instacart.careers

instacart.careers

Instacart is a leading grocery technology company in North America that works with grocers and retailers to transform how people shop. They partner with over 1,000 national, regional, and local retail banners to facilitate online shopping, delivery, an...

Internet Software & Services
1K-5K

Description

  • Own the architecture, security, and day-to-day operations of the enterprise Okta tenant and related identity systems.
  • Implement and maintain Okta Identity Governance, lifecycle management, SCIM provisioning, SSO integrations, MFA, risk-based policies, and device trust.
  • Design and maintain Infrastructure-as-Code for identity and access workflows using Terraform.
  • Build automated provisioning and deprovisioning workflows integrated with HRIS and ITSM systems to support least-privilege access.
  • Architect, operate, and improve office network infrastructure across San Francisco, New York City, and Toronto.
  • Drive zero-trust segmentation, observability, capacity planning, and vendor and partner management for office networking.
  • Lead incident response for identity and network events, including mitigation, root-cause analysis, and durable remediation.
  • Standardize certificate and key lifecycles for SAML and TLS across SaaS applications and reduce manual toil through scripting and runbooks.
  • Partner with Security and Compliance on access reviews, evidence collection, access risk management, and license optimization.
  • Mentor teammates, improve documentation and operational excellence, and help prioritize the team roadmap.

Requirements

  • 7+ years of experience in corporate IT engineering or a related field focused on IAM and enterprise networking.
  • 3+ years of hands-on Okta administration in production environments with 1,000+ users.
  • Experience with SSO integrations using SAML and OIDC, SCIM provisioning, MFA, and policy design.
  • 2+ years implementing identity governance and automation using Okta Workflows, Okta Identity Governance, or an equivalent IGA platform.
  • Proficiency with Terraform and at least one scripting language such as Python, Bash, or PowerShell.
  • Experience planning and executing certificate rotations and key management for SAML and TLS across multiple SaaS applications.
  • Hands-on experience with office network infrastructure including switching, routing, wireless, firewalls, and VPN or zero-trust access.
  • Experience with device management and device trust tools such as Jamf, Kandji, or Intune.
  • Proven track record leading critical incidents, writing runbooks, and managing structured change processes.
  • Bachelor’s degree in Computer Science, Engineering, Information Systems, or equivalent practical experience.
  • Okta certifications or networking/security certifications such as CCNP or PCNSE are preferred.
  • Experience building Git-based CI/CD pipelines and implementing policy-as-code is preferred.
  • Familiarity with compliance frameworks such as SOX, SOC 2, and ISO 27001 is preferred.
  • Experience administering Google Workspace or Microsoft 365 identity and security configurations at scale is preferred.
  • Exposure to secrets management, PKI, and monitoring tools such as HashiCorp Vault, AWS KMS, Datadog, or Splunk is preferred.
  • Strong cross-functional communication skills and experience leading complex multi-stakeholder projects are preferred.

Benefits

  • Highly market-competitive compensation.
  • Base salary range of $187,000-$197,500 USD in CA, NY, CT, and NJ; $179,000-$189,000 USD in WA; $172,000-$181,500 USD in several other listed states; and $156,000-$164,500 USD in all other states.
  • Remote-friendly Flex First work policy.
  • Eligible for a new hire equity grant.
  • Eligible for annual refresh equity grants.
  • Flexible work location within North America, with regular in-person connection opportunities.
  • Benefits offerings available through Instacart's employee benefits program.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Operations Engineer

Mozilla 251-1K Internet Software & Services

Mozilla is hiring a Staff Operations Engineer to lead the design, reliability, and evolution of hybrid-cloud and workplace infrastructure across teams.

Ansible DNS Linux Puppet Python TCP/IP Unix
7 hours, 43 minutes ago

Saviynt IAM Specialist

The Missing Link 51-250 Internet Software & Services

The Missing Link is seeking a Security Engineer - Saviynt to support large enterprise identity governance initiatives, design and deliver Saviynt-based solutions, and strengthen its growing cyber security practice.

Active Directory Azure Cybersecurity JavaScript PowerShell REST API SAP SQL
7 hours, 43 minutes ago

AI Security Architect (REMOTE - United States)

EnableComp 251-1K Insurance

EnableComp is seeking a remote AI Security Architect to secure and govern its AI and machine learning initiatives within its healthcare revenue cycle management environment.

Azure Cybersecurity HIPAA LLM Machine Learning
7 hours, 58 minutes ago

Senior Infrastructure Security Engineer

Dropbox 1K-5K Internet Software & Services

Dropbox is hiring a Security Engineer to secure its AI and agentic infrastructure while helping protect products and users across cloud and on-prem environments.

Bash CI/CD CrowdStrike Go Java Kubernetes Linux LLM Node.js OAuth OpenID Connect OWASP Python Ruby Rust SIEM
7 hours, 58 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers