Job Description
Job Description
ComResource is looking for an IAM Engineer - Okta.
Responsibilities:
Discovery & Assessment
- Review existing manual user access review documentation, spreadsheets, timelines, and workflows currently used for AD groups.
- Identify and document the definitive owners, stakeholders, and reviewers for each AD group within scope.
- Verify the current sync configuration between Active Directory and Okta to ensure AD groups and memberships are importing accurately and in a timely manner.
Strategy & Governance Design
- Translate existing manual business rules into Okta Access Requests and Access Certification campaign logic, including review frequency, multi-stage approvals, and escalation paths.
- Establish automated behaviors required when access is denied, such as immediate automatic removal from AD groups.
- Draft exception workflows for handling orphaned groups, unresponsive reviewers, or emergency access extensions during live campaigns.
Configuration & Implementation
- Configure Okta Identity Governance (OIG) Access Certifications for targeted AD groups, establishing specific resource-based or user-based review scopes.
Testing & Validation
- Launch dry-run access certification campaigns with a subset of non-critical AD groups to test reviewer user experience and notification layouts.
- Verify that when a reviewer selects "Revoke Access" in Okta, the user is automatically removed from the corresponding on-premises Active Directory group.
- Ensure Okta system logs and governance reports accurately capture reviewer identity, action, timestamp, and justification for compliance purposes.
Training & Documentation
- Develop visual how-to documentation and quick-reference guides for business managers and group owners conducting reviews in Okta.
- Provide knowledge transfer sessions for internal IT and Identity teams on how to manage, launch, troubleshoot, and modify Okta governance campaigns.
- Deliver a final configuration blueprint detailing mapped workflows suitable for presentation to internal or external auditors to demonstrate compliance with user access review controls.
Essentials:
- Hands-on experience with Okta Identity Governance (OIG), including Access Certifications and Access Requests.
- Experience configuring and administering Okta in an enterprise environment.
- Strong understanding of Active Directory groups, memberships, and directory synchronization with Okta.
- Experience supporting change management with IT and compliance teams.
- Ability to translate manual business rules and controls into automated governance workflows.
- Strong written and verbal communication skills with the ability to create clear documentation for both technical and non-technical audiences.
Req ID: CG70217961
