We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Sr. IAM Engineer

Franchise World Headquarters, LLC
tuition reimbursement, 401(k)
United States, Connecticut, Shelton
1 Corporate Drive (Show on map)
Aug 07, 2026

Sr. IAM Engineer

Franchise World Headquarters, LLC

Shelton, CT

Why Join Subway?

At Subway, we are not standing still. We are building.

This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.

You will not just do the work. You will shape it.

We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.

If you bring energy, accountability and a bias for action, you will fit right in.

We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.

This is your chance to be part of what's next.

Position Overview

The Sr. IAM Engineer is a hands-on senior technologist responsible for engineering, securing, and evolving Subway's enterprise identity platform. Subway operates a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This role owns complex federation, provisioning, and access-governance problems end to end, treating identity infrastructure as software - version-controlled, tested, deployed through CI/CD pipelines, and observable in production. The Sr. IAM Engineer serves as a senior subject matter expert and co-owner of IAM technical direction, a technical mentor within the IAM team, and a trusted design partner to Cybersecurity, Infrastructure, and HR Technology.

Responsibilities

* Engineer and operate Okta as the enterprise identity broker - Universal Directory, lifecycle management, SSO integrations (SAML 2.0, OIDC, WS-Federation to Microsoft 365), and Okta Workflows; design and troubleshoot federation end to end including assertion and token contents, claim/attribute mapping, signing and encryption, and session behavior across Okta, Entra ID, Active Directory, and downstream SaaS applications.

* Maintain and enhance SCIM 2.0 provisioning at the protocol level - schemas, custom extensions, PATCH semantics, error handling, and reconciliation - between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, AWS IAM Identity Center, and Microsoft 365; own the hybrid attribute-mastering model and drive architectural changes that consolidate source-of-truth authority.

* Apply zero-trust principles and enforce least privilege across the estate: phishing-resistant MFA and passwordless authentication, continuous evaluation of session and device context, privileged access management (PAM) with time-bound and just-in-time elevation, separation of duties, and access-governance controls via Okta Identity Governance including access certification campaigns and self-service access requests.

* Secure identity for LLM and agentic AI systems - govern non-human identities, enforce scoped and short-lived credentials for agent access, apply human-in-the-loop authorization for sensitive actions; apply API security best practices including OAuth 2.0-protected API design, token validation and scoping, and defense against OWASP API Security Top 10 risks including BOLA/IDOR.

* Integrate endpoint security with identity on Windows and macOS: device trust and posture signals in authentication policy, Okta FastPass/Device Trust, Entra device compliance, EDR posture, platform SSO, desktop MFA, and device-bound phishing-resistant credentials.

* Design and implement joiner/mover/leaver automation driven by HRIS events; expand self-service access through the Okta access catalog and AWS IAM Identity Center permission-set-based self-service; build operational automation in PowerShell, Python, and bash; manage identity platform code in Git with peer-reviewed CI/CD pipelines and Terraform for identity-bearing cloud resources.

* Own day-to-day identity platform operations: SSO application setup, IAM incident resolution and root-cause analysis, upgrades, patching, MFA management, and access cleanup; query identity telemetry in CrowdStrike Falcon Next-Gen SIEM and operate identity threat detection and response with CrowdStrike Falcon Identity Protection; support internal and external audits with access evidence.

* Serve as a senior technical authority for IAM architecture and engineering decisions; develop and maintain identity architecture diagrams and configuration baselines; author technical design documents for significant automations and integrations prior to build; mentor IAM engineers and operations analysts; contribute to the strategic IAM roadmap and program maturity assessments.

Qualifications

* Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field - or equivalent work experience.

* 7+ years in identity and access management, identity engineering, or security engineering with substantial IAM scope, including senior or lead-level ownership of identity platforms.

* Deep, protocol-level expertise in OAuth 2.0 and OIDC (grant types, token lifecycles, PKCE, scopes and claims, bearer-token handling) and SAML 2.0 (assertions, metadata exchange, signing and encryption, SP- and IdP-initiated flows).

* Hands-on expertise with Okta as an enterprise identity broker: Universal Directory, lifecycle management, Okta Workflows, SSO application integration, and SCIM provisioning; Okta Identity Governance experience strongly preferred.

* Demonstrated application of zero-trust architecture and least-privilege access design in a production enterprise environment.

* Advanced Active Directory design and administration in a hybrid IDaaS environment: OU and group strategy, GPO design, and tiered administration models; advanced Microsoft Entra ID policy design including Conditional Access, Identity Protection risk policies, and MFA policy.

* Expert, protocol-level SCIM 2.0 knowledge - core and enterprise schemas, custom schema extensions, PATCH semantics, and provisioning error handling.

* Strong grounding in API security: OAuth 2.0-protected API design, token validation and scoping, and the OWASP API Security Top 10 including BOLA/IDOR vulnerabilities.

* Experience securing or governing identity for LLM and agentic AI systems: non-human identity lifecycle, credential scoping for AI agents, and least-privilege controls on machine-to-machine access.

* Proficiency with CrowdStrike Falcon Identity Protection (ITDR, risk-based policy enforcement) or a comparable ITDR platform; experience querying identity telemetry in an enterprise SIEM.

* Experience integrating endpoint security with identity on Windows and macOS: device posture signals in access policy, platform SSO/desktop MFA, and MDM integration (Jamf, Intune, or equivalent).

* Proficient scripting in PowerShell, Python, and bash; DevOps fluency including Git-based source control and CI/CD pipeline authorship (Azure Pipelines or GitHub Actions).

* 1+ year of experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, SuccessFactors, UKG, or similar).

Preferred Qualifications

* Direct Ceridian Dayforce REST API experience (XRefCode addressing, position management, employment-status events).

* AWS IAM and AWS IAM Identity Center experience, particularly permission-set-based access management.

* Exposure to dedicated IGA tooling (SailPoint, Saviynt, Omada) at design or implementation level.

* Familiarity with NIST SP 800-63 (digital identity assurance) and NIST SP 800-207 (zero trust architecture).

* Background in regulated, franchise, or multi-entity environments where identity governance crosses organizational boundaries.

* Relevant certifications: Okta Certified Professional/Consultant, CISSP, SC-300, or AWS Security Specialty.

What do we offer?

* Insurance Plans (Medical, Life)

* Pension/401K/RSP (country specific)

* Competitive Bonus

* Mobility Allowance

* Tuition Reimbursement

* Company Holidays

* Volunteering time

* And More.....

Applied = 0

(web-77cf7d65c7-wz29x)