Senior Security Consultant - Okta (Remote in the US)
- Role
- Fullstack
- Experience
- Senior
- Employment
- Full-time
- Company size
- Enterprise
Open to US only. Set where you work from to check your eligibility.
No BS summary
GuidePoint Security is hiring a Senior Security Consultant – Okta Access Management to join our delivery team on a full-time basis. This is a fully remote role for a seasoned IAM engineer/architect who can independently lead complex Okta engagements from design through implementation with minimal oversight.
Core skills
Required skills
Optional skills
Required languages
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
General Description
GuidePoint Security is hiring a Senior Security Consultant – Okta Access Management to join our delivery team on a full-time basis. This is a fully remote role for a seasoned IAM engineer/architect who can independently lead complex Okta engagements from design through implementation with minimal oversight.
The Senior Security Consultant is a hands-on technical leader responsible for architecting, implementing, and optimizing Access Management solutions across the Okta Identity Engine (OIE) and Auth0 platforms. This role requires deep expertise in Okta Workflows, federation, and modern authentication patterns — with the ability to flex between workforce and customer identity use cases depending on engagement needs.
This individual will serve as the technical authority on assigned engagements, driving solution design, leading client workshops, mentoring junior staff, and ensuring delivery excellence across the full engagement lifecycle.
Access Management / CIAM Practice
Coming to the Access Management team means working on the leading edge in the IAM space. As a Senior Security Consultant focused on Okta, you will lead complex identity engagements for some of the largest enterprises in the US — designing solutions that secure millions of users across workforce and customer-facing applications. You will have the autonomy to own your engagements end-to-end while being backed by a collaborative team of IAM specialists.
We partner with the largest vendors in the space to ensure that the latest training is always available to our team. High level communication and collaboration are the standard. Mentorship at all levels is foundational to our culture. We don't just talk about work life balance; we facilitate it with an unlimited PTO benefit.
We understand that in order to retain our talented team, leadership must provide regular feedback and coaching. We recruit new members to the team with the understanding that opportunities for growth are important. Whether your goals include future leadership opportunities, becoming a Practice Director, or even moving to another discipline within security in time, the leadership team is focused on partnering with you to help achieve them.
Roles and Responsibilities:
Technical Delivery & Solution Architecture (50%)
Lead end-to-end design and implementation of Okta OIE solutions including SSO, MFA, adaptive access policies, and Lifecycle Management (LCM) Design and implement comprehensive LCM solutions including joiner/mover/leaver automation, SCIM provisioning to downstream applications, HR-driven identity workflows, provisioning agent deployment, and directory integrations (AD, LDAP, HR systems such as Workday and SuccessFactors) Leverage Okta Workflows to extend LCM beyond native connectors — building custom integrations for disconnected applications, automating account reconciliation, orchestrating complex provisioning logic, and implementing event-driven automation across connected systems (including approval chains, attribute transformations, and onboarding/offboarding sequences) Architect and build Auth0 solutions for customer identity use cases (B2C, B2B, B2B2C) including Universal Login, Actions, Organizations, and custom database connections Develop federation architectures leveraging SAML 2.0, OAuth 2.0, and OpenID Connect across hybrid environments Configure and optimize Okta API Access Management including custom authorization servers, token policies, scopes, and claims for securing APIs and microservices Apply infrastructure-as-code and DevOps/SecDevOps practices to Okta environments — managing tenant configurations via the Okta Terraform Provider, version-controlling policy and application definitions in Git, and integrating identity changes into CI/CD pipelines (e.g., GitHub Actions, GitLab CI) for repeatable, auditable deployments Lead technical discovery sessions, whiteboarding, and solution design workshops with client architects and engineering teams Produce technical design documents, architecture diagrams, runbooks, and implementation guides Perform platform migrations, tenant configurations, and identity consolidation efforts
