HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    OP

    Openlane

    Automotive

    Manager, Identity and Access Management

    US - IN - Carmel (OPENLANE), United StatesRemoteFull-time5+ yrs experiencePosted 2h ago
    All Openlane jobs

    Job description

    Who We Are:
    At OPENLANE we make wholesale easy so our customers can be more successful.
    We’re a technology company building the world’s most advanced—and uncomplicated—digital marketplace for used vehicles.
    We’re a data company helping customers buy and sell smarter with clear, actionable insights they can understand and use.
    And we’re an innovation company accelerating the future of wholesale remarketing through curiosity, collaboration, and an entrepreneurial spirit.
    Our Values:
    Driven Waybuilders. We pursue challenges that inspire us to build, create, and innovate.
    Relentless Curiosity. We seek to understand and improve our customers’ experience.
    Smart Risk-Taking. We transform risk into progress through data, experience, and intuition.
    Fearless Ownership. We deliver what we promise and learn along the way.

    We’re Looking For:

    A Manager of Identity & Access Management to lead the team that owns identity across OPENLANE — workforce and customer, cloud and on-premises. You will own the IAM roadmap and service delivery across multiple Okta organizations, our privileged access program, and enterprise access governance, while building and developing a team of identity engineers. You will set the standard for how a modern identity team operates: automation over manual fulfillment, engineering discipline over ticket queues, and AI-assisted work as a daily habit rather than an experiment.

    You Are

    • An AI-first leader. You use AI coding and productivity tools daily, and you are accountable for how your team uses them — you define the responsible-use standards, coach adoption, remove the friction, and can point to the leverage your team actually gained. You treat AI fluency as a core engineering competency, not a side project.
    • A developer of engineers. You genuinely enjoy growing early-career and mid-level engineers into confident identity practitioners through direct coaching, clear expectations, and real ownership.
    • A leader who amplifies senior ICs. You know how to partner with a deeply technical lead engineer — giving them room to architect and execute while you clear the path, set priorities, and handle the organizational weight.
    • Security-minded and pragmatic. You hold a high bar on least privilege, Zero Trust, and auditability, and you can tell the difference between a control that reduces risk and one that only adds friction.
    • Calm under incident pressure. When identity breaks, everything breaks. You lead incident response with structure and clear communication, then make sure the same failure cannot happen twice.
    • A translator. You move fluently between engineering teams, security architecture, compliance, and business stakeholders, and you can explain an access decision to any of them.

    You Bring

    • Core knowledge of identity lifecycle management, Zero Trust architecture, least-privilege design, identity governance and administration (IGA), and role- and attribute-based access control (RBAC/ABAC).
    • Functional expertise in enterprise single sign-on (SSO), multi-factor authentication and phishing-resistant authentication (FIDO2, passkeys), federated identity protocols (SAML 2.0, OAuth 2.0, OpenID Connect), privileged access management, and access certification programs.
    • Technical depth in administering Okta at scale across multiple organizations, and in hybrid directory environments — including Active Directory running on cloud infrastructure (AWS and Azure) and Microsoft Entra ID — with the judgment and experience to reduce and ultimately retire legacy directory dependencies in favor of cloud-native identity.
    • Enough technical credibility to review an architecture, challenge a design, interpret an identity log, and hold your own with senior engineers
    • Leadership practice in hiring, performance management, career development, and prioritization for a small, high-leverage engineering team.

    You Will Own

    • The IAM roadmap, service delivery, and operational health across multiple Okta organizations, spanning both workforce identity and customer-facing identity.
    • Enterprise identity lifecycle: automated joiner-mover-leaver provisioning and deprovisioning, self-service access requests, and entitlement models.
    • The privileged access management program — privileged account inventory, vaulting, session controls, and standing-access reduction.
    • Access governance and audit readiness: access certification campaigns, segregation of duties, evidence collection, and remediation follow-through.
    • Okta and IAM vendor relationships — renewals, roadmap reviews, escalations, and quarterly business reviews.
    • License and entitlement optimization, including measuring and managing consumption — monthly active users and machine-to-machine usage — against contracted entitlement.
    • Budget inputs and forecasting for identity platforms and services, in partnership with your leader.
    • Team composition, performance, development, and hiring — and the operating standards the team works to, including its use of AI tooling.

    You Drive

    Execution: Modernizing authentication across the application estate, consolidating and rationalizing identity across multiple Okta organizations, automating identity lifecycle and certification work, and reducing legacy directory dependency.

    Results:

    • Mature identity incident response. Clear runbooks, tested escalation paths, meaningful detection for identity abuse, and closed loops on known operational gaps — so identity incidents are contained quickly and do not recur.
    • Scale without headcount. Joiner-mover-leaver workflows and access certification automated to the point where growth in users, applications, and audit scope does not require growth in team size.
    • Bench depth, not key-person risk. Cross-trained engineers and documented systems so that no single individual is the only person who can operate a critical identity platform. 
    • A defensible access posture. Least privilege enforced and evidenced, audit findings closed on schedule, and access decisions traceable.

    Who You Will Work With

    Reporting to the leader of Site Reliability Engineering and Identity & Access Management, you will lead a team of identity engineers spanning lead, senior, and associate levels. You will partner daily to weekly with Cloud Engineering, IT Infrastructure, Security Architecture, Application Engineering, Compliance, and the business units that depend on customer identity. You will have regular exposure to technology leadership on identity posture, platform strategy, and commercial performance.

    Where You Work

    Your work is performed as a remote employee based in the United States, with periodic travel to OPENLANE World Headquarters.

    Your Tech Stack

    • Okta (multi-org / multi-tenant), Microsoft Entra ID, Active Directory, LDAP
    • SSO, MFA and phishing-resistant authentication; SAML 2.0, OAuth 2.0, OpenID Connect, SCIM
    • Privileged access management and secrets management platforms
    • Identity governance and access certification tooling
    • Scripting and automation (Python, PowerShell) and Infrastructure as Code (Terraform)
    • AWS, Azure, and Google Cloud identity services
    • AI coding assistants and LLM-based automation as part of the team’s daily workflow

    Must Have’s

    • 5+ years of hands-on experience in Identity and Access Management or identity-focused security engineering.
    • 2+ years leading engineers, including direct people management — hiring, performance, and career development.
    • Demonstrated leadership of a team that uses AI tooling in its daily engineering work — you have set the expectations and standards for responsible AI use, driven adoption, and can describe the concrete outcomes it produced.
    • Hands-on administration experience with Okta in a production enterprise environment, including policy configuration, application integration, and troubleshooting.
    • Working experience with Active Directory and hybrid directory environments, including cloud-hosted domain infrastructure and integration with a cloud identity provider.
    • Practical command of federated identity and modern authentication protocols (SAML 2.0, OAuth 2.0, OpenID Connect) and of SSO and MFA at enterprise scale.
    • Track record of defining and enforcing access policy, and of supporting audit and compliance requirements with evidence.
    • Strong written and verbal communication skills, with the ability to explain identity risk and access decisions to both engineers and business stakeholders.
    • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.

    Nice to Have’s

    • Okta certifications (Okta Certified Administrator, Okta Certified Professional, or Okta Certified Consultant).
    • Security or identity certifications such as CISSP, CISM, or Certified Identity and Access Manager (CIAM).
    • Experience with customer identity and access management (CIAM) at consumer scale, including multi-tenant or multi-org identity consolidation.
    • Experience scaling a privileged access management program in a hybrid environment.
    • Experience migrating applications and workloads off legacy directory services onto cloud-native identity.
    • Multi-cloud identity experience across AWS, Azure, and Google Cloud.
    • Experience applying automation or AI-assisted workflows to identity operations — access review triage, log investigation, or lifecycle provisioning.
    • Experience in the automotive, auction, marketplace, or e-commerce industries.

    What We Offer:

    • Competitive pay

    • Medical, dental, and vision benefits with employer HSA contributions (US) and FSA options (US)

    • Immediately vested 401K (US) or RRSP (Canada) with company match

    • Paid Vacation, Personal, and Sick Time

    • Paid maternity and paternity leave (US)

    • Employer-paid short-term disability, long-term disability, life insurance, and AD&D (US)

    • Robust Employee Assistance Program

    • Employer paid Leap into Service Day to volunteer

    • Tuition Reimbursement for eligible programs

    • Opportunities to expand your skill set and share your knowledge across a publicly traded, global organization

    • Company culture of internal promotions, diverse career paths, and meaningful advancement

    Sound like a match? Apply Now - We can't wait to hear from you!

    Job details are sourced from the employer's original posting.

    Open job posting
    OP

    About the company

    Openlane

    OPENLANE is a technology and data company building the world's most advanced digital marketplace for used vehicles, making wholesale easy for customers.

    View all Openlane jobs
    Industry
    Automotive
    Open roles
    52

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.