We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

IAM Engineer

Franchise World Headquarters, LLC
tuition reimbursement, 401(k)
United States, Connecticut, Shelton
1 Corporate Drive (Show on map)
Aug 07, 2026

IAM Engineer

Franchise World Headquarters, LLC

Shelton, CT

Why Join Subway?

At Subway, we are not standing still. We are building.

This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.

You will not just do the work. You will shape it.

We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.

If you bring energy, accountability and a bias for action, you will fit right in.

We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.

This is your chance to be part of what's next.

Position Overview

The IAM Engineer builds and operates the day-to-day identity and access management capabilities that keep Subway's workforce productive and secure. Subway runs a modern, broker-centered identity architecture: an HRIS-driven identity pipeline feeds Okta as the identity broker and primary SSO provider, which federates and provisions access across a hybrid estate spanning Active Directory, Microsoft Entra ID, Microsoft 365, ServiceNow, AWS IAM Identity Center, and a broad SaaS portfolio. This is a hands-on operational and engineering role - owning the daily health of the identity platform while building the automation that steadily retires manual work. The role carries a clear development path toward senior-level identity engineering, including deeper federation and protocol work, access governance, identity threat detection, and security architecture.

Responsibilities

* Operate the identity platform day to day: new SSO application setup, access request fulfillment and escalations, MFA management, group and access cleanup, and account lifecycle corrections; troubleshoot provisioning and authentication issues end to end - SCIM sync failures, attribute mismatches, SSO errors - performing root-cause analysis and documenting resolutions as runbooks.

* Handle complex onboarding, offboarding, and HR-driven downstream changes outside automated lifecycle flows, treating offboarding as security-critical work; manage IAM tickets and service requests in ServiceNow meeting SLA targets; serve as an internal escalation point for complex identity issues from the Technology Support Center and business teams.

* Build Okta Workflows for identity lifecycle events, application provisioning, and remediation tasks; expand the Okta access catalog to convert recurring ticket categories into governed self-service with owner/manager approval; implement joiner/mover/leaver automation driven by HRIS events; contribute to AWS access self-service through AWS IAM Identity Center permission sets.

* Script operational automation in PowerShell or Python - reconciliation, reporting, cleanup, and provisioning tasks; participate in upgrades, patching, and change tickets for identity infrastructure, and the team's shared on-call rotation.

* Operate SCIM 2.0 provisioning between Ceridian Dayforce, Okta, and downstream systems including Active Directory, Entra ID, ServiceNow, Jamf, Microsoft 365, and AWS IAM Identity Center; support the transition off a legacy custom SCIM connector to broker-native provisioning; configure SSO integrations (SAML 2.0, OIDC) for new applications.

* Apply least-privilege principles in daily access work - right-sized group and role assignments, time-bound privileged access, and cleanup of dormant or over-privileged accounts; support Okta Identity Governance operations including access certification campaigns; administer non-human identities and service accounts for LLM and agentic AI integrations applying least-privilege credential-scoping patterns.

* Collaborate with the broader Cybersecurity engineering teams on shared projects; assist investigations of access anomalies alongside senior engineers and the Detect & Respond team; support internal and external audits with access evidence; author and maintain runbooks, knowledge-base articles, and hand-off documentation for new automations.

Qualifications

* Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field - or equivalent work experience.

* 3-5 years in IAM, identity operations, systems administration with significant identity scope, or a related security/infrastructure role.

* Hands-on experience with Okta or a comparable identity provider: user and group administration, application SSO integration, and lifecycle management; Okta strongly preferred.

* Working knowledge of SSO and federation protocols - SAML 2.0, OIDC, and OAuth 2.0 fundamentals - sufficient to configure and troubleshoot integrations.

* Working knowledge of SCIM provisioning concepts and troubleshooting: attribute mapping, sync errors, and reconciliation.

* Active Directory fundamentals (users, groups, OUs, group policy awareness) and familiarity with Microsoft Entra ID and Microsoft 365 administration.

* Scripting proficiency in PowerShell or Python for operational automation (both, plus bash, preferred).

* Experience working with REST APIs: authentication, reading API documentation, and basic troubleshooting of API-driven integrations.

* Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.

* Comfort working with Git-based source control and participating in CI/CD-based change processes.

* Hands-on fluency with LLM and generative AI tools in day-to-day technical work.

Preferred Qualifications

* Working understanding of how AI agents authenticate and are authorized to enterprise systems - non-human identities, credential scoping, and emerging integration patterns such as the Model Context Protocol (MCP) - including experience building, deploying, or securing MCP servers or agentic AI workflows.

* Exposure to identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar) or SIEM platforms.

* Awareness of API security concepts including the OWASP API Security Top 10 and authorization flaws such as BOLA/IDOR.

* Exposure to endpoint management and device trust as they relate to identity (Jamf, Intune) on Windows or macOS.

* Experience with HRIS-driven identity automation (Ceridian Dayforce, Workday, UKG, or similar).

* AWS IAM or AWS IAM Identity Center exposure.

* Okta Certified Professional/Administrator or Microsoft identity certification (SC-300).

What do we offer?

* Insurance Plans (Medical, Life)

* Pension/401K/RSP (country specific)

* Competitive Bonus

* Mobility Allowance

* Tuition Reimbursement

* Company Holidays

* Volunteering time

* And More.....

Applied = 0

(web-77cf7d65c7-jdxdg)