Engagement Leadership & Delivery Execution (25%)
Lead assigned engagements independently — owning timelines, deliverables, and client communication with minimal oversight Develop and maintain engagement plans, track milestones, and proactively manage risks and dependencies Facilitate status meetings, steering committees, and executive briefings Manage scope and drive change control processes when requirements evolve Coordinate with other workstreams and delivery resources to ensure alignment across parallel efforts Ensure engagement closeout includes proper documentation, knowledge transfer, and transition planning
Mentorship & Technical Enablement (15%)
Mentor junior consultants and business analysts on Okta/Auth0 technical concepts and delivery best practices Conduct internal knowledge-sharing sessions, brown bags, and technical deep dives Review deliverables and solution designs produced by other team members for quality and accuracy Contribute to the development of reusable assets including templates, accelerators, and reference architectures Support onboarding of new team members to the Okta practice
Presales & Practice Development (10%)
Support sales efforts by participating in scoping calls, technical qualification, and solution demonstrations Contribute to SOW development, LOE estimation, and proposal creation for Okta/Auth0 opportunities Identify expansion opportunities within active engagements and communicate to account teams Stay current on Okta/Auth0 product roadmaps, releases, and emerging capabilities Represent GuidePoint at vendor events, webinars, and industry forums as appropriate Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Required Experience and Education:
Bachelor’s degree in Computer Science, Information Security, or related field — or equivalent work experience 7+ years of hands-on experience in Identity and Access Management 4+ years of direct implementation experience with Okta OIE (Workforce Identity Cloud) Full proficiency in Okta Workflows — including connector development, error handling, complex flow logic, and API-driven automations Strong LCM implementation background — proven experience designing and deploying joiner/mover/leaver processes, SCIM provisioning, and automated lifecycle orchestration using Okta Workflows Demonstrated experience with Auth0 implementation including Actions, Rules, Universal Login customization, Organizations, and tenant architecture Deep understanding of federation protocols (SAML 2.0, OAuth 2.0, OpenID Connect) and their practical application Experience with Okta API Access Management, token policies, and custom authorization servers Proven ability to lead engagements independently with minimal oversight — managing scope, timelines, and client relationships Strong client-facing communication skills with the ability to present to both technical and executive audiences Experience producing professional technical deliverables (design documents, architecture diagrams, runbooks)
Preferred Experience and Education:
Experience with additional Okta OIE modules:
Okta Privileged Access (OPA) Okta Identity Governance (OIG) Okta Device Access Okta Identity Threat Protection (ITP) Okta for AI Agents (O4AA)
Experience with Ping Identity products (PingFederate, PingOne, PingAccess) or other Access Management vendors (Microsoft Entra ID, ForgeRock) Familiarity with infrastructure-as-code tooling for identity — Okta Terraform Provider, Git-based version control, and CI/CD pipeline integration Okta certifications:
Okta Certified Professional Okta Certified Administrator Okta Certified Consultant
Experience with complementary IAM platforms (CyberArk, SailPoint) Background in customer identity (CIAM) architecture patterns and multi-tenant design Additional certifications (CISSP, Security+, AWS/Azure identity certifications) Prior consulting or professional services delivery experience
Travel Requirements:
Up to 10% travel
Physical Requirements:
Sedentary work Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day
We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint?
GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,300 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.
Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.
This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.
Some added perks….
Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions) Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options) Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans 12 corporate holidays and a Flexible Time Off (FTO) program Healthy mobile phone and home internet allowance Eligibility for retirement plan after 2 months at open enrollment Pet Benefit Option
What you'll do
- Lead end-to-end design and implementation of Okta OIE solutions including SSO, MFA, adaptive access policies, and Lifecycle Management (LCM)
- Design and implement comprehensive LCM solutions including joiner/mover/leaver automation, SCIM provisioning to downstream applications, HR-driven identity workflows, provisioning agent deployment, and directory integrations (AD, LDAP, HR systems such as Workday and SuccessFactors)
- Leverage Okta Workflows to extend LCM beyond native connectors — building custom integrations for disconnected applications, automating account reconciliation, orchestrating complex provisioning logic, and implementing automation, role-based control
- Architect and build Auth0 solutions for customer identity use cases (B2C, B2B, B2B2C) including Universal Login, Actions, Organizations, and custom database connections
- Develop federation architectures leveraging SAML 2.0, OAuth 2.0, and OpenID Connect across hybrid environments
- Configure and optimize Okta API Access Management including custom authorization servers, token policies, scopes, and claims for securing APIs and microservices
- Apply infrastructure-as-code and DevOps/SecDevOps practices for Okta environments — managing tenant configurations with the Okta Terraform Provider, version-controlling policies in Git, and integrating CI/CD pipelines (e.g., GitHub Actions, GitLab CI)
- Lead technical discovery sessions, workshops with client architects and engineers
- Produce technical design documents, architecture diagrams, runbooks, and implementation guides
- Perform platform migrations, tenant configurations, and identity consolidation
- Lead assigned engagements independently — owning timelines, deliverables, and client communication with minimal oversight
- Develop engagement and change control plans and manage scope
- Facilitate status meetings, steering committees, and executive briefings
- Coordinate with other workstreams and teams
- Provide knowledge transfer and transition planning upon project completion
- Mentor junior consultants and business analysts
- Conduct team knowledge-sharing sessions and brown bags
- Review deliverables and designs for quality
- Contribute and maintain reusable assets
- Support onboarding of new team members
- Participate in presales activities: scoping, demos, proposals
- Identify expansion opportunities to account teams
- Stay current on product roadmaps and emerging capabilities
- Embrace emerging technologies, including AI
- travel_requirements_percent_min_estimated_globally_total_average_value_integer_should_be_at_least_1_if_required_at_least_once_a_month_else_0_shold_be_0_for_5_percent_if_seldom_0_strict_daily_hours_min_for_driving_forever_0_to_10_percent_work_hours_int_{-"dc_relationship_validation":"liaison: strength matching substring"}
- requirements
- travel_percentage_range_min_max_extracted_from_posting_note_plus_string_response
- physical_requirements_text_exact_fragment_copy
- Requirements
What they require
- 7+ years of hands-on experience in identity and access management
- 4+ years direct implementation experience with Okta OIE (Workforce Identity)
- Full proficiency in Okta Workflows
- Strong LCM implementation background including deployment of joiner/mover/leaver processes, SCIM, and automated orchestration using Okta Workflows
- Demonstrated experience with Auth0 implementation including Actions, Rules, Universal Login customization, Organizations, and tenant architecture
- Deep understanding of federation protocols (SAML 2.0, OAuth 2.0, OpenID Connect) and application architecture
- Experience with Okta API Access Management, token policies, and custom authorization servers
- Proven ability to lead engagements independently — managing scope, timelines, and client relationships
- Strong client-facing communication and presentation skills
- Professional experience producing technical deliverables (design documents, architecture diagrams, runbooks)
- Bachelor's degree in Computer Science, Information Security or related field — or equivalent work experience
- Willingness to stay current in product roadmaps and releases
- Travel up to 10% of the time
- Sedentary work with substantial movement of wrists . hands and fingers
- Close visual acuity for view of computer terminal and extensive reading for a minimum of 8 hours a day
- travel_requirement_exact_fragment_asterisk_presence_of_travel_requirements_section
- Physical requirements include handwriting.
- Bachelor’s degree in Computer Science, Information Security, or related field — or equivalent work experience
- 4+ years of direct implementation experience with Okta OIE (Workforce Identity Cloud)
- Full proficiency in Okta Workflows — including connector development, error handling, complex flow logic, and API-driven automations
- Strong client-facing communication skills with the ability to present to both technical and executive audiences
Benefits
- Remote workforce (U.S. based only)
- Group Medical Insurance options: Zero Deductible PPO Plan or High Deductible Health Plan with HSA
- Group Dental Insurance: GuidePoint pays 100% of premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
- Unlimited PTO
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
What people say about this company
4.2/ 5
- Supportive work environment that encourages collaboration.
- Opportunities for professional development and growth.
- Some concerns about management effectiveness.