About this role.
Cision is hiring an IAM Security Engineer to design, implement, and operate identity and access management capabilities across its global environment. The role centers on Okta, including SSO, MFA, Universal Directory, lifecycle management, RBAC, SCIM provisioning, and integrations with Azure AD, AWS IAM, Active Directory, and third-party applications. The engineer will support compliance and audit work, investigate IAM security incidents, and contribute to the broader IAM roadmap. This is a remote Hungary-based full-time role requiring 3–5 years of IAM or related security experience and occasional availability for urgent after-hours incident response. Candidates should be ready to demonstrate relevant technical skills in a screen-shared practical exercise.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
4/5Pace & Pressure
4/5Autonomy Level
4/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would define authoritative HR attributes and event triggers, map them to Okta Universal Directory profiles, and automate account creation, group assignment, application provisioning, and deprovisioning through lifecycle management and SCIM where supported. I would apply role-based access rules, include approval paths for elevated access, and regularly validate that termination events promptly revoke sessions, factors, tokens, and downstream access.
SAML is an XML-based federation standard commonly used for browser-based enterprise SSO to SaaS applications. OIDC is an identity layer built on OAuth 2.0 that uses JSON tokens and is often better suited to modern web, mobile, and API-centric applications. I select the protocol based on the application's supported standards, architecture, token requirements, and security controls.
I would first preserve and review Okta System Log events, focusing on sign-ins, MFA changes, factor enrollments, administrative actions, policy changes, application assignments, and anomalous session activity. I would correlate those events with endpoint, SIEM, directory, cloud, and application logs; contain the issue by revoking sessions or disabling affected accounts; then remediate the root cause and document lessons learned.
I would use centrally governed roles and groups, attribute-driven access where appropriate, just-in-time elevation for privileged work, periodic access recertification, and automated removal of stale entitlements. I would integrate Okta with cloud IAM platforms, ensure privileged accounts have strong MFA and logging, and monitor for excessive permissions, orphaned accounts, and policy exceptions.
I use PowerShell or Python with APIs to automate repetitive activities such as account audits, group membership reviews, application assignment checks, bulk remediation, and reporting. I build scripts with secure credential handling, input validation, idempotent behavior, logging, error handling, and a testing process so automation improves both speed and control quality.
At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you’ll thrive in an environment that champions curiosity, collaboration, and innovation, all while making meaningful contributions to the brands we accelerate.
Join us in shaping the future of communication and building authentic connections that matter. Whether you’re solving complex problems or driving bold innovations, your growth is our success, and together, we’ll create the conversations of tomorrow.
Empower your impact at Cision. Be seen, be understood, be you.
Cision is a global leader in media intelligence and communications solutions. Our InfoSec team is expanding to meet the growing demands of a secure, scalable, and resilient identity infrastructure. We are seeking a skilled IAM Security Engineer to help us build and maintain a robust identity and access management ecosystem across our global footprint, with a strong focus on Okta technologies.
As an IAM Security Engineer, you will play a critical role in designing, implementing, and maintaining identity and access management solutions using Okta as our primary platform. You will collaborate with global teams across security, infrastructure, and application development to ensure IAM policies and technologies align with business and compliance requirements.
Key Responsibilities:
- Design and implement IAM solutions using Okta, including SSO, MFA, and lifecycle management.
- Manage identity lifecycle processes (Joiner, Mover, Leaver) across enterprise systems.
- Integrate Okta with cloud platforms (e.g., Azure AD, AWS IAM), directory services (e.g. Active Directory) and third-party applications.
- Support audits, compliance initiatives (e.g., SOC2, ISO27001), and security assessments.
- Monitor and respond to IAM-related incidents and vulnerabilities.
- Define and enforce access policies and role-based access controls (RBAC) within Okta as well as maintain our existing IdP instances.
- Contribute to the development of IAM roadmaps and strategic initiatives.
Qualifications:
- 3–5 years of experience in IAM engineering or related security roles.
- Hands-on experience with Okta Identity Cloud, including Universal Directory, Lifecycle Management, and Advanced Server Access.
- Strong background experience with SAML and OIDC federation protocols and working with various federated Identity Providers such as Okta.
- Familiarity with Okta Workflows, API integrations, and SCIM provisioning.
- Experience with scripting and automation (e.g., PowerShell, Python).
- Knowledge of regulatory frameworks (e.g., GDPR, ISO27001, SOC2).
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Relevant certifications (e.g., Okta Certified Professional, CISSP, Azure Security Engineer) are a plus.
What we offer:
- Friendly and welcoming environment focused on people, learning & development
- 25 vacation days and extra vacation days after age and after children
- Cafeteria benefit via SZEP card
- Medicover private health insurance for employees and their family members
- 10% of your time to work on anything you like, reading groups, tech talks
- Flexible working and working from home
- An extensive people development program, including access to Udemy
Please note:
- Candidates must be available for after-hours incident response when urgent security events require investigation or support.
- The interview process will include a hands-on practical exercise conducted through screen sharing, where candidates will be asked to demonstrate relevant technical skills.
Cision is the global leader in consumer and media intelligence, engagement, and communication solutions. We equip PR and corporate communications, marketing, and social media professionals with the tools they need to excel in today’s data driven world. Our deep expertise, exclusive data partnerships, and award-winning products, including CisionOne, Brandwatch, and PR Newswire, enable over 75,000 companies and organizations, including 84% of the Fortune 500, to see and be seen, understand and be understood by the audiences that matter most to them.
Cision is committed to fostering an inclusive environment where all employees can be their authentic selves and perform at their best. We believe diversity, equity, and inclusion is vital to driving our culture, sparking innovation and achieving long-term success. Cision is proud to have joined more than 600 companies in signing the CEO Action for Diversity & Inclusion™ pledge and named a “Top Diversity Employer” for 2021 by DiversityJobs.com.
Cision is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or other protected statuses.
Cision is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Cision will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact hr.support@cision.com
Cision, Inc. “the Company” only communicates with candidates and extends job offers through direct channels, not third parties.
Please review our Global Candidate Data Privacy Statement to learn about Cision’s commitment to protecting personal data collected during the hiring process.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.







