Careers
For additional information on how we handle your data, see www.LRS.com/privacy
What to do if you suspect fraud:
If you receive a suspicious offer or communication claiming to be from us, do not share any personal or financial information. You can notify us using our contact page at Contact Levi, Ray & Shoup, Inc.
IMPORTANT NOTES:
- All legitimate correspondence from our recruiting team will only come from an email address ending in @lrs.com. We do not use generic domains like @gmail.com, @yahoo.com, or @outlook.com.
- We never conduct interviews solely via text-based chat on Microsoft Teams, Telegram, or WhatsApp. All virtual interviews involve a scheduled video or phone call with a member of our team.
- LRS will never ask a candidate for payment, fees, or to purchase equipment (e.g., laptops, software) as a condition of employment.
- All genuine job opportunities are listed directly on our official careers portal at Careers.
Job Description
LRS Consulting Services is seeking a Senior Okta Identity and Access Management (IAM) Engineer who is passionate about securing enterprise environments, advancing Zero Trust initiatives, and designing modern identity solutions that protect critical business and government systems. This hybrid direct-hire opportunity offers the chance to serve as the lead Okta subject matter expert in a complex federal environment, shaping enterprise identity strategy while ensuring secure, compliant, and scalable access management solutions.
Location: Washington, DC (Hybrid - 1 day per week onsite)
Responsibilities
- Serve as the primary technical authority for enterprise Okta Identity and Access Management capabilities.
- Architect, engineer, implement, administer, and continuously improve Okta-based IAM solutions across on-premises, cloud, and hybrid environments.
- Design and implement secure identity architectures supporting Zero Trust security initiatives and federal cybersecurity requirements.
- Configure and support Okta Workforce Identity Cloud, Customer Identity Cloud (Auth0), Universal Directory, Adaptive Multi-Factor Authentication (AMFA), Single Sign-On (SSO), Lifecycle Management, API Access Management, Advanced Server Access, and Privileged Access solutions.
- Design and maintain enterprise SSO integrations utilizing SAML 2.0, OIDC, OAuth 2.0, and related federation technologies.
- Develop and enforce identity governance, access control, authentication, authorization, and least-privilege access strategies.
- Configure and optimize adaptive authentication policies, phishing-resistant MFA solutions, risk-based access controls, and device trust integrations.
- Implement and support lifecycle management processes including provisioning, profile synchronization, role management, and automated deprovisioning.
- Collaborate with cybersecurity, network engineering, cloud operations, DevSecOps, Microsoft infrastructure, and application development teams to deliver secure identity solutions.
- Support identity integrations across enterprise applications, infrastructure platforms, cloud services, and third-party systems.
- Participate in architecture reviews, security assessments, platform upgrades, and continuous improvement initiatives.
- Create and maintain architecture documentation, implementation guides, operational procedures, security standards, and support documentation.
- Support compliance, audit, and security initiatives within highly regulated federal environments.
Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field, or equivalent professional experience.
- 7+ years of experience in Identity and Access Management, cloud security, cybersecurity engineering, or related disciplines.
- 4+ years of hands-on experience implementing, administering, and supporting Okta Workforce Identity Cloud in a large enterprise environment.
- Strong experience designing and implementing enterprise Single Sign-On (SSO) solutions using SAML 2.0, OpenID Connect (OIDC), and OAuth 2.0.
- Experience configuring and managing Okta Adaptive Multi-Factor Authentication (AMFA), risk-based authentication, phishing-resistant MFA, and conditional access policies.
- Experience with Okta Lifecycle Management, including provisioning, profile management, synchronization, and deprovisioning processes.
- Strong understanding of Identity and Access Management principles, identity federation, authentication, authorization, and Zero Trust security architectures.
- Experience designing secure identity solutions across cloud, on-premises, and hybrid infrastructures.
- Knowledge of identity governance, access management, privileged access management, and least-privilege security principles.
- Strong troubleshooting, analytical, and problem-solving skills.
- Experience creating technical documentation, architecture diagrams, implementation procedures, and operational support materials.
- Experience supporting federal government, regulated, or highly secure enterprise environments.
- Ability to communicate effectively with technical teams, business stakeholders, leadership, and government personnel.
- Must be able to obtain a Public Trust Clearance.
- Must be able to communicate effectively in English, both written and verbal.
Preferred Qualifications
- Experience serving as a lead Okta engineer or architect within a federal government environment.
- Hands-on experience with:
- Okta API Access Management
- Okta Workflows
- Okta Advanced Server Access
- Okta Privileged Access
- Auth0 / Okta Customer Identity Cloud
- Experience supporting FedRAMP-authorized environments and federal compliance requirements.
- Familiarity with NIST, Zero Trust Architecture, FedRAMP, FISMA, and related federal cybersecurity frameworks.
- Experience integrating Okta with Microsoft Entra ID, Active Directory, cloud platforms, SaaS applications, and enterprise security tools.
- Industry certifications related to Okta, cybersecurity, cloud security, or identity management are highly desirable.
The base salary range for this direct-hire position is $130,000 -$160,000 annually, depending on experience. The range displayed reflects the minimum and maximum target for new hires across all U.S. locations. Individual compensation is determined by experience, certifications, technical expertise, location, and other job-related factors.
LRS Consulting Services is an equal opportunity employer. Applicants for employment will receive consideration without unlawful discrimination based on race, color, religion, creed, national origin, sex, age, disability, marital status, gender identity, domestic partner status, sexual orientation, genetic information, citizenship status, or protected veteran status.
In some cases, LRS Consulting Services uses generative artificial intelligence ("AI") in support of our hiring processes. LRS takes steps to ensure the use of AI does not result in discrimination based on protected class(es). AI may be used solely in support of the assessment of candidate qualifications. All hiring decisions are made by LRS employees. If AI will be used in the hiring process for the position for which you are applying, you will be notified and will have the opportunity to opt out. Please contact AI.Questions@lrs.com with any questions.
What to do if you suspect fraud:
If you receive a suspicious offer or communication claiming to be from us, do not share any personal or financial information. You can notify us using our contact page at Contact Levi, Ray & Shoup, Inc.
IMPORTANT NOTES:
- All legitimate correspondence from our recruiting team will only come from an email address ending in @lrs.com. We do not use generic domains like @gmail.com, @yahoo.com, or @outlook.com.
- We never conduct interviews solely via text-based chat on Microsoft Teams, Telegram, or WhatsApp. All virtual interviews involve a scheduled video or phone call with a member of our team.
- LRS will never ask a candidate for payment, fees, or to purchase equipment (e.g., laptops, software) as a condition of employment.
- All genuine job opportunities are listed directly on our official careers portal at Careers.