Zappsec is an intelligent infrastructure consultancy. We deliver security, network, cloud, and identity as an integrated platform for enterprise clients across North America.
About the Role
We are hiring an Identity Architect to lead the design of a large-scale enterprise identity modernization program. The program consolidates workforce identity onto Okta and retires legacy identity infrastructure. You will own the target-state architecture and guide a delivery team of workstream leads and engineers. This is a client-facing role. You will present designs to senior stakeholders, defend architectural decisions, and sequence a complex migration across multiple parallel workstreams.
What You Will Do
Define the target-state workforce identity architecture on Okta, covering SSO, MFA, and adaptive access
Design the identity governance model on Okta Identity Governance, including access requests and certification campaigns
Architect joiner, mover, and leaver (JML) lifecycle automation using Okta Workflows, driven by the HR system of record
Lead the replacement strategy for Microsoft Identity Manager (MIM), including provisioning logic and data flows
Define the migration approach for SAML and OIDC applications moving onto Okta
Design the modernization path for legacy LDAP directories and RADIUS-based authentication
Set the integration pattern between Okta, Active Directory, and Entra ID, with Entra scoped to Microsoft 365 use cases
Produce and maintain architecture deliverables: high-level designs, low-level designs, and migration sequencing plans
Review engineering work for alignment with the target architecture
Identify design risks early and bring options to client stakeholders with a clear recommendation
What You Bring
10+ years in identity and access management, with 5+ years architecting Okta at enterprise scale
Deep knowledge of Okta Workforce Identity, Okta Identity Governance, and Okta Workflows
Hands-on history with federation protocols: SAML 2.0, OIDC, OAuth 2.0, and SCIM
Experience decommissioning or replacing legacy IAM platforms such as MIM
Working knowledge of Active Directory, LDAP directory services, and RADIUS authentication
Understanding of hybrid identity models where AD remains a dependency alongside a cloud identity platform
A record of leading identity workstreams on multi-month enterprise programs
Strong written design documentation and the ability to explain trade-offs to executives and engineers alike
Nice to Have
Okta certifications (Okta Certified Consultant, Okta Certified Professional, or equivalent)
Experience with HR-driven provisioning integrations
Prior consulting or professional services delivery experience
Exposure to identity governance migrations from legacy IGA or homegrown tooling
How to Apply
Send your resume and a short note on the largest Okta program you have architected to [email protected]