Role Description
The Security Team is seeking a highly skilled IAM Engineer with a strong focus on identity and access management to help drive our mission of securing user and workforce authentication at scale. This role is ideal for someone who thrives in solving complex challenges and has a passion for building robust, scalable identity solutions in dynamic engineering environments.
In this role you work hands-on with SailPoint, Okta and Okta Workflows to design and implement secure SSO integrations, manage access policies, and streamline identity automation across the enterprise. Experience with authentication protocols, identity lifecycle management, and SailPoint is essential, as you’ll play a key role in shaping the future of access control and enterprise identity at Dropbox.
Our Engineering Career Framework is viewable by anyone outside the company and describes what’s expected for our engineers at each of our career levels. Check out our blog post on this topic and more here.
Responsibilities
- Design, implement, and maintain secure identity and access management (IAM) solutions using Okta, Okta Workflows, and SailPoint to support scalable, automated, and auditable identity lifecycle management
- Lead SSO integration efforts for internal and third-party applications, ensuring secure authentication and seamless user experience across the enterprise
- Develop and enforce access control policies and governance models to meet security, compliance, and SOX certification requirements
- Support the onboarding of enterprise applications into Okta, including custom configuration, testing, and rollout to production
- Enhance and maintain synchronization services between identity sources and downstream systems using SailPoint IdentityNow and directory services
- Participate in incident response, troubleshooting, and resolution of identity-related issues across infrastructure and application stacks
- Contribute to the development of documentation, standards, and reusable templates for identity workflows and access reviews
Requirements
- 5+ years of experience in identity and access management (IAM), with direct ownership of Okta and/or SailPoint implementations
- BS degree in Computer Science, Information Technology, Cybersecurity or related technical field, or equivalent technical experience
- Demonstrated expertise in Okta platform administration, including Universal Directory, Okta Workflows, Lifecycle Management, and SSO integrations
- Hands-on experience with SailPoint IdentityNow, configuring identity governance, access reviews, provisioning, and policy management
- Strong understanding with authentication protocols, i.e. SAML, OAuth, OIDC, and MFA
- Experience with automation and API integration and ability to build workflows and automations using tools like Okta Workflows, Python, or JavaScript, and comfort working with REST APIs
- Background in security and compliance, namely familiarity with SOX, access certifications, and audit support for IAM environments
Preferred Qualifications
- 3+ years of experience in identity and access management (IAM), with direct ownership of Okta and/or SailPoint implementations
- Hands-on experience with Okta Workflows, advanced SSO configurations, and lifecycle management
- Strong working knowledge of SailPoint IdentityNow, including identity governance, role management, and access certifications
- Relevant certifications such as Okta Certified Professional, Certified Identity and Access Manager (CIAM), CISSP, or Security+ are a plus
Compensation
Dropbox applies increased tax deductible costs to remuneration earned by certain qualifying employees (to the extent an employee will be involved in the creation of the software as an “author”) for the transfer of copyrights, in accordance with the relevant provisions of the Personal Income Tax Act.