Senior IAM and SaaS Engineer
Listed on 2026-09-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Support
Senior IAM & SaaS Engineer (Build the Function)
Radost Solutions is a consulting firm based in Portland, Oregon. We place consultants with clients to lead and deliver critical projects. Learn more ost.us.
About the Client
Our client is a large startup eCommerce and consumer products company in Los Angeles, known for machine-washable home goods. The company has corporate offices and fulfillment and manufacturing facilities, and runs on a modern SaaS stack. Identity and access management has grown with the company rather than been designed. Okta is in place, but provisioning, access reviews, and documentation are limited or missing.
The Role
This is a W2 contract role for someone who wants to build an IAM and SaaS administration function, not maintain one. You will report to the Director of Tech Ops and Enablement and work alongside the Security Team.
This is not a ticket queue. You will audit what exists, fix the highest-risk gaps, and put in place the processes, documentation, and ownership model the company will run on after you. If you have wanted to set up IAM the right way from the start, this role gives you that chance.
What You Will Do
Identity and Access Management
- Audit the current Okta environment and identify risk: orphaned accounts, excess permissions, and unmanaged apps
- Own Okta administration: app integrations, SSO and SCIM, groups, and rules
- Design and run joiner, mover, and leaver processes across the SaaS portfolio
- Establish access review cadence and least-privilege standards with the Security Team
- Document configurations, processes, and policies so they support audits and outlast your contract
SaaS Administration
- Administer Google Workspace and Atlassian (Jira, Confluence, JSM)
- Own application configuration, licensing, and provisioning workflows
- Build integrations and automation across the stack
- Serve as the escalation point for SaaS technical issues
- Set up the application intake, configuration, and decommission process
First 90 Days
- 30 days: Okta and IAM environment audited, SaaS integrations mapped, top risks agreed with the team
- 60 days: Orphaned accounts and provisioning gaps resolved, Okta configuration documented, first access review underway
- 90 days: Highest-risk gaps closed, operating model and review cadence documented, clear ownership for ongoing administration
Required
- 4+ years in IT systems, IAM, or SaaS administration with hands-on ownership
- Hands-on Okta administration: SSO, SCIM, app integrations, groups and rules, and lifecycle management
- Working knowledge of IAM fundamentals: least privilege, joiner/mover/leaver processes, deprovisioning, and access reviews
- Google Workspace administration:
Admin Console, groups, provisioning, and security settings - Atlassian administration:
Jira, Confluence, and JSM - Documentation habits that hold up to audit
- Experience working independently where no playbook exists
Preferred
- Led an IAM cleanup, audit, or access governance effort
- Workflow automation tools such as Zapier or Workato
- DTC, eCommerce, or high-growth company experience
- Data classification, vendor risk, or security fundamentals
- Interest in AI tools and AI governance
Location and Travel
- Remote, with a preference for candidates in the Los Angeles area
- Regular travel to the client's Los Angeles offices is required
- Candidates must reside in the United States
- W2 contract, 7 months, with potential to convert to a full-time role
- Not open to C2C or third-party arrangements
- Pay: $55 to $75/hour, based on experience and location
- Benefits: 401(k), health insurance stipend, paid time off, paid holidays, and professional development
Our Hiring Process
To protect candidates and our client, we use the following steps:
- All interviews are conducted on camera
- Offers are contingent on identity verification, I-9 completion, and a background check
- Equipment ships only to a verified US address
- Radost will only contact you from an email address. We will never ask for payment or banking information before an offer.
Radost Solutions is an equal opportunity employer. We do not discriminate based on any protected characteristic.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).