JobTarget Logo

IAM Engineer in Shelton, Connecticut at Subway

NewJob Function: Engineering
Subway
Shelton, Connecticut, 06484, United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

IAM Engineer

IAM Engineer

Franchise World Headquarters, LLC

Shelton, CT

Why Join Subway?

At Subway, we are not standing still. We are building.

This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.

You will not just do the work. You will shape it.

We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.

If you bring energy, accountability and a bias for action, you will fit right in.

We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.

This is your chance to be part of whats next.

Position Overview

The IAM Engineer builds and operates the day-to-day identity and access management capabilities that keep Subway's workforce productive and secure. Subway runs a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This is a hands-on operational and engineering role owning the daily health of the identity platform while building the automation that steadily retires manual work. The role carries a clear development path toward senior-level identity engineering, including deeper federation and protocol work, access governance, identity threat detection, and security architecture.

Responsibilities

Operate the identity platform day to day: new SSO application setup, access request fulfillment and escalations, MFA management, group and access cleanup, and account lifecycle corrections; troubleshoot provisioning and authentication issues end to end SCIM sync failures, attribute mismatches, SSO errors performing root-cause analysis and documenting resolutions as runbooks.

Handle complex onboarding, offboarding, and HR-driven downstream changes outside automated lifecycle flows, treating offboarding as security-critical work; manage IAM tickets and service requests in ServiceNow meeting SLA targets; serve as an internal escalation point for complex identity issues from the Technology Support Center and business teams.

Build Okta Workflows for identity lifecycle events, application provisioning, and remediation tasks; expand the Okta access catalog to convert recurring ticket categories into governed self-service with owner/manager approval; implement joiner/mover/leaver automation driven by HRIS events; contribute to AWS access self-service through AWS IAM Identity Center permission sets.

Script operational automation in PowerShell or Python reconciliation, reporting, cleanup, and provisioning tasks; participate in upgrades, patching, and change tickets for identity infrastructure, and the team's shared on-call rotation.

Operate SCIM 2.0 provisioning between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, Microsoft 365, and AWS IAM Identity Center; support the transition off a legacy custom SCIM connector to broker-native provisioning; configure SSO integrations (SAML 2.0, OIDC) for new applications.

Apply least-privilege principles in daily access work right-sized group and role assignments, time-bound privileged access, and cleanup of dormant or over-privileged accounts; support Okta Identity Governance operations including access certification campaigns; administer non-human identities and service accounts for LLM and agentic AI integrations applying least-privilege credential-scoping patterns.

Collaborate with the broader Cybersecurity engineering teams on shared projects; assist investigations of access anomalies alongside senior engineers and the Detect & Respond team; support internal and external audits with access evidence; author and maintain runbooks, knowledge-base articles, and hand-off documentation for new automations.

Qualifications

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field or equivalent work experience.

35 years in IAM, identity operations, systems administration with significant identity scope, or a related security/infrastructure role.

Hands-on experience with Okta or a comparable identity provider: user and group administration, application SSO integration, and lifecycle management; Okta strongly preferred.

Working knowledge of SSO and federation protocols SAML 2.0, OIDC, and OAuth 2.0 fundamentals sufficient to configure and troubleshoot integrations.

Working knowledge of SCIM provisioning concepts and troubleshooting: attribute mapping, sync errors, and reconciliation.

Active Directory fundamentals (users, groups, OUs, group policy awareness) and familiarity with Microsoft Entra ID and Microsoft 365 administration.

Scripting proficiency in PowerShell or Python for operational automation (both, plus bash, preferred).

Experience working with REST APIs: authentication, reading API documentation, and basic troubleshooting of API-driven integrations.

Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.

Comfort working with Git-based source control and participating in CI/CD-based change processes.

Hands-on fluency with LLM and generative AI tools in day-to-day technical work.

Preferred Qualifications

Working understanding of how AI agents authenticate and are authorized to enterprise systems non-human identities, credential scoping, and emerging integration patterns such as the Model Context Protocol (MCP) including experience building, deploying, or securing MCP servers or agentic AI workflows.

Exposure to identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar) or SIEM platforms.

Awareness of API security concepts including the OWASP API Security Top 10 and authorization flaws such as BOLA/IDOR.

Exposure to endpoint management and device trust as they relate to identity (Jamf, Intune) on Windows or macOS.

Experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, UKG, or similar).

AWS IAM or AWS IAM Identity Center exposure.

Okta Certified Professional/Administrator or Microsoft identity certification (SC-300).

What do we offer?

Insurance Plans (Medical, Life)

Pension/401K/RSP (country specific)

Competitive Bonus

Mobility Allowance

Tuition Reimbursement

Company Holidays

Volunteering time

And More..

Job Location

Shelton, Connecticut, 06484, United States

Frequently asked questions about this position

Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.