, ensuring thorough testing and validation.
• Coordinate IAM-related changes with DevOps and change management teams to minimize disruptions during deployments.
• Provide guidance to IT and Delivery teams on secure authentication patterns, token usage, and best practices for IAM.
• Ensure IAM solutions align with enterprise security policies, identify gaps, and provide progress updates.
• Monitor IAM environments for authentication issues, anomalies, and performance bottlenecks.
• Document IAM architectures, integrations, and operational procedures.
• Execute and manage access recertification campaigns, ensuring timely completion and accurate audit reporting.
• Implement and maintain least-privilege and segregation-of-duties controls across IAM systems.
• Leverage microservices and API architectures to design, build, and manage IAM functionalities, enabling secure and scalable authentication, authorization, and service access controls.
• Serve as the primary technical contact with the Ping Identity support team to address environment-related issues, tenant performance concerns, incidents, and troubleshooting.
• Track vendor releases, platform updates, and new capabilities for adoption within the organization.
• Coordinate maintenance windows, patch updates, and feature releases with the Change Advisory Board, Delivery Team, and Ping Identity vendor.
• Validate vendor fixes in lower environments before production rollout.
• Monitor authentication health, login trends, and token issuance metrics.
• Perform root cause analysis for authentication and authorization incidents.
• Assist in investigations of security incidents involving identity compromise.
• Maintain detailed logging and audit trails aligned with regulatory requirements.
• Monitor IAM logs and integrate events with SIEM platforms to support security monitoring and incident response.
• Support audit activities by providing technical guidance and documentation, and act as a liaison for internal and external audit reviews as needed.
• Develop automation scripts (e.g., Python, Java, or similar) to streamline IAM processes.
• Leverage PingOne REST APIs for configuration management tasks.
• Support CI/CD deployment of IAM configurations.
• Support infrastructure-as-code initiatives where applicable.
• Assist the IAM Lead and Information Security Manager (ISM) in reviewing IAM capabilities and defining a roadmap for IAM enhancements.
• Support the development and implementation of information security awareness and training initiatives.
• Stay current on industry trends, emerging threats, and relevant technologies, and communicate key insights to the IAM Lead and ISM.
• Provide regular briefings to the IAM Lead and ISM, escalating issues and blockers as necessary.
• Perform other duties as assigned within the scope of IAM.

Qualifications

Required:
• Minimum of seven (7) years of experience in Customer Identity and Access Management (CIAM) implementation and support, with a minimum of three (3) years within that experience focused on implementing and supporting CIAM solutions using PingOne Identity Cloud.
• Hands-on experience with Okta including SSO, MFA, federation, application integrations, and identity lifecycle management.
• Experience with IAM migration projects.
• Hands-on experience implementing authentication and authorization protocols including OAuth, OIDC, and SAML.
• Experience integrating web, mobile, and API applications with IAM platforms using token-based authentication mechanisms.
• Experience in implementing SSO, MFA, federation, and identity lifecycle management.
• Familiarity with customer registration, authentication journeys, and identity flows in CIAM platforms.
• Hands-on software development or scripting experience using languages such as Java, JavaScript, Python, or similar.
• Demonstrated knowledge of IAM best practices, including risk-based authentication and consumer data protection strategies.
• Experience supporting IRS/CMS or other relevant audits in the context of IAM.
• Experience working in Agile/Scrum environments, collaborating with product owners, scrum masters, and development teams during sprint cycles.
• Familiarity with DevOps processes, change management, and release coordination to support secure and stable deployments.
• Understanding of secure authentication patterns, token lifecycle management, and identity integration best practices.
• Experience working with enterprise security policies, identity governance practices, and compliance requirements.
• Demonstrated communication and collaboration skills with the ability to provide technical guidance to IT, delivery teams, and developers on secure IAM integration.
• Minimum of seven (7) years of experience in IAM, including work with Customer Identity and Access Management (CIAM) platforms.
• Experience working with REST API integrations for IAM services.
• Knowledge in integrating IAM systems with API gateways and backend services to ensure secure access control.
• Experience managing IAM platform configuration changes and automated deployments across development, staging, and production environments.
• Experience integrating IAM platforms with SIEM or security monitoring tools for authentication and identity event monitoring.
Desired:
• Experienced in creating comprehensive reports and dashboards to communicate findings, track remediation progress, and provide visibility to management and relevant teams.
• Experience participating in sprint planning, backlog refinement, and technical design discussions to integrate identity and authentication requirements into application development.
• Motivated self-starter with initiative to take independent action and accept responsibility for your actions.
• Excellent understanding of emerging threats in the IAM landscape.
• Hands-on experience with CI/CD pipelines for IAM configuration deployments, including tools such as Jenkins.
• Experience using source control and deployment workflows with GitHub for managing IAM configuration scripts or integration code.
• Familiarity with DevOps practices and infrastructure automation supporting IAM or CIAM platform changes.
• Experience troubleshooting authentication failures, federation issues, token validation issues, and identity integrations.
• Demonstrates strong interpersonal and collaboration skills, effectively partnering with internal management, staff, and cross-functional teams as well as external partners and vendors.
• Ability to prioritize identified gaps and collaborate with cross-functional teams to ensure timely remediation and effective risk mitigation.
• Demonstrates a proactive approach by consistently identifying potential blockers and communicating them early, while maintaining a solutions-focused mindset to facilitate continued progress.
• Creative and proactive problem solver; must possess the ability to make independent decisions, set work priorities, and address issues promptly.
• Experience in developing, reviewing, and updating security standards, procedures, awareness, and training.
• Demonstrated knowledge of secure software development lifecycle (SDLC) and secure architecture design principles.

