Sr. IAM Engineer
Franchise World Headquarters, LLC
Shelton, CT
Position Overview
The Sr. IAM Engineer is a hands-on senior technologist responsible for engineering, securing, and evolving Subway's enterprise identity platform. Subway operates a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This role owns complex federation, provisioning, and access-governance problems end to end, treating identity infrastructure as software - version-controlled, tested, deployed through CI/CD pipelines, and observable in production. The Sr. IAM Engineer serves as a senior subject matter expert and co-owner of IAM technical direction, a technical mentor within the IAM team, and a trusted design partner to Cybersecurity, Infrastructure, and HR Technology.
Responsibilities
• Engineer and operate Okta as the enterprise identity broker - Universal Directory, lifecycle management, SSO integrations (SAML 2.0, OIDC, WS-Federation to Microsoft 365), and Okta Workflows; design and troubleshoot federation end to end including assertion and token contents, claim/attribute mapping, signing and encryption, and session behavior across Okta, Entra ID, Active Directory, and downstream SaaS applications.
• Maintain and enhance SCIM 2.0 provisioning at the protocol level - schemas, custom extensions, PATCH semantics, error handling, and reconciliation - between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, AWS IAM Identity Center, and Microsoft 365; own the hybrid attribute-mastering model and drive architectural changes that consolidate source-of-truth authority.
• Apply zero-trust principles and enforce least privilege across the estate: phishing-resistant MFA and passwordless authentication, continuous evaluation of session and device context, privileged access management (PAM) with time-bound and just-in-time elevation, separation of duties, and access-governance controls via Okta Identity Governance including access certification campaigns and self-service access requests.
• Secure identity for LLM and agentic AI systems - govern non-human identities, enforce scoped and short-lived credentials for agent access, apply human-in-the-loop authorization for sensitive actions; apply API security best practices including OAuth 2.0-protected API design, token validation and scoping, and defense against OWASP API Security Top 10 risks including BOLA/IDOR.
• Integrate endpoint security with identity on Windows and macOS: device trust and posture signals in authentication policy, Okta FastPass/Device Trust, Entra device compliance, EDR posture, platform SSO, desktop MFA, and device-bound phishing-resistant credentials.
• Design and implement joiner/mover/leaver automation driven by HRIS events; expand self-service access through the Okta access catalog and AWS IAM Identity Center permission-set-based self-service; build operational automation in PowerShell, Python, and bash; manage identity platform code in Git with peer-reviewed CI/CD pipelines and Terraform for identity-bearing cloud resources.
• Own day-to-day identity platform operations: SSO application setup, IAM incident resolution and root-cause analysis, upgrades, patching, MFA management, and access cleanup; query identity telemetry in CrowdStrike Falcon Next-Gen SIEM and operate identity threat detection and response with CrowdStrike Falcon Identity Protection; support internal and external audits with access evidence.
• Serve as a senior technical authority for IAM architecture and engineering decisions; develop and maintain identity architecture diagrams and configuration baselines; author technical design documents for significant automations and integrations prior to build; mentor IAM engineers and operations analysts; contribute to the strategic IAM roadmap and program maturity assessments.
Qualifications
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field - or equivalent work experience.
• 7+ years in identity and access management, identity engineering, or security engineering with substantial IAM scope, including senior or lead-level ownership of identity platforms.
• Deep, protocol-level expertise in OAuth 2.0 and OIDC (grant types, token lifecycles, PKCE, scopes and claims, bearer-token handling) and SAML 2.0 (assertions, metadata exchange, signing and encryption, SP- and IdP-initiated flows).
• Hands-on expertise with Okta as an enterprise identity broker: Universal Directory, lifecycle management, Okta Workflows, SSO application integration, and SCIM provisioning; Okta Identity Governance experience strongly preferred.
• Demonstrated application of zero-trust architecture and least-privilege access design in a production enterprise environment.
• Advanced Active Directory design and administration in a hybrid IDaaS environment: OU and group strategy, GPO design, and tiered administration models; advanced Microsoft Entra ID policy design including Conditional Access, Identity Protection risk policies, and MFA policy.
• Expert, protocol-level SCIM 2.0 knowledge - core and enterprise schemas, custom schema extensions, PATCH semantics, and provisioning error handling.
• Strong grounding in API security: OAuth 2.0-protected API design, token validation and scoping, and the OWASP API Security Top 10 including BOLA/IDOR vulnerabilities.
• Experience securing or governing identity for LLM and agentic AI systems: non-human identity lifecycle, credential scoping for AI agents, and least-privilege controls on machine-to-machine access.
• Proficiency with CrowdStrike Falcon Identity Protection (ITDR, risk-based policy enforcement) or a comparable ITDR platform; experience querying identity telemetry in an enterprise SIEM.
• Experience integrating endpoint security with identity on Windows and macOS: device posture signals in access policy, platform SSO/desktop MFA, and MDM integration (Jamf, Intune, or equivalent).
• Proficient scripting in PowerShell, Python, and bash; DevOps fluency including Git-based source control and CI/CD pipeline authorship (Azure Pipelines or GitHub Actions).
• 1+ year of experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, SuccessFactors, UKG, or similar).
Preferred Qualifications
• Direct Ceridian Dayforce REST API experience (XRefCode addressing, position management, employment-status events).
• AWS IAM and AWS IAM Identity Center experience, particularly permission-set-based access management.
• Exposure to dedicated IGA tooling (SailPoint, Saviynt, Omada) at design or implementation level.
• Familiarity with NIST SP 800-63 (digital identity assurance) and NIST SP 800-207 (zero trust architecture).
• Background in regulated, franchise, or multi-entity environments where identity governance crosses organizational boundaries.
• Relevant certifications: Okta Certified Professional/Consultant, CISSP, SC-300, or AWS Security Specialty.
What do we offer?
• Insurance Plans (Medical, Life)
• Pension/401K/RSP (country specific)
• Competitive Bonus
• Mobility Allowance
• Tuition Reimbursement
• Company Holidays
• Volunteering time
• And More.....