instacart.careers

instacart.careers

Instacart is a leading grocery technology company in North America that works with grocers and retailers to transform how people shop. They partner with over 1,000 national, regional, and local retail banners to facilitate online shopping, delivery, an...

Internet Software & Services
1K-5K

Description

  • Own the architecture, security, and day-to-day operations of the enterprise Okta tenant.
  • Implement and maintain Okta Identity Governance, lifecycle management, SCIM provisioning, SSO integrations, MFA, risk-based policies, and device trust.
  • Design and maintain Infrastructure-as-Code for identity and access using Terraform, including reusable modules, guardrails, and automated workflows.
  • Integrate identity automation with HRIS and ITSM systems to support least-privilege access and timely provisioning and deprovisioning.
  • Architect, operate, and continuously improve office network infrastructure across San Francisco, New York City, and Toronto.
  • Drive zero-trust segmentation, observability, capacity planning, and vendor and partner management for office networking.
  • Lead incident response for identity and network events, including mitigation, root-cause analysis, and durable remediation.
  • Standardize certificate and key lifecycles for SAML and TLS across SaaS applications and reduce manual toil through scripting and runbooks.
  • Partner with Security and Compliance on access reviews, evidence collection, access risk management, and license optimization.
  • Mentor teammates, improve documentation and operational excellence, and help prioritize the team roadmap.

Requirements

  • 7+ years of experience in corporate IT engineering or a related field with a focus on IAM and enterprise networking.
  • 3+ years of hands-on Okta administration in production environments with 1,000+ users.
  • Experience with SSO integrations using SAML and OIDC, SCIM provisioning, MFA, and policy design.
  • 2+ years implementing identity governance and automation using Okta Workflows, Okta Identity Governance, or an equivalent IGA platform.
  • Proficiency with Terraform and at least one scripting language such as Python, Bash, or PowerShell.
  • Experience planning and executing certificate rotations and key management for SAML and TLS across multiple SaaS applications.
  • Hands-on experience with office network infrastructure, including switching, routing, wireless, firewalls, VPN, and zero-trust access.
  • Experience with technologies such as Cisco/Meraki, Aruba, and Palo Alto.
  • Working knowledge of endpoint management and device trust tools such as Jamf, Kandji, or Intune.
  • Bachelor’s degree in Computer Science, Engineering, Information Systems, or equivalent practical experience.
  • Okta certifications such as Administrator, Professional, or Consultant are preferred.
  • Networking or security certifications such as CCNP or PCNSE are preferred.
  • Experience building Git-based CI/CD pipelines for identity and network automation, such as GitHub Actions or CircleCI, is preferred.
  • Familiarity with compliance frameworks and audits such as SOX, SOC 2, and ISO 27001 is preferred.
  • Experience administering Google Workspace and/or Microsoft 365 identity and security configurations at scale is preferred.
  • Exposure to secrets management, PKI, and monitoring tools such as HashiCorp Vault, AWS KMS, Datadog, or Splunk is preferred.
  • Strong cross-functional communication skills and experience leading complex multi-stakeholder projects are preferred.

Benefits

  • Highly market-competitive compensation.
  • Base salary range of $148,000 to $156,000 CAD for Canadian candidates.
  • Eligible for a new hire equity grant.
  • Eligible for annual refresh grants.
  • Flexible remote work under Instacart’s Flex First policy.
  • Remote-friendly hiring within Canada, with current hiring in Ontario, Alberta, British Columbia, and Nova Scotia.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

CNAPP Cloud Security Engineer (Remote) - Northeast region

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring a CNAPP Cloud Security Engineer to help customers design, implement, and operate cloud security tooling and controls across multi-cloud environments.

AWS Azure CI/CD CloudFormation GCP Jenkins JSON Kubernetes Microservices PowerShell Python Terraform
20 minutes ago

Associate - Security

TEECOM 51-250 Construction & Engineering

TEECOM is hiring an Associate in Security to support remote project delivery for technology systems projects, owning discipline-specific deliverables and contributing to coordinated design work across client and project teams.

Asana GitHub
1 hour, 6 minutes ago

Blockchain Security AI Application Support Engineer

Crypto.com 1K-5K Capital Markets

Crypto.com is hiring a Blockchain Security AI Application Support Engineer in Warsaw to support production blockchain applications and infrastructure, with a focus on stability, incident response, and support automation.

Blockchain Encryption Go LLM Node.js Python Rust Solana
3 hours, 17 minutes ago

Systems & AI Cloud Architect

Endeavour. Inspired Infrastructure. 11-50 Electric Utilities

Endeavour is seeking a remote Systems & AI Cloud Architect to support its IT ecosystem by shaping enterprise architecture, modernizing infrastructure, and enabling scalable AI and cloud solutions for sustainable infrastructure initiatives.

AWS Azure CI/CD Cybersecurity GCP Generative AI Machine Learning Microservices MLOps
5 hours, 26 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers