IAM Engineer
About the role
The IAM Engineer builds and operates the day-to-day identity and access management capabilities that keep Subway's workforce productive and secure. Subway runs a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This is a hands-on operational and engineering role — owning the daily health of the identity platform while building the automation that steadily retires manual work. The role carries a clear development path toward senior-level identity engineering, including deeper federation and protocol work, access governance, identity threat detection, and security architecture.
Responsibilities
- Operate the identity platform day to day: new SSO application setup, access request fulfillment and escalations, MFA management, group and access cleanup, and account lifecycle corrections; troubleshoot provisioning and authentication issues end to end — SCIM sync failures, attribute mismatches, SSO errors — performing root-cause analysis and documenting resolutions as runbooks.
- Handle complex onboarding, offboarding, and HR-driven downstream changes outside automated lifecycle flows, treating offboarding as security-critical work; manage IAM tickets and service requests in ServiceNow meeting SLA targets; serve as an internal escalation point for complex identity issues from the Technology Support Center and business teams.
- Build Okta Workflows for identity lifecycle events, application provisioning, and remediation tasks; expand the Okta access catalog to convert recurring ticket categories into governed self-service with owner/manager approval; implement joiner/mover/leaver automation driven by HRIS events; contribute to AWS access self-service through AWS IAM Identity Center permission sets.
- Script operational automation in PowerShell or Python — reconciliation, reporting, cleanup, and provisioning tasks; participate in upgrades, patching, and change tickets for identity infrastructure, and the team's shared on-call rotation.
- Operate SCIM 2.0 provisioning between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, Microsoft 365, and AWS IAM Identity Center; support the transition off a legacy custom SCIM connector to broker-native provisioning; configure SSO integrations (SAML 2.0, OIDC) for new applications.
- Apply least-privilege principles in daily access work — right-sized group and role assignments, time-bound privileged access, and cleanup of dormant or over-privileged accounts; support Okta Identity Governance operations including access certification campaigns; administer non-human identities and service accounts for LLM and agentic AI integrations applying least-privilege credential-scoping patterns.
- Collaborate with the broader Cybersecurity engineering teams on shared projects; assist investigations of access anomalies alongside senior engineers and the Detect & Respond team; support internal and external audits with access evidence; author and maintain runbooks, knowledge-base articles, and hand-off documentation for new automations.
Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field — or equivalent work experience.
- 3–5 years in IAM, identity operations, systems administration with significant identity scope, or a related security/infrastructure role.
- Hands-on experience with Okta or a comparable identity provider: user and group administration, application SSO integration, and lifecycle management; Okta strongly preferred.
- Working knowledge of SSO and federation protocols — SAML 2.0, OIDC, and OAuth 2.0 fundamentals — sufficient to configure and troubleshoot integrations.
- Working knowledge of SCIM provisioning concepts and troubleshooting: attribute mapping, sync errors, and reconciliation.
- Active Directory fundamentals (users, groups, OUs, group policy awareness) and familiarity with Microsoft Entra ID and Microsoft 365 administration.
- Scripting proficiency in PowerShell or Python for operational automation (both, plus bash, preferred).
- Experience working with REST APIs: authentication, reading API documentation, and basic troubleshooting of API-driven integrations.
- Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.
- Comfort working with Git-based source control and participating in CI/CD-based change processes.
- Hands-on fluency with LLM and generative AI tools in day-to-day technical work.
Preferred Qualifications
- Working understanding of how AI agents authenticate and are authorized to enterprise systems — non-human identities, credential scoping, and emerging integration patterns such as the Model Context Protocol (MCP) — including experience building, deploying, or securing MCP servers or agentic AI workflows.
- Exposure to identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar) or SIEM platforms.
- Awareness of API security concepts including the OWASP API Security Top 10 and authorization flaws such as BOLA/IDOR.
- Exposure to endpoint management and device trust as they relate to identity (Jamf, Intune) on Windows or macOS.
- Experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, UKG, or similar).
- AWS IAM or AWS IAM Identity Center exposure.
- Okta Certified Professional/Administrator or Microsoft identity certification (SC-300).
Benefits
- Insurance Plans (Medical, Life)
- Pension/401K/RSP (country specific)
- Competitive Bonus
- Mobility Allowance
- Tuition Reimbursement
- Company Holidays
- Volunteering time