instacart.careers

instacart.careers

Instacart is a leading grocery technology company in North America that works with grocers and retailers to transform how people shop. They partner with over 1,000 national, regional, and local retail banners to facilitate online shopping, delivery, an...

Internet Software & Services
1K-5K

Description

  • Own the architecture, security, and day-to-day operations of the enterprise Okta tenant and related identity systems.
  • Implement and maintain Okta Identity Governance, lifecycle management, SCIM provisioning, SSO integrations, MFA, risk-based policies, and device trust.
  • Design and maintain Infrastructure-as-Code for identity and access workflows using Terraform.
  • Build automated provisioning and deprovisioning workflows integrated with HRIS and ITSM systems to support least-privilege access.
  • Architect, operate, and improve office network infrastructure across San Francisco, New York City, and Toronto.
  • Drive zero-trust segmentation, observability, capacity planning, and vendor and partner management for office networking.
  • Lead incident response for identity and network events, including mitigation, root-cause analysis, and durable remediation.
  • Standardize certificate and key lifecycles for SAML and TLS across SaaS applications and reduce manual toil through scripting and runbooks.
  • Partner with Security and Compliance on access reviews, evidence collection, access risk management, and license optimization.
  • Mentor teammates, improve documentation and operational excellence, and help prioritize the team roadmap.

Requirements

  • 7+ years of experience in corporate IT engineering or a related field focused on IAM and enterprise networking.
  • 3+ years of hands-on Okta administration in production environments with 1,000+ users.
  • Experience with SSO integrations using SAML and OIDC, SCIM provisioning, MFA, and policy design.
  • 2+ years implementing identity governance and automation using Okta Workflows, Okta Identity Governance, or an equivalent IGA platform.
  • Proficiency with Terraform and at least one scripting language such as Python, Bash, or PowerShell.
  • Experience planning and executing certificate rotations and key management for SAML and TLS across multiple SaaS applications.
  • Hands-on experience with office network infrastructure including switching, routing, wireless, firewalls, and VPN or zero-trust access.
  • Experience with device management and device trust tools such as Jamf, Kandji, or Intune.
  • Proven track record leading critical incidents, writing runbooks, and managing structured change processes.
  • Bachelor’s degree in Computer Science, Engineering, Information Systems, or equivalent practical experience.
  • Okta certifications or networking/security certifications such as CCNP or PCNSE are preferred.
  • Experience building Git-based CI/CD pipelines and implementing policy-as-code is preferred.
  • Familiarity with compliance frameworks such as SOX, SOC 2, and ISO 27001 is preferred.
  • Experience administering Google Workspace or Microsoft 365 identity and security configurations at scale is preferred.
  • Exposure to secrets management, PKI, and monitoring tools such as HashiCorp Vault, AWS KMS, Datadog, or Splunk is preferred.
  • Strong cross-functional communication skills and experience leading complex multi-stakeholder projects are preferred.

Benefits

  • Highly market-competitive compensation.
  • Base salary range of $187,000-$197,500 USD in CA, NY, CT, and NJ; $179,000-$189,000 USD in WA; $172,000-$181,500 USD in several other listed states; and $156,000-$164,500 USD in all other states.
  • Remote-friendly Flex First work policy.
  • Eligible for a new hire equity grant.
  • Eligible for annual refresh equity grants.
  • Flexible work location within North America, with regular in-person connection opportunities.
  • Benefits offerings available through Instacart's employee benefits program.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Lead Security Engineer, Enterprise Security

Klaviyo 1K-5K IT Services

Klaviyo is hiring a Lead Security Engineer to secure its corporate systems and platforms across SaaS, identity, endpoints, Zero Trust networking, and perimeter security.

AWS Azure Cloudflare CrowdStrike GCP OAuth Secrets Management Terraform Vercel
9 minutes ago

Head of Classified Infrastructure, Frontier Systems

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is seeking a senior security leader for its Frontier Systems team to shape and execute classified infrastructure and information security strategy for defense and intelligence programs.

Cybersecurity Penetration Testing
1 hour, 30 minutes ago

Staff Security Engineer

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Security Engineer to secure its OT and ICS environments and help design foundational defenses for advanced defense technology and factory systems.

Go Linux Python Rust
1 hour, 30 minutes ago

Senior Security Engineering Manager, Enterprise Security

Upstart 1K-5K Banks

Upstart is hiring a Senior Security Manager to lead enterprise security engineering efforts that reduce risk across corporate systems, cloud environments, and security operations.

AWS CI/CD Kubernetes SIEM
1 hour, 45 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers