Senior Identity and Access Management Engineer

Charger Logistics Inc — Canada · Posted ~4 hours ago

Senior Full-time

Skills

IAM Okta Microsoft Entra ID SSO SCIM identity governance GCP

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior IAM engineering role focused on securing identities, access controls, and authentication platforms. The position involves managing identity systems and establishing governance for users, applications, and automated agents.

Highlights

Opportunity to lead identity security initiatives across human and machine identities in a growing technology environment.

Description

Charger logistics Inc. is a world- class asset-based carrier with locations across North America. With over 20 years of experience providing the best logistics solutions, Charger logistics has transformed into a world-class transport provider and continue to grow. Senior IAM Engineer - Non-Human & AI Agent Identity We are looking for a highly motivated Senior IAM Engineer to join our team based out of our Brampton office and own identity security for both people and AI agents across our company. We run Okta alongside Microsoft Entra ID, and we're extending that setup to a fast-growing number of non-human identities: AI agents, bots, service accounts and machine credentials. You'll set the standards, run the platforms, and decide how every agent in the company signs in, what it's allowed to do, and how it gets shut off. Responsibilities: Own our Okta environment end to end: SSO, SCIM provisioning, Identity Governance and Privileged Access.Roll out and run Okta's AI agent capabilities, including Agent SSO, Cross App Access (XAA/MCP patterns) and lifecycle governance for agents.Lead discovery of all non-human identities through Identity Security Posture Management (ISPM): service accounts, API keys, tokens and unsanctioned "shadow" AI agents. Own the baseline inventory.Set and enforce our agent identity standards: a dedicated identity for each autonomous workload, a named human owner, least-privilege access, short-lived credentials and no shared logins.Build credential vaulting, rotation and zero-standing-privilege patterns for machine identities.Own incident containment for agent identities, including a central token-revocation "kill switch."Connect identity across Okta, Entra ID and Google Cloud IAM, working with our platform team on agent identity in GCP.Write the developer-facing standards: how teams request an agent identity, what they get, and what's not allowed. Requirements 5+ years in identity and access management, with deep hands-on Okta administration. An Okta Certified Professional, Administrator or Consultant certification is a strong plus.Strong working knowledge of Entra ID (Azure AD) in a hybrid environment.A deep understanding of how OAuth 2.0, OIDC and SAML actually work, beyond configuring them.Experience managing non-human identities: service accounts, secrets, API keys and workload identity.Hands-on experience with identity governance, privileged access management and SCIM lifecycle automation, on Okta or comparable platforms (e.g., SailPoint, CyberArk, BeyondTrust, HashiCorp Vault).Python or PowerShell scripting against identity APIs. Nice to Have Exposure to AI agent identity: Okta for AI Agents, Microsoft Entra Agent ID, SPIFFE/SPIRE, or MCP/agent authorization patterns.Experience with non-human identity security tools such as Oasis, Astrix, Token Security or Aembit.Google Cloud IAM or workload identity federation.Infrastructure-as-code for identity, such as Terraform for Okta or Okta Workflows.Zero-trust access tools such as Zscaler, Cloudflare or Tailscale.Experience in transportation, logistics, supply chain or another 24/7 operations environment. Benefits Competitive Salary Healthcare Benefit Package Career Growth