← Все вакансии/cultureamp
HybridMelbourne

Identity & Access Management Engineer

C
cultureamp
Формат
Hybrid
О роли

Описание вакансии

About the company

We're big believers in the power of IRL, so for most roles we ask Campers to work from their local Culture Amp office an average of 2 days a week to unlock connection, pace and culture together.

Join us on our mission to make a better world of work.

Culture Amp is the world's leading employee experience platform, revolutionizing how 25 million employees across more than 6,000 companies create a better world of work. Culture Amp empowers companies of all sizes and industries to transform employee engagement, drive performance management, and develop high-performing teams. Powered by people science and the most comprehensive employee dataset in the world, the most innovative companies including Canva, On, Asana, Dolby, McDonalds and Nasdaq depend on Culture Amp every day.

Culture Amp is backed by leading venture capital funds and has offices in the US, UK, Germany and Australia. Culture Amp has been recognized as one of the world's top private cloud companies by Forbes and most innovative companies by Fast Company.

Responsibilities
  • Manage day-to-day identity and access administration in Okta, including provisioning, deprovisioning, MFA resets, application access requests, and authentication, session, and device trust policies.
  • Full lifecycle management of SaaS applications and maintain existing SAML, SCIM, and OIDC configurations and group mappings as Culture Amp's technology environment evolves.
  • Build and own joiner, mover, and leaver workflows end to end, including automated pipelines using Okta Workflows, APIs, and SCIM to connect the HRIS to Okta.
  • Configure, deploy, and continuously improve Okta Identity Governance, including access request workflows and self-service or automated approval paths aligned to access policy.
  • Support audit and compliance activities by automating access certification reporting, gathering system and directory log evidence for SOC 2 and ISO 27001 audits, and reviewing inactive SaaS licences and unapproved OAuth integrations.
  • Contribute to configuration, optimisation and troubleshooting for other ancillary platforms as required, such as Google Workspace, Active Directory / MS Entra, Island & Jamf.
Requirements
  • Hands-on experience administering Okta or a similar identity provider, including SAML, SCIM, OIDC, MFA, lifecycle policies, and authentication, session, and device trust policies.
  • Proven experience onboarding SaaS applications end to end, including SSO setup, SCIM attribute and group mapping, and troubleshooting provisioning issues.
  • Experience with Okta Identity Governance or equivalent access request and identity governance tooling.
  • Experience building identity lifecycle automation pipelines that connect HRIS systems to an identity provider using tools such as Okta Workflows, APIs, or SCIM.
  • Familiarity with SaaS governance practices, including access certification, audit evidence, licence utilisation reviews, and OAuth or shadow IT detection.
  • Familiarity with SaaS platforms, cloud providers, networking fundamentals and device management.
Conditions
  • Equity through our Employee Share Option Program, so you can share in our long-term success
  • Learning programs and coaching to help you thrive and grow
  • Quarterly refresh days, an extended end-of-year break and a monthly allowance to support your wellbeing and lifestyle
  • Inclusive parental leave from day one
  • A MacBook and budget to set up your home workspace, enabling flexibility
  • Five annual social impact days to to give back to causes that matter to you
  • Medical insurance coverage for you and your family (Available for US & UK only)
Стек и навыки

С чем работаем