OEC logo
OEC

QSP Geographics Inc. (QSP) is a fast-growing geospatial technology company that provides a range of industry-leading solutions in disciplines that include GIS services, CAD drafting, survey, engineering, and asset management services. We presently have over 125 employees with offices in Toronto and Ottawa.

Sr Identity & Access Engineer

EngineerEngineerFull TimeRemoteSeniorTeam 1,001-5,000

Location

United States

Posted

29 days ago

Salary

0

Seniority

Senior

Job Description

Sr Identity & Access Engineer

OEC

Role Description You’ll own and evolve OEC’s enterprise identity platform—the core security control plane that protects everything we do. This role goes beyond administration: you’ll shape architecture, strengthen our security posture, and drive scalable identity solutions across Active Directory, Microsoft Entra ID, and Okta. You’ll operate in a distributed U.S./India environment where autonomy, strong documentation, and thoughtful engineering are key. If you enjoy balancing security with user experience and want true ownership of a critical platform, this is that role. What You’ll Do - Own the identity platform end-to-end: availability, performance, and security across AD, Entra ID, and Okta - Design modern access controls: MFA, passwordless, Conditional Access, and adaptive authentication - Enforce least privilege at scale using RBAC/ABAC and automate Joiner/Mover/Leaver (JML) processes - Lead cloud identity strategy across Entra ID and AWS IAM, including federation and workload identities - Secure privileged access with PIM/PAM and resilient break-glass patterns - Detect and respond to threats using SIEM/log platforms; lead identity-related incident investigations - Own SOC 2 identity controls including access reviews, certifications, and audit readiness - Act as a subject matter expert: build architecture diagrams, runbooks, and integration standards - Collaborate and mentor through peer reviews, knowledge sharing, and team upskilling - Participate in an on-call rotation supporting a critical security platform Qualifications - 7+ years of hands-on IAM experience in enterprise environments - Deep expertise across Active Directory, Entra ID, and Okta - Experience designing hybrid identity architectures and modern access strategies - Strong background in identity security, incident response, and compliance frameworks (SOC 2, NIST, ISO) - Proven ability to own and evolve platforms, not just support them Technical Skills - Active Directory: domains, forests, GPOs, Kerberos, LDAP - Microsoft Entra ID: Conditional Access, MFA, Identity Protection, PIM, Entra Connect - Okta: SSO, lifecycle management, integrations, federation, Workflows - Protocols: SAML, OAuth 2.0, OIDC - Access Models: RBAC/ABAC, entitlement design, JML automation - Privileged Access: PIM, PAM, break-glass strategies - Cloud IAM: AWS IAM, federated identity, cross-platform trust - Security Monitoring: SIEM tools (Sentinel, Splunk), Entra & Okta logs - IGA Tools: SailPoint, Saviynt, or Entra ID Governance - PAM Tools: CyberArk, BeyondTrust, or Delinea - Automation: SCIM provisioning, scripting (PowerShell required) - Familiarity with AI-assisted scripting/tools (e.g., Copilot, Claude) is a plus - External identity (B2B): guest access, federation, Entra External ID How You Work - Communicate clearly and constructively—even in high-pressure situations - Adapt quickly as priorities shift in a fast-moving environment - Thrive in a remote-first, highly autonomous team Requirements - Bachelor’s degree in Computer Science, IT, or related field (or equivalent experience) - Relevant certifications preferred: SC-300, AZ-500, Okta Certified Professional/Admin Benefits - Full benefits starting Day 1: Medical, Dental, and Vision - 401(k) with company match - Unlimited Flex Time Off plus 10 company-paid holidays - Professional development programs, tuition assistance, and quarterly book program - Free wellness coaching and pet insurance - Home office equipment stipend - Employee resource groups and exclusive employee discounts Why This Role This is a high-impact, high-ownership position where you’ll directly influence the security and scalability of a growing enterprise platform. You won’t just maintain systems—you’ll design, improve, and lead.

Related Categories

Related Job Pages

More Engineer Jobs

NICE logo

Forward Deployed Engineer

NICE

Make experiences flow.

Engineer29 days ago
Full TimeRemoteTeam 5,001-10,000Since 1991H1B Sponsor

• A NiCE AI Forward Deployed Engineer is a highly technical full-stack engineer responsible for designing, building, and deploying AI-driven customer engagement solutions using the NiCE digital and AI portfolio. • This role sits at the intersection of software engineering, AI agent development, and customer solution architecture. • The engineer works directly with customers and internal stakeholders to translate complex business challenges into intelligent automation solutions across voice and digital channels. • The AI Forward Deployed Engineer will design, prototype, and operationalize AI agents that integrate with enterprise systems and deliver scalable customer self-service experiences powered by intelligent virtual agents, knowledge management, and omnichannel engagement capabilities. • You'll architect and deliver production-ready conversational AI agents that sit at the core of the business and directly fuel company growth. • These are live, scalable agentic AI systems, not experiments or proof-of-concepts, operating across sectors like financial services, healthcare, and commerce. • You'll have full ownership of the entire AI agent lifecycle, steering projects from early pilot through launch and ongoing refinement. • You'll collaborate directly with decision-makers at the world’s leading enterprises to tackle their highest-priority challenges with agentic AI. • The patterns and problems you encounter in the field will feed directly into the evolution of the platform, tools, and product roadmap.

Australia
Dudek logo

Fire Protection Engineer

Dudek

Doing work that matters, since 1980.

Engineer29 days ago
Full TimeRemoteTeam 501-1,000Since 1980H1B No Sponsor

• Assist clients in the development of energy infrastructure, including battery energy storage system (BESS) facilities. • Serve as both a technical expert and business partner with Dudek clients. • Ensure that fire detection and suppression systems for projects comply with relevant regulatory standards (such as NFPA 855 and UL 9540) • Review of 9540A test reports, discussion of applicability to system design constraints, and ensuring that system designs meet local and state requirements as required by authorities having jurisdiction (AHJs). • Collaborate closely with the energy design team to develop fire detection, suppression, and ventilation solutions. • Foster relationships with Fire Marshals, first responders, regulators, public utility commissions, and community stakeholders. • Conduct analyses including Hazard Mitigation Analysis (HMA), Failure Mode and Effects Analysis (FMEA), heat flux assessments, and CFD modeling. • Present findings and recommendations to decision-making committees, project teams, and industry groups. • Remain current with industry advancements, new energy storage chemistries and technologies, innovative techniques, and evolving best practices.

California
$140K - $165K / year
Spike logo

Junior Performance Engineer

Spike

Spike are retail technology experts delivering end-to-end, go-live confidence for the biggest retail brands.

Engineer29 days ago
Full TimeRemoteTeam 51-200Since 2015H1B No Sponsor

• Contribute to the successful delivery of performance testing across client projects • Execute performance engineering activities across the software delivery lifecycle • Apply agreed tools, standards, and approaches to ensure high‑quality outcomes • Develop your technical, consultancy, and client‑facing skills within a supportive environment • Build a strong foundation for progression within Spike’s Performance practice

United Kingdom
£30K - £55K / year
Job Closed
IRIUM logo

Ingeniero/a Google Cloud Platform

IRIUM

Líderes en gestión de servicios integrados de infraestructuras y plataformas IT.

Engineer29 days ago
Full TimeRemoteTeam 501-1,000Since 2002H1B No Sponsor

• Colaborar en un proyecto en modalidad full-remote.

Spain