- Company Name
- Navan
- Job Title
- Senior Corporate Security Engineer, IAM
- Job Description
-
**Job Title:** Senior Corporate Security Engineer, IAM
**Role Summary:**
Lead the design, implementation, and automation of corporate security controls for a global SaaS environment. Focus on workforce identity and access management, endpoint protection, zero‑trust networking, and data loss prevention to maintain a robust security posture across all devices, applications, and networks.
**Expectations:**
- Minimum 5 years of corporate security engineering experience in a SaaS or comparable enterprise.
- Demonstrated ability to own end‑to‑end IAM solutions, automate workflows, and drive security initiatives at scale.
- Proactive learner who stays current on emerging threats, standards, and technologies.
- Strong collaboration skills with cross‑functional teams (IT, engineering, compliance).
**Key Responsibilities:**
- Design, configure, and manage Okta IAM platform (SSO, MFA, IGA, Access Requests, Workflows, Device Trust).
- Integrate SaaS and custom applications via SAML 2.0, OpenID Connect, and SCIM for automated provisioning.
- Deploy and maintain endpoint security: Microsoft Intune (Windows), Jamf (macOS), Google Admin (ChromeOS).
- Lead CrowdStrike Falcon EDR implementation, tuning, incident investigation, and threat hunting.
- Architect and enforce Zero Trust Network Access (e.g., ZScaler) and conditional access policies.
- Implement DLP controls for PII/PCI in Google Workspace, Salesforce, Box, etc.
- Oversee large‑scale patch management and OS hardening across Windows, macOS, and ChromeOS.
- Automate security posture checks for new infrastructure deployments using IaC tools (Terraform, Ansible, Chef, Puppet).
- Develop custom security scripts/tools and contribute to open‑source solutions.
- Extend security controls to acquired entities and hybrid/multi‑cloud environments (Microsoft Entra ID).
**Required Skills:**
- Expert-level Okta administration and identity governance (certification preferred).
- Strong knowledge of MFA, SSO, access request automation, and Okta Workflows.
- Hands‑on experience with MDM solutions (Intune, Jamf, Google Admin).
- Proficient with CrowdStrike Falcon (Insight, Prevent) and EDR processes.
- Understanding of Zero Trust models and ZScaler or similar solutions.
- Familiarity with Microsoft Entra ID / Azure AD in hybrid settings.
- Experience with DLP technologies and SaaS application security.
- Infrastructure‑as‑code proficiency (Terraform, Ansible, Chef, Puppet).
- Solid scripting/programming (PowerShell, Bash, Python) for automation.
- Excellent problem‑solving, documentation, and communication abilities.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant certifications (strongly preferred): Okta Certified Professional/Administrator, Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), or similar.