← Back to results

Lead IAM Engineer

Lead the technical direction of Braze's identity and access management strategy with a focus on automation and security.

Location
New York City
Compensation
$101k–$158k/yr
Level
lead
Type
full time · Hybrid

Posted by employer 1 week ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at Braze → Save job Scanned from braze.com

What you'll build

  • Own the technical roadmap for Identity & Access Management
  • Architect Okta capabilities across SSO and authentication
  • Build integrations between Okta and enterprise applications
  • Drive identity automation using Okta Workflows and APIs
  • Lead identity governance initiatives

Must have

  • Deep hands-on expertise with Okta
  • Advanced understanding of SAML, OIDC, OAuth 2.0
  • Strong experience with identity governance
  • Strong scripting and automation skills using Python or PowerShell
  • Strong API integration experience

Nice to have

  • Okta certifications
  • Experience managing Okta configuration through Terraform
  • Experience using Git-based workflows
  • Familiarity with enterprise platforms like Google Workspace
  • Experience managing service accounts or machine identities

Not disclosed in this posting: years of experience, visa sponsorship.

Benefits

401k Match Unlimited PTO Equity/Stock Options Health Insurance Parental Leave

Joblaze summary

The Lead IAM Engineer at Braze is responsible for shaping and enhancing the company's identity and access management strategy, focusing on building a secure and automated identity ecosystem centered around Okta. This role requires deep expertise in identity governance, automation, and API integrations, along with strong scripting skills to streamline processes. Ideal candidates are seasoned IAM professionals who can lead complex initiatives and mentor others, contributing to a collaborative team environment. Braze emphasizes a culture of teamwork and high standards, making it suitable for those who thrive in dynamic settings.

Joblaze insights

  • Listed yesterday — first seen on Joblaze September 17, 2026. Last confirmed on Braze's careers page September 17, 2026.
  • This exact title is also open at 3 other locations at Braze: Toronto, Austin, Chicago.
  • Salary band is below the typical range for Security roles (median ~$169,000).
  • Starts above 15% of 13 comparable lead security roles in United States that list Python we track (median $200,000 across 8 companies). See Python salary trends
  • Python appears in 42.2% of 45 comparable lead security roles in United States; SCIM appears in 4.4% of 45 comparable lead security roles in United States.

Quick facts

Is the Lead IAM Engineer role remote?
It's hybrid — Braze expects some on-site time in New York City.
What's the salary range?
Braze lists $101,000–$158,000 for this role.
Where is the role based?
Braze is hiring for this position in New York City.
What's the tech stack?
Joblaze extracted these technologies from the posting: OAuth 2.0, OIDC, Okta, PowerShell, Python, SAML.
What seniority level is this role?
Braze targets lead candidates for this position.
Is this full-time or contract?
Full-time for this Lead IAM Engineer role at Braze.

From the original posting

At Braze, we have found our people. We’re a genuinely approachable, exceptionally kind, and intensely passionate crew.

WHAT YOU'LL DO

We’re seeking a Lead IAM Engineer to own the technical direction and evolution of our enterprise identity and access management strategy. In this senior individual contributor role, you’ll architect, build, and continuously improve a secure, scalable, and automated identity ecosystem centered on Okta, identity lifecycle, access governance, and automation.

You’ll partner across Information Systems, Security, Engineering, Financial, and People Systems to ensure employees, contractors, partners, applications, and services have the right access at the right time while maintaining strong security, governance, reliability, and user experience.

A major focus of this role will be improving onboarding, access-change, and offboarding reliability, reducing manual administration, strengthening access governance, and expanding automation across our identity ecosystem. You’ll help modernize how identity configuration changes are managed through APIs, infrastructure as code, automated workflows, and repeatable engineering practices.

You’ll also help strengthen the broader Identity & Access capability by developing reusable patterns, improving documentation and operational resilience, mentoring other engineers, and reducing key-person dependencies across critical identity services.

If you’re an experienced IAM engineer with deep Okta expertise who enjoys both defining architecture and getting hands-on with automation, integrations, governance, and platform engineering, we’d love to meet you.

