IAM Engineer
Shelton, CT - USA
Job Summary
IAM Engineer
Franchise World Headquarters LLC
Shelton CT
Why Join Subway
At Subway we are not standing still. We are building.
This is a business focused on what matters most: growing franchisee profitability strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.
You will not just do the work. You will shape it.
We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.
If you bring energy accountability and a bias for action you will fit right in.
We take the work seriously but we also know the best results come from teams that support each other celebrate wins and show up ready to build something better every day.
This is your chance to be part of whats next.
Position Overview
The IAM Engineer builds and operates the day-to-day identity and access management capabilities that keep Subways workforce productive and secure. Subway runs a modern broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider which federates and provisions access across a hybrid estate spanning Active Directory Microsoft Entra ID Microsoft 365 ServiceNow AWS IAM Identity Center and a broad SaaS portfolio. This is a hands-on operational and engineering role owning the daily health of the identity platform while building the automation that steadily retires manual work. The role carries a clear development path toward senior-level identity engineering including deeper federation and protocol work access governance identity threat detection and security architecture.
Responsibilities
Operate the identity platform day to day: new SSO application setup access request fulfillment and escalations MFA management group and access cleanup and account lifecycle corrections; troubleshoot provisioning and authentication issues end to end SCIM sync failures attribute mismatches SSO errors performing root-cause analysis and documenting resolutions as runbooks.
Handle complex onboarding offboarding and HR-driven downstream changes outside automated lifecycle flows treating offboarding as security-critical work; manage IAM tickets and service requests in ServiceNow meeting SLA targets; serve as an internal escalation point for complex identity issues from the Technology Support Center and business teams.
Build Okta Workflows for identity lifecycle events application provisioning and remediation tasks; expand the Okta access catalog to convert recurring ticket categories into governed self-service with owner/manager approval; implement joiner/mover/leaver automation driven by HRIS events; contribute to AWS access self-service through AWS IAM Identity Center permission sets.
Script operational automation in PowerShell or Python reconciliation reporting cleanup and provisioning tasks; participate in upgrades patching and change tickets for identity infrastructure and the teams shared on-call rotation.
Operate SCIM 2.0 provisioning between Ceridian Dayforce Okta and downstream systems including Active Directory Entra ID ServiceNow Jamf Microsoft 365 and AWS IAM Identity Center; support the transition off a legacy custom SCIM connector to broker-native provisioning; configure SSO integrations (SAML 2.0 OIDC) for new applications.
Apply least-privilege principles in daily access work right-sized group and role assignments time-bound privileged access and cleanup of dormant or over-privileged accounts; support Okta Identity Governance operations including access certification campaigns; administer non-human identities and service accounts for LLM and agentic AI integrations applying least-privilege credential-scoping patterns.
Collaborate with the broader Cybersecurity engineering teams on shared projects; assist investigations of access anomalies alongside senior engineers and the Detect & Respond team; support internal and external audits with access evidence; author and maintain runbooks knowledge-base articles and hand-off documentation for new automations.
Qualifications
Bachelors degree in Computer Science Information Technology Cybersecurity or a related field or equivalent work experience.
35 years in IAM identity operations systems administration with significant identity scope or a related security/infrastructure role.
Hands-on experience with Okta or a comparable identity provider: user and group administration application SSO integration and lifecycle management; Okta strongly preferred.
Working knowledge of SSO and federation protocols SAML 2.0 OIDC and OAuth 2.0 fundamentals sufficient to configure and troubleshoot integrations.
Working knowledge of SCIM provisioning concepts and troubleshooting: attribute mapping sync errors and reconciliation.
Active Directory fundamentals (users groups OUs group policy awareness) and familiarity with Microsoft Entra ID and Microsoft 365 administration.
Scripting proficiency in PowerShell or Python for operational automation (both plus bash preferred).
Experience working with REST APIs: authentication reading API documentation and basic troubleshooting of API-driven integrations.
Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.
Comfort working with Git-based source control and participating in CI/CD-based change processes.
Hands-on fluency with LLM and generative AI tools in day-to-day technical work.
Preferred Qualifications
Working understanding of how AI agents authenticate and are authorized to enterprise systems non-human identities credential scoping and emerging integration patterns such as the Model Context Protocol (MCP) including experience building deploying or securing MCP servers or agentic AI workflows.
Exposure to identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar) or SIEM platforms.
Awareness of API security concepts including the OWASP API Security Top 10 and authorization flaws such as BOLA/IDOR.
Exposure to endpoint management and device trust as they relate to identity (Jamf Intune) on Windows or macOS.
Experience with HRIS-driven identity automation (Ceridian Dayforce Workday UKG or similar).
AWS IAM or AWS IAM Identity Center exposure.
Okta Certified Professional/Administrator or Microsoft identity certification (SC-300).
What do we offer
Insurance Plans (Medical Life)
Pension/401K/RSP (country specific)
Competitive Bonus
Mobility Allowance
Tuition Reimbursement
Company Holidays
Volunteering time
And More..
Required Experience:
IC