.
Identity & Access Management (IAM) Engineer
  • Kraków
Identity & Access Management (IAM) Engineer
Kraków, Kraków, Lesser Poland Voivodeship, Polska
StoneX Financial LTD Sp. z o.o. Oddział w Polsce
29. 1. 2025
Informacje o stanowisku

Identity & Access Management (IAM) Engineer

Miejsce pracy: Kraków

Technologies we use

Expected

  • Okta
  • OIDC
  • SAML

Optional

  • CIAM
  • CISA
  • CAMS
  • C#
  • .NET

Operating system

  • Windows

About the project

StoneX requires the expertise of an Okta Contractor to support internal software development and platform engineering teams in implementing advanced Okta configurations, enhancing security, and automating identity workflows. This engagement will focus on securing and scaling identity solutions across workforce and customer applications while ensuring that operational and development teams are trained in best practices. In this role, you will take an important part in optimizing, securing, and scaling our Okta platform, ensuring it remains a robust foundation for millions of interactions. Our journey is also one of governance, as we contribute to efforts that ensure our platforms meet industry standards and regulatory requirements.

Your responsibilities

  • Develop and configure Okta Workflows to streamline the setup of OpenID Connect applications, including the creation of associated groups, assigning administrative roles, and setting up custom authorization servers with scoped security.
  • Create workflows to automate the integration of third-party identity providers and provide troubleshooting assistance for federation-related issues.
  • Support development teams in implementing OpenID Connect auth flows using Okta SDKs.
  • Offer guidance to ensure client-facing apps are both efficient and secure, utilizing CIAM (Customer Identity and Access Management) best practices.
  • Assist with maturing StoneX’s Okta workforce tenants, including transitioning from static to risk-based authentication policies and roll out of passwordless authentication flows.
  • Assist internal software development teams in implementing customer-friendly UX for the upcoming flagship app, covering features such as MFA enrollment, registration flows, lockout handling, step-up authentication, and session management.
  • Collaborate with development teams to design a scalable, secure model for Okta auth server configurations. Educate teams on necessary auth server changes and guide them through the migration process, ensuring alignment with secure downstream API consumption.
  • Develop training materials on new Okta functionalities to operational, identity-focused teams.
  • Educate operational teams on best practices for application health monitoring and SCIM integrations, especially for applications currently lacking provisioning capabilities.
  • Work with the Platform Engineering team to build an IaC repository to automate Okta application lifecycle management, including app creation, group management, and policy configuration.
  • Support the migration of StoneX’s internal M2M (machine-to-machine) authorization platform to use Okta client credentials flow for OIDC applications.
  • Assist with the migration of applications currently using Entra for Single Sign-On (SSO) to Okta, ensuring minimal disruption and secure integration.

Our requirements

You need to have a history of being self-motivated and capable of solving problems with minimal oversight. The ability to learn quickly and retain information is key to being successful in this role. You have strong experience working in a competitive, fast-paced, highly technical environment, ideally in the Financial Services industry. You must have a proven ability to establish structure, process and frameworks to operate at scale.

•3+ years of experience engineering and deploying custom app integrations and new functionalities in Okta (SAML/OpenID Connect).

•5+ years of experience in the identity management space.

•Possess a high level of attention to detail and accuracy.

•Experience with automation and/or scripting using Okta APIs.

•Experience with Okta Workflows Engine.

•Experience with implementing Okta with customer identity (CIAM) use cases.

•Strong experience with OIDC auth flows and custom authorization server configuration.

•Must possess a strong ability to document standards and processes.

•Ability to manage multiple competing priorities, and work effectively under the pressure of time constraints in a fast-paced, collaborative environment.

•Ability to work independently and manage workload with minimal supervision.

Education / Certification requirements: in at least one of or working towards the following:

•Bachelors degree in computer science, Information Security, or related field.

•Okta Certified Developer – Workforce Identity Cloud certification (required).

•Okta Certified Administrator (optional, highly desired).

•Okta Certified Professional certification (optional, highly desired).

Optional

  • Desired experience with object-oriented programming languages with emphasis on C# / .NET.
  • Relevant industry certifications such as CIAM, CISA, CAMS (desired).
  • Other appropriate field certifications may be considered.

