The Lead Engineer, Identity Management is responsible for the design, engineering, and operational excellence of Sony Pictures Entertainment’s (SPE) enterprise Identity and Access Management (IAM) ecosystem, with a primary focus on Okta Identity Governance, Identity Lifecycle Management, Security Operations, and Identity Compliance initiatives.
This role leads the end-to-end engineering, configuration, and maintenance of SPE’s Identity Governance and Administration (IGA) platform, ensuring secure, compliant, and efficient management of digital identities across all user populations. The position requires deep expertise in Okta and its governance, access, and lifecycle capabilities, as well as the ability to define and enforce identity standards and policies that align with enterprise security and compliance objectives.
This role will be responsible for providing ongoing support, request fulfillment of the SPE’s IAM platform services, and provide escalation and support to internal application teams and IAM team members. This role also focuses on analyzing emerging authentication technologies to design and implement secure, intuitive, scalable, and reliable Access Management solutions that support SPE’s both internal and external users.
This role must have experience with Okta Identity Management platform.
Lead the design, implementation, and operations of the Okta IGA platform, including lifecycle management (Joiner–Mover–Leaver processes), access governance, and compliance controls.
Partner with business and security stakeholders to develop and enforce identity governance policies, ensuring adherence to corporate, regulatory, and audit requirements.
Manage directory services, including user provisioning, synchronization, and role-based access control (RBAC) models.
Provide a technical expertise to various application teams in Identity Access Management and governance, to include Single Sign On, MFA, Identity Federation, Lifecycle Management, Enterprise Directory architecture and design, and resource provisioning.
Experience in security and implementation of best practices such as least privilege, Privileged Access Management, passwordless authentication, etc.
Expertise in SSO, MFA, Federation, and directory integration (Active Directory, LDAP, and SCIM-based provisioning).
Hands-on experience with scripting and automation (e.g., PowerShell, Python, or REST APIs) for identity orchestration.
The anticipated base salary for this position is $138,000-$167,000. This role may also qualify for annual incentive and/or comprehensive benefits. The actual base salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location of the position.
Sony Pictures Entertainment is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status, age, sexual orientation, gender identity, or other protected characteristics.
SPE will consider qualified applicants with arrest or conviction records in accordance with applicable law.