×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Sr. IAM Engineer

Job in Shelton, Fairfield County, Connecticut, 06484, USA
Listing for: Pho Prime, LLC
Full Time position
Listed on 2026-08-09
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 120000 - 170000 USD Yearly USD 120000.00 170000.00 YEAR
Job Description & How to Apply Below

At Subway, we are not standing still. We are building.

This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.

You will not just do the work. You will shape it.

We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.

If you bring energy, accountability and a bias for action, you will fit right in.

We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.

This is your chance to be part of what’s next.

Position Overview

The Sr. IAM Engineer is a hands-on senior technologist responsible for engineering, securing, and evolving Subway's enterprise identity platform. Subway operates a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra , Microsoft 365, Service Now, AWS IAM Identity Center, and a broad SaaS portfolio.

This role owns complex federation, provisioning, and access-governance problems end to end, treating identity infrastructure as software — version-controlled, tested, deployed through CI/CD pipelines, and observable in production. The Sr. IAM Engineer serves as a senior subject matter expert and co-owner of IAM technical direction, a technical mentor within the IAM team, and a trusted design partner to Cybersecurity, Infrastructure, and HR Technology.

Responsibilities
  • Engineer and operate Okta as the enterprise identity broker — Universal Directory, lifecycle management, SSO integrations (SAML 2.0, OIDC, WS-Federation to Microsoft 365), and Okta Workflows; design and troubleshoot federation end to end including assertion and token contents, claim/attribute mapping, signing and encryption, and session behavior across Okta, Entra , Active Directory, and downstream SaaS applications.
  • Maintain and enhance SCIM 2.0 provisioning at the protocol level — schemas, custom extensions, PATCH semantics, error handling, and reconciliation — between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra , Service Now, Jamf, AWS IAM Identity Center, and Microsoft 365; own the hybrid attribute-mastering model and drive architectural changes that consolidate source-of-truth authority.
  • Apply zero-trust principles and enforce least privilege across the estate: phishing-resistant MFA and passwordless authentication, continuous evaluation of session and device context, privileged access management (PAM) with time-bound and just-in-time elevation, separation of duties, and access-governance controls via Okta Identity Governance including access certification campaigns and self-service access requests.
  • Secure identity for LLM and agentic AI systems — govern non-human identities, enforce scoped and short-lived credentials for agent access, apply human-in-the-loop authorization for sensitive actions; apply API security best practices including OAuth 2.0-protected API design, token validation and scoping, and defense against OWASP API Security Top 10 risks including BOLA/IDOR.
  • Integrate endpoint security with identity on Windows and macOS: device trust and posture signals in authentication policy, Okta Fast Pass/Device Trust, Entra device compliance, EDR posture, platform SSO, desktop MFA, and device-bound phishing-resistant credentials.
  • Design and implement joiner/mover/leaver automation driven by HRIS events; expand self-service access through the Okta access catalog and AWS IAM Identity Center permission-set-based self-service; build operational automation in Power Shell, Python, and bash; manage identity platform code in Git with peer-reviewed CI/CD pipelines and Terraform for identity-bearing cloud resources.
  • Own day-to-day identity platform operations: SSO application setup, IAM incident resolution and root-cause…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary