Sr. Cloud Security Engineer (Okta Identity Platform Engineering)

vanguardΒ· The Vanguard Group, Inc.
Apply Now β†—

About this role

Shape the future of enterprise identity by engineering, securing, and automating mission-critical workforce identity services that enable secure access across the enterprise. As a senior member of the Identity Platform team, you will drive the design, implementation, operation, and continuous improvement of Okta capabilities that improve security, resiliency, reliability, and user experience.

This role combines identity architecture, platform engineering, automation, operational excellence, and technical leadership. You will partner with application teams, infrastructure engineers, cybersecurity, and cloud teams to deliver scalable identity solutions while reducing operational risk and improving service maturity.

The ideal candidate brings deep expertise in Okta, modern authentication protocols, identity lifecycle management, cloud security engineering, automation, and incident response, along with a passion for mentoring others and driving continuous improvement.

Core Responsibilities:

Platform Engineering & Identity Solutions

  • Design, implement, and maintain enterprise-scale identity solutions leveraging Okta Workforce Identity capabilities.
  • Lead application onboarding initiatives including SAML, OIDC/OAuth, SCIM provisioning, federation, lifecycle management, and authentication integrations.
  • Develop scalable identity architectures that improve security, operational efficiency, and end-user experience.
  • Partner with cloud and platform engineering teams to integrate identity controls across enterprise platforms and cloud environments.

Automation & Engineering Excellence

  • Design and implement automation solutions using APIs, scripting, workflows, infrastructure-as-code, and CI/CD pipelines to reduce manual effort and improve service delivery.
  • Automate operational processes, platform governance controls, application onboarding activities, and compliance reporting.
  • Drive platform engineering best practices including Git-based deployment models, testing strategies, release management, and configuration standardization.
  • Continuously evaluate emerging technologies and capabilities to improve scalability, reliability, security, and operational effectiveness.

Operational Reliability & Resiliency

  • Own platform resiliency initiatives include disaster recovery planning, service continuity testing, monitoring, observability, and operational readiness reviews.
  • Participate in production support and critical incident response while driving permanent engineering solutions that eliminate recurring operational issues.
  • Lead root cause analysis activities and implement preventative controls to improve platform stability.
  • Establish and maintain monitoring, alerting, and operational dashboards that provide visibility into platform health and key performance indicators.

Security, Governance & Compliance

  • Implement and maintain secure authentication, authorization, and access management controls.
  • Support audit readiness through development of controls, documentation, evidence collection processes, and governance standards.
  • Assess and mitigate security risks associated with identity systems, integrations, and cloud-based services.
  • Drive initiatives that enhance platform security posture through continuous improvement, vulnerability remediation, policy modernization, and threat detection capabilities.

Technical Leadership

  • Serve as a technical leader and trusted advisor for workforce identity services and authentication technologies.
  • Influence architecture decisions, engineering standards, and operational best practices across teams.
  • Mentor engineers and support knowledge-sharing initiatives that reduce key-person dependency and improve organizational resiliency.
  • Collaborate with internal stakeholders, vendors, and cross-functional teams to deliver strategic identity initiatives.

Operational Leadership

  • Experience managing major incidents, root cause analysis, and operational readiness activities.
  • Ability to analyze complex authentication, authorization, and provisioning issues across multiple integrated systems.
  • Strong stakeholder communication and cross-functional collaboration skills.
  • Experience developing technical documentation, standards, procedures, and operational runbooks.

Business Outcomes

  • Drive measurable improvements in:
    • Faster application onboarding
    • Platform reliability and availability
    • Incident response effectiveness
    • Automation adoption
    • Audit readiness
    • Reduction of operational risk
    • Service scalability and engineering efficiency

Required Qualifications

  • Minimum 7 years of broad experience working on large-scale systems or services, Cloud Security Engineering, Identity Platform Engineering, Identity and Access Management or related disciplines.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience.
  • Extensive hands-on experience with Okta Workforce Identity Cloud.
  • At least 2 current Okta certifications (e.g., Okta Certified Professional, Administrator, Consultant, Developer)

Technical Skills

Demonstrated expertise in:

  • SAML 2.0
  • OIDC / OAuth 2.0
  • SCIM Provisioning
  • Okta APIs
  • MFA and Adaptive Authentication
  • FastPass
  • Device Assurance
  • Sign-On Policies/Patterns
  • FIDO2 and Okta Verify Implementations
  • Identity Lifecycle Management
  • Federation Design
  • Application Onboarding and Troubleshooting
  • Directory Services

Strong experience with:

  • CI/CD Pipelines
  • GitHub-based Development
  • Infrastructure as Code (Terraform or OpenTofu)
  • Python, PowerShell, or similar scripting languages
  • AWS Services (Lambda, Secrets Manager, CloudWatch)
  • REST APIs
  • Okta Workflows
  • Splunk and Log Analysis
  • Change Management and Production Support

Nice to Have:

Identity Innovation

  • Identity Threat Protection
  • Behavior Detection and Risk Signals
  • Okta AI and Agentic AI capabilities

Platform Engineering

  • Automation Framework Development
  • Event-Driven Architectures

Governance & Recovery

  • Identity Governance Concepts
  • Disaster Recovery Planning
  • Backup and Recovery Solutions
  • Audit and Compliance Frameworks

Cloud & Security

  • AWS, GCP and Azure security controls
  • Secrets management
  • PKI and certificate management
  • Security monitoring and observability platforms

What Success Looks Like

In this role, success means delivering reliable, secure, and scalable identity services that:

  • Accelerate application onboarding.
  • Improve platform automation and operational efficiency.
  • Strengthen the organization's security posture.
  • Increase platform resiliency and reliability.
  • Enhance audit readiness and regulatory compliance.
  • Reduce operational and key-person risk.
  • Enable exceptional workforce identity experiences across the enterprise.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a missionβ€”we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Frequently Asked Questions

Is the salary disclosed for the Sr. Cloud Security Engineer (Okta Identity Platform Engineering) position at vanguard?
The salary for this Sr. Cloud Security Engineer (Okta Identity Platform Engineering) role at vanguard is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Sr. Cloud Security Engineer (Okta Identity Platform Engineering) position at vanguard located?
This Sr. Cloud Security Engineer (Okta Identity Platform Engineering) role at vanguard is based in Dallas/Ft. Worth, TX, Malvern, PA, North Carolina. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Sr. Cloud Security Engineer (Okta Identity Platform Engineering) role at vanguard full-time or part-time?
This is listed as a Full time position. It is posted as a Sr. Cloud Security Engineer (Okta Identity Platform Engineering) role in the The Vanguard Group, Inc. department at vanguard.
Which team or department does the Sr. Cloud Security Engineer (Okta Identity Platform Engineering) at vanguard belong to?
This Sr. Cloud Security Engineer (Okta Identity Platform Engineering) position is part of the The Vanguard Group, Inc. department at vanguard. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Sr. Cloud Security Engineer (Okta Identity Platform Engineering) position at vanguard?
Click the "Apply Now" button on this page. You will be redirected to vanguard's official application portal hosted on workday where you can submit your application directly.
When was the Sr. Cloud Security Engineer (Okta Identity Platform Engineering) job at vanguard posted?
This Sr. Cloud Security Engineer (Okta Identity Platform Engineering) position at vanguard was posted on Aug 21, 2026. Apply as soon as possible β€” early applications are often reviewed first.
Sr. Cloud Security Engineer (Okta Identity Platform Engineering)
vanguard
Apply for this role β†—

You'll be redirected to vanguard's official application page on Workday.