Duties
1. This role will be the technical engine behind our IAM platforms, ensuring our digital ecosystem remains secure and accessible. You will lead the deployment of identity solutions, configure integrations, and act as the bridge between our internal IT teams and our external managed service partners. Duties include but are not limited to:
2. Administer and Implement IAM Platforms: Serve as the primary technical owner for our Okta, Active Directory and Microsoft Entra ID environments, ensuring identity lifecycle management is secure, compliant, and efficient.
3. Implement the Okta Security Roadmap: Execute hands-on deployments of security improvements, such as configuring device posture checking, patching alignment, and building out refined authentication policies.
4. Enhance the End-User Experience: Champion initiatives to reduce user friction, such as optimizing Single Sign-On (SSO), reducing password entry requirements.
5. Manage relationship with External Partners: Act as the primary liaison with our managed service provider for OKTA / Microsoft Entra ID / Active Directory. Clearly define operational boundaries, manage escalations, and coordinate with them on complex project work, integrations, and testing environment alignment.
6. Liaise with internal teams: Liaise with infosec, architecture, infrastructure and support. Acting as the champion for IAM and ensuring that the processes and guidelines are respected.
7. Ensure QA and Testing Integrity: Manage the quality assurance process for IAM rollouts. Maintain testing and production environments to enable robust testing and reliable deployments into production.
8. Develop Technical Documentation: Create and maintain clear, user-friendly technical documentation and ticket-raising guidelines for ONTRC/SharePoint.
9. SSO integrations: Implement and manage SSO integration and SCIM provisioning for SaaS and other applications
PERSON SPECIFICATION Essential Desirable Qualifications/ Education
10. Relevant certifications in Okta (e.g., Okta Certified Professional/Administrator) or equivalent in Microsoft Security/Identity
Experience
11. Strong IAM Foundation: Demonstrable experience managing Identity and Access Management platforms
12. Integration & Troubleshooting: Proven experience integrating third-party applications with identity providers via SAML, OIDC and API integrations.
13. Testing & QA: Experience maintaining and migrating configurations between testing/QA environments and production.
14. Okta Expertise: Hands-on experience administering Okta (highly desirable, though candidates with strong alternative IAM backgrounds and a willingness to learn Okta will be considered).
15. Other IDPs: Experience with other Identity Providers (e.g. Ping Identity, ForgeRock, Auth0, Keycloak, or Google Cloud Identity) would be highly beneficial.
16. Okta Realms: Experience managing and configuring identity Realms will be considered a strong differentiator.
17. Vendor Management: Experience working alongside or directing external managed service providers (MSPs).
Knowledge/Skills/
Abilities
18. Solid understanding of Active Directory and Microsoft Entra ID
19. Solid hands-on understanding of authentication and authorization protocols including SAML, OAuth 2.0, and OpenID Connect (OIDC)
20. You are passionate about finding inefficiencies in the user journey and building elegant, secure solutions to fix them (e.g., reducing password fatigue).
21. You possess strong communication skills and can clearly translate complex IAM changes to end-users through company-wide communications and training.
22. Security-First Mindset: A highly security-conscious approach to access management and system configuration.
Attitude/Other
Requirements
23. You are proactive; you do more than just fix urgent issues; you look ahead at the roadmap to make the platform better and more secure.