Senior Corporate Engineer II responsible for the architecture of security-critical platforms at Instacart. Collaborating with engineering teams to enhance identity and access management infrastructure.
Responsibilities
Own the architecture, security, and day-to-day operations of our enterprise Okta tenant, including delivery of Okta Identity Governance (OIG), lifecycle management, SCIM provisioning, SSO integrations (SAML/OIDC), MFA, risk-based policies, and device trust.
Design and maintain Infrastructure-as-Code for identity and access using Terraform, building reusable modules, guardrails, and automated workflows integrated with HRIS and ITSM systems to achieve least-privilege and timely provisioning/deprovisioning.
Architect, operate, and continuously improve Instacart’s office network infrastructure (firewalls, routing/switching, wireless) across SF, NYC, and Toronto; drive zero-trust segmentation, observability, capacity planning, and vendor/partner management.
Lead and participate in incident response for identity and network events, drive rapid mitigation and root-cause analysis, and implement durable remediations through post-incident reviews and change management.
Standardize and execute certificate and key lifecycles for SAML/TLS across SaaS applications; eliminate manual toil with scripting and robust runbooks that increase reliability and auditability.
Partner with Security and Compliance to meet controls and audit needs (e.g., access reviews, evidence collection), improve access risk management, and unlock license savings via automated revocation and right-sizing.
Mentor teammates, elevate documentation and operational excellence, and help shape the roadmap by prioritizing high-impact work in a rapidly evolving environment.
Requirements
7+ years of experience in corporate IT engineering or a related field with a focus on identity and access management (IAM) and enterprise networking.
3+ years of hands-on administration of Okta in production (1,000+ users), including SSO integrations (SAML/OIDC), SCIM provisioning, MFA, and policy design.
2+ years implementing identity governance and automation using Okta Workflows, Okta Identity Governance (OIG), or an equivalent IGA platform.
Proficiency with Infrastructure-as-Code and automation: Terraform (required) and at least one scripting language (Python, Bash, or PowerShell).
Demonstrated experience planning and executing certificate rotations and key management for SAML/TLS across multiple SaaS applications.
Hands-on experience operating and troubleshooting office network infrastructure (switching, routing, wireless, firewalls) and VPN/zero-trust access using technologies such as Cisco/Meraki, Aruba, and Palo Alto.
Proven track record leading critical incidents and executing structured change management, including authoring runbooks and conducting post-incident reviews.
Working knowledge of endpoint management and device trust (e.g., Jamf, Kandji, Intune) and integrating device posture into access controls.
Bachelor’s degree in Computer Science, Engineering, Information Systems, or equivalent practical experience.
Environmental Engineer/Geoscientist at a forensic engineering firm in Halifax. Responsible for overseeing environmental investigations and liaising with clients.
Senior Project Engineer overseeing capital project execution for Agropur in Bedford, Nova Scotia. Leading multidisciplinary teams and ensuring alignment with business objectives in a fast - paced environment.
Lead Verification Engineer developing high - performance physical IP at Cadence. Responsible for digital RTL verification and developing re - usable verification components and environments.
Senior Digital Verification Engineer at Ciena focusing on implementing innovative strategies for validating Forward Error Correction IP subsystems. Collaborating with design engineers to ensure functional integrity.
Ingénieur(e) en mécanique du bâtiment concevant des systèmes (plomberie, chauffage, ventilation). Coordination des projets dans le cadre du développement des trains à grande vitesse au Canada.
Lead Release Train Engineer managing Agile delivery systems for financial services. Fostering collaboration, continuous improvement, and alignment between strategy and execution.
Data Engineer managing data ingestion, modeling, and reporting using Microsoft Fabric at BDO. Collaborating with stakeholders and maintaining pipelines, reports, and documentation.
Project Engineer coordinating project activities and engineering deliverables for mining projects at Sedgman, based in Vancouver. Involves diverse projects from feasibility studies to construction.
Engineer architecting and building AI - powered products at an AI - first company. Join a dynamic startup with a mission to empower everyone in drafting legal documents using AI.