Supplemental Information

APPLICATION INSTRUCTIONS
This position will be open until we find a suitable number of candidates to review. If interested, please submit an application (CLICK HERE) as soon as possible. The Exchange reserves the right to close the recruitment at any time.

SALARY INFORMATION
Full Salary Range: $98,842.00 to $148,263.00 annually, with midpoint at $123,552.00.

Hiring Range: $ 113,668.00 and $123,552.00 annually. This is an estimate of where a qualified candidate can expect to receive an offer.

The actual salary offer will consider candidate experience, skills, qualifications, internal equity, and the market. Our compensation policy reserves the salary range above the midpoint for employees who are meeting and exceeding expectations and for growth and development, up to the maximum.

BENEFITS
Take a peek at our

WORKING CONDITIONS
Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday. There are times where irregular hours will be required. The preferred duty station is our Olympia, Washington headquarters. The nature of this role relies heavily on remote and in-person collaboration. While a hybrid remote and on-site schedule may be considered, the position will require flexibility to allow for in-office availability as business needs dictate. Travel requirements will be limited, however there may be occasions where an employee is required to travel and work irregular hours to attend meetings or trainings. Duties of this position require the use of standard office furniture and equipment, including setup for remote work. The employee is responsible for providing and maintaining a safe, ergonomic, and secure workspace at their remote location.

The working conditions and physical demands are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

SPECIAL REQUIREMENTS
A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained by the position. The result of this background screen must meet the Exchanges eligibility standards.

About State of Washington

State of Washington Careers

Joining the State of Washington's diverse team offers more than just a job; it opens opportunities to build and grow a career in an array of fields. State of Washington is renowned for its commitment to excellence and innovation in public service.

Explore Job Opportunities

State of Washington offers a variety of job opportunities that cater to a range of skills and interests. From environmental science to public health, the state provides roles that contribute significantly to the community and the environment. Each position at the State of Washington supports a culture of leadership and professional growth.

Experience Professional Growth

Career advancement is a cornerstone of employment with the State of Washington. With programs designed to foster leadership skills and professional development, employees are encouraged to ascend through the ranks. The State of Washington is committed to providing career pathways that help individuals achieve their professional goals.

Engage in Diversity Training and Innovation

The State of Washington places a high priority on creating an inclusive work environment. Diversity training is integral, ensuring all team members understand and appreciate the value of differences. Innovation is at the heart of the State of Washington, where new ideas and perspectives lead to effective solutions and services.

Benefits and Culture

Employees at the State of Washington enjoy a comprehensive benefits package that supports both their professional and personal lives. Health benefits, retirement plans, and wellness programs are just the beginning. The culture here is built on mutual respect, collaboration, and a commitment to excellence.

Internship Programs

For those starting their career journey, internship opportunities provide a gateway to full-time employment and a chance to develop valuable industry skills. Internships at the State of Washington are designed to give hands-on experience and insights into the workings of state government.

Join the Team

State of Washington is continuously hiring new talent. Interested candidates are encouraged to review open positions that match their skills and career interests. The hiring process is thorough, ensuring that both the candidate and the position are a perfect match.

Prepare for Your Interview

To help candidates succeed, State of Washington offers resources on how to effectively prepare for interviews. Tips on crafting a compelling resume and mastering interview techniques are available to ensure applicants present their best selves.

Networking and Career Events

Regular networking events and career fairs provide opportunities to connect with leaders in various fields and explore potential job openings. These events are ideal for sharing professional experiences, meeting potential mentors, and learning more about the State of Washington's mission and values.

Stay Connected

Keep up to date with the latest news, job alerts, and career tips from the State of Washington by subscribing to the careers newsletter. Discover the exciting and rewarding opportunities that await at the State of Washington.

SEARCH STATE OF WASHINGTON JOBS

READ CAREERS BLOG

JOB ALERT EMAILS

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the rewarding career opportunities at the State of Washington today.
Learn more about State of Washington

Similar Jobs

More Jobs at State of Washington

More Information Technology Jobs

Find similar Senior Identity and Access Management Engineer jobs: