How you can help make a better world of work
As our Identity & Access Management Engineer, you’ll help keep Culture Amp secure, connected, and easy to work in. You’ll own the day-to-day administration and continuous improvement of our identity and access environment, with a focus on Okta, application integrations, lifecycle automation, and identity governance. Your work will help ensure that every Camper has the right access at the right time, while strengthening our audit readiness and reducing manual effort across the business.
As part of this team of amazing humans,
You’ll work across Technology and with stakeholders throughout Culture Amp to make identity and access processes reliable, secure, and straightforward. You’ll bring a practical, automation-oriented approach to managing the systems that enable Campers to do their best work.
You will
- Manage day-to-day identity and access administration in Okta, including provisioning, deprovisioning, MFA resets, application access requests, and authentication, session, and device trust policies.
- Full lifecycle management of SaaS applications and maintain existing SAML, SCIM, and OIDC configurations and group mappings as Culture Amp’s technology environment evolves.
- Build and own joiner, mover, and leaver workflows end to end, including automated pipelines using Okta Workflows, APIs, and SCIM to connect the HRIS to Okta.
- Configure, deploy, and continuously improve Okta Identity Governance, including access request workflows and self-service or automated approval paths aligned to access policy.
- Support audit and compliance activities by automating access certification reporting, gathering system and directory log evidence for SOC 2 and ISO 27001 audits, and reviewing inactive SaaS licences and unapproved OAuth integrations.
- Contribute to configuration, optimisation and troubleshooting for other ancillary platforms as required, such as Google Workspace, Active Directory / MS Entra, Island & Jamf.
You have
- Hands-on experience administering Okta or a similar identity provider, including SAML, SCIM, OIDC, MFA, lifecycle policies, and authentication, session, and device trust policies.
- Proven experience onboarding SaaS applications end to end, including SSO setup, SCIM attribute and group mapping, and troubleshooting provisioning issues.
- Experience with Okta Identity Governance or equivalent access request and identity governance tooling.
- Experience building identity lifecycle automation pipelines that connect HRIS systems to an identity provider using tools such as Okta Workflows, APIs, or SCIM.
- Familiarity with SaaS governance practices, including access certification, audit evidence, licence utilisation reviews, and OAuth or shadow IT detection.
- Familiarity with SaaS platforms, cloud providers, networking fundamentals and device management.
You are
- Security-minded and thoughtful about balancing strong access controls with a simple experience for end users.
- Comfortable owning operational systems, troubleshooting issues, and improving processes rather than relying on manual workarounds.
- A clear communicator who can work pragmatically with technical and non-technical stakeholders.
- A systems thinker, who will understand the end to end picture and not just complete the task that’s in front of them.