This is how we organize our work

This is how we work

  • in house
  • you focus on a single project at a time
  • you develop several projects simultaneously
  • you can change the project
  • you have influence on the product
  • you focus on product development

Team members

  • architect
  • product owner
  • business analyst

This is how we work on a project

  • documentation
  • testing environments

Development opportunities we offer

  • development budget
  • industry-specific e-learning platforms
  • intracompany training
  • mentoring
  • substantive support from technological leaders
  • technical knowledge exchange within the company
  • time for development of your ideas

What we offer

  • Remote (1-2 travels to Cracow per month)
  • Length of contract - 6 to 12 months

Benefits

  • sharing the costs of sports activities
  • private medical care
  • sharing the costs of professional training & courses
  • life insurance
  • remote work opportunities
  • flexible working time
  • fruits
  • corporate products and services at discounted prices
  • integration events
  • parking space for employees

Business Segment Overview:

  • Engage in a deep variety of business-critical activities that keep our company running efficiently. From strategic marketing and financial management to human resources and operational oversight, you’ll have the opportunity to optimize processes and implement game-changing policies.

StoneX Financial LTD Sp. z o.o. Oddział w Polsce

With 4,300 employees and over 400,000 retail and institutional clients from more than 80 offices spread across five continents, we’re a Fortune-100, Nasdaq-listed provider, connecting clients to the global markets – focusing on innovation, human connection, and providing world-class products and services to all types of investors.

Whether you want to forge a career connecting our retail clients to potential trading opportunities, or ingrain yourself in the world of institutional investing, The StoneX Group is made up of four segments that offer endless potential for progression and growth.

Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez StoneX Financial LTD Sp. z o.o. oddział w Polsce z siedzibą w: Szlak 49, 31-153 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu.
Twoje dane osobowe będą przetwarzane w oparciu o następujące podstawy prawne: (a) aby podjąć działania na Twoje żądanie przed zawarciem umowy (np. informacje o oczekiwanym wynagrodzeniu i dostępności do rozpoczęcia pracy); (b) w oparciu o nasz prawnie uzasadniony interes (np. imię, nazwisko, data urodzenia, dane kontaktowe, wykształcenie, kwalifikacje zawodowe, przebieg dotychczasowego zatrudnienia); c) w oparciu o Twoją zgodę, która wyrażona jest poprzez przeslanie dokumentów aplikacyjnych zawierających takie informacje jak np. wizerunek czy zainteresowania.
Podanie wszystkich danych osobowych, o których mowa powyżej jest dobrowolne, natomiast dane wymienione w lit. a) i b) są niezbędne do wzięcia udziału w rekrutacji. Niepodanie danych skutkuje brakiem możliwości rozpatrzenia kandydatury. Podanie pozostałych danych jest dobrowolne, ale może pomóc w sprawnym przeprowadzeniu procesu rekrutacji.
Masz prawo żądać dostępu do Twoich danych (w tym uzyskania ich kopii), sprostowania danych, ich usunięcia, ograniczenia przetwarzania, przeniesienia, jak również wniesienia sprzeciwu wobec ich przetwarzania. Masz także prawo wniesienia skargi do Prezesa Urzędu Ochrony Danych Osobowych.
Twoje dane osobowe mogą zostać przekazane dostawcom usługi publikacji ogłoszeń o pracę, dostawcom systemów do zarządzania rekrutacjami, dostawcom usług IT (hosting), dostawcom systemów informatycznych.
Podane przez Ciebie dane osobowe nie będą wykorzystywane w celu profilowania albo podejmowania decyzji w sposób zautomatyzowany.
Twoje dane osobowe będą przetwarzane przez okres maks. 1 roku od zakończenia publikacji ogłoszenia, chyba, że wyraziłeś odrębną zgodę na wykorzystanie Twoich danych osobowych w przyszłych rekrutacjach.
W celu realizacji praw lub w przypadku jakichkolwiek pytań związanych z przetwarzaniem Twoich danych osobowych skontaktuj się z nami pod adresem: monika.antczak@stonex.com.

  • Praca Kraków
  • Kraków - Oferty pracy w okolicznych lokalizacjach


    84 430
    14 887