Skip to content

Open nowPosted 46 days ago

Sr. Cloud Security Engineer (Okta Identity Platform Engineering)

Vanguard81 open roles

Where
Malvern PA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr. Cloud Security Engineer (Okta Identity Platform Engineering)Vanguard · Malvern PA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Vanguard's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Vanguard postings stay open a median of 1 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 46 days ago

Vanguard median: 1 days open

The posting

Shape the future of enterprise identity by engineering, securing, and automating mission-critical workforce identity services that enable secure access across the enterprise. As a senior member of the Identity Platform team, you will drive the design, implementation, operation, and continuous improvement of Okta capabilities that improve security, resiliency, reliability, and user experience.

This role combines identity architecture, platform engineering, automation, operational excellence, and technical leadership. You will partner with application teams, infrastructure engineers, cybersecurity, and cloud teams to deliver scalable identity solutions while reducing operational risk and improving service maturity.

The ideal candidate brings deep expertise in Okta, modern authentication protocols, identity lifecycle management, cloud security engineering, automation, and incident response, along with a passion for mentoring others and driving continuous improvement.

Core Responsibilities:

Platform Engineering & Identity Solutions

  • Design, implement, and maintain enterprise-scale identity solutions leveraging Okta Workforce Identity capabilities.
  • Lead application onboarding initiatives including SAML, OIDC/OAuth, SCIM provisioning, federation, lifecycle management, and authentication integrations.
  • Develop scalable identity architectures that improve security, operational efficiency, and end-user experience.
  • Partner with cloud and platform engineering teams to integrate identity controls across enterprise platforms and cloud environments.

Automation & Engineering Excellence

  • Design and implement automation solutions using APIs, scripting, workflows, infrastructure-as-code, and CI/CD pipelines to reduce manual effort and improve service delivery.
  • Automate operational processes, platform governance controls, application onboarding activities, and compliance reporting.
  • Drive platform engineering best practices including Git-based deployment models, testing strategies, release management, and configuration standardization.
  • Continuously evaluate emerging technologies and capabilities to improve scalability, reliability, security, and operational effectiveness.

Operational Reliability & Resiliency

  • Own platform resiliency initiatives include disaster recovery planning, service continuity testing, monitoring, observability, and operational readiness reviews.
  • Participate in production support and critical incident response while driving permanent engineering solutions that eliminate recurring operational issues.
  • Lead root cause analysis activities and implement preventative controls to improve platform stability.
  • Establish and maintain monitoring, alerting, and operational dashboards that provide visibility into platform health and key performance indicators.

Security, Governance & Compliance

  • Implement and maintain secure authentication, authorization, and access management controls.
  • Support audit readiness through development of controls, documentation, evidence collection processes, and governance standards.
  • Assess and mitigate security risks associated with identity systems, integrations, and cloud-based services.
  • Drive initiatives that enhance platform security posture through continuous improvement, vulnerability remediation, policy modernization, and threat detection capabilities.

Technical Leadership

  • Serve as a technical leader and trusted advisor for workforce identity services and authentication technologies.
  • Influence architecture decisions, engineering standards, and operational best practices across teams.
  • Mentor engineers and support knowledge-sharing initiatives that reduce key-person dependency and improve organizational resiliency.
  • Collaborate with internal stakeholders, vendors, and cross-functional teams to deliver strategic identity initiatives.

Operational Leadership

  • Experience managing major incidents, root cause analysis, and operational readiness activities.
  • Ability to analyze complex authentication, authorization, and provisioning issues across multiple integrated systems.
  • Strong stakeholder communication and cross-functional collaboration skills.
  • Experience developing technical documentation, standards, procedures, and operational runbooks.

Business Outcomes

  • Drive measurable improvements in:Faster application onboarding Platform reliability and availability Incident response effectiveness Automation adoption Audit readiness Reduction of operational risk Service scalability and engineering efficiency

Required Qualifications

  • Minimum 7 years of broad experience working on large-scale systems or services, Cloud Security Engineering, Identity Platform Engineering, Identity and Access Management or related disciplines.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience.
  • Extensive hands-on experience with Okta Workforce Identity Cloud.
  • At least 2 current Okta certifications (e.g., Okta Certified Professional, Administrator, Consultant, Developer)

Technical Skills

Demonstrated expertise in:

  • SAML 2.0
  • OIDC / OAuth 2.0
  • SCIM Provisioning
  • Okta APIs
  • MFA and Adaptive Authentication
  • FastPass
  • Device Assurance
  • Sign-On Policies/Patterns
  • FIDO2 and Okta Verify Implementations
  • Identity Lifecycle Management
  • Federation Design
  • Application Onboarding and Troubleshooting
  • Directory Services

Strong experience with:

  • CI/CD Pipelines
  • GitHub-based Development
  • Infrastructure as Code (Terraform or OpenTofu)
  • Python, PowerShell, or similar scripting languages
  • AWS Services (Lambda, Secrets Manager, CloudWatch)
  • REST APIs
  • Okta Workflows
  • Splunk and Log Analysis
  • Change Management and Production Support

Nice to Have:

Identity Innovation

  • Identity Threat Protection
  • Behavior Detection and Risk Signals
  • Okta AI and Agentic AI capabilities

Platform Engineering

  • Automation Framework Development
  • Event-Driven Architectures

Governance & Recovery

  • Identity Governance Concepts
  • Disaster Recovery Planning
  • Backup and Recovery Solutions
  • Audit and Compliance Frameworks

Cloud & Security

  • AWS, GCP and Azure security controls
  • Secrets management
  • PKI and certificate management
  • Security monitoring and observability platforms

What Success Looks Like

In this role, success means delivering reliable, secure, and scalable identity services that:

  • Accelerate application onboarding.
  • Improve platform automation and operational efficiency.
  • Strengthen the organization's security posture.
  • Increase platform resiliency and reliability.
  • Enhance audit readiness and regulatory compliance.
  • Reduce operational and key-person risk.
  • Enable exceptional workforce identity experiences across the enterprise.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Vanguard's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Vanguard's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Vanguard's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.