Main responsibilities:

  • Own the technical roadmap and architecture for enterprise Identity & Access Management, with Okta as a core identity platform
  • Architect and continuously improve Okta capabilities across SSO, authentication, lifecycle automation, Workflows, Identity Governance, and Access Requests
  • Design reliable onboarding, role-change, and offboarding identity processes for employees, contractors, partners, and other user populations
  • Build and improve integrations between Okta and systems such as Workday, Google Workspace, Slack, GitHub, Atlassian, MDM, and other enterprise applications
  • Drive identity automation using Okta Workflows, APIs, scripting, Terraform, and other engineering tools
  • Modernize how identity configuration changes are made through infrastructure as code, automated validation, peer review, and controlled deployment where appropriate
  • Lead identity governance initiatives including access reviews, access requests, role-based access, approval workflows, entitlement management, and least-privilege controls
  • Design and implement authentication, federation, and provisioning solutions using SAML, OIDC, OAuth, SCIM, MFA, and related identity standards
  • Partner with Security on authentication standards, privileged access, identity risk, and zero-trust initiatives
  • Support and continuously improve identity-related SOX controls, audit evidence, access reviews, and remediation processes
  • Design identity solutions for partners, resellers, service accounts, machine identities, and other non-standard access needs
  • Serve as a senior escalation point for complex identity issues and lead root cause analysis when identity or lifecycle processes fail
  • Identify recurring administrative or support work and create automation, self-service, runbooks, or delegated workflows to reduce manual intervention
  • Establish repeatable engineering standards for how identity changes are designed, tested, deployed, and documented
  • Mentor other engineers and help build broader IAM expertise and independent backup coverage across the team
  • Evaluate emerging identity capabilities and recommend where they can improve security, reliability, scalability, or user experience

WHO YOU ARE

  • Deep hands-on expertise with Okta in a complex enterprise environment, including SSO, Lifecycle Management, Authentication, MFA, Workflows, and Identity Governance
  • Advanced understanding of SAML, OIDC, OAuth 2.0, SCIM, federation, provisioning, authentication, and authorization
  • Experience automating employee onboarding, role changes, and offboarding using an HRIS such as Workday as the authoritative source for employee data
  • Strong experience with identity governance including access reviews, entitlement management, access requests, role-based access control, and least privilege
  • Strong scripting and automation skills using Python, PowerShell, or similar languages
  • Strong API integration experience and the ability to connect identity platforms with broader enterprise systems
  • Experience with Terraform or another infrastructure-as-code framework
  • Experience turning manual identity administration into scalable, automated, and auditable processes
  • Experience supporting IAM controls in a SOX-regulated or similarly controlled environment
  • Proven ability to lead complex cross-functional IAM initiatives without requiring formal people-management authority
  • Strong communication skills with the ability to explain identity architecture, technical decisions, and risk to both technical and non-technical audiences

Bonus Points:

  • Okta certifications such as Okta Certified Administrator, Consultant, Developer, or Identity Governance credentials
  • Experience managing Okta configuration through Terraform or similar tooling
  • Experience using Git-based workflows or CI/CD practices to manage identity or infrastructure changes
  • Familiarity with adjacent enterprise platforms such as Google Workspace, Slack, GitHub, Atlassian, Iru, Kandji, Jamf, Zscaler, or 1Password
  • Experience with partner, reseller, B2B, or external identity architectures
  • Experience managing service accounts, machine identities, workload identities, or other non-human access
  • Experience automating audit evidence or identity governance controls

For candidates based in the United States, the pay range for this position at the start of employment is expected to be between $101,000 and $158,000/year, with an expected On Target Earnings (OTE) between $112,000 and $176,000/year (including bonus or commission). Your exact offer may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition to cash compensation, this role qualifies for a comprehensive Total Rewards package that includes equity grants of restricted stock (RSUs) so that you will own a piece of our company.

#LI-Hybrid

WHAT WE OFFER

Standard company text repeated across Braze's postings is omitted here.

Similar positions

Braze
Lead IAM Engineer
Braze · Chicago
Braze
Lead IAM Engineer
Braze · Austin
Braze
Lead IAM Engineer
Braze · Toronto
Elastic
Okta Identity Engineer
Elastic · United States
Okta
Staff Identity Engineer
Okta · Bellevue, Washington; Chicago, Illinois; Washington, DC