Client Platform Engineer, Windows and VDI
Get to know OktaOkta is The World’s Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences. Join our team! We’re building a world where Identity belongs to you.
The Business Technology Team
The Business Technology (BT) team at Okta is the internal IT organization responsible for the technology infrastructure, applications, and services that empower Okta employees globally. We partner across the business to deliver solutions that drive productivity, collaboration, and innovation. Effective financial management and operational discipline are critical to our success in enabling Okta's rapid growth and ensuring we operate efficiently.
The Client Platform Engineer, Windows and VDI Opportunity
Reporting to the Lenny Vaknine, this role will play a critical role in the secure management of Windows-based endpoints across both commercial and federally regulated environments (GovCloud).We’re a passionate team of engineers who thrive on building scalable, secure, and user-friendly systems. We welcome challenges, automate wherever possible, and are deeply focused on improving the employee experience through modern, compliant, and maintainable client infrastructure.
What you’ll be doing
- Manage and secure Windows devices across Okta’s global environment, including:
- Physical Windows PCs
- Windows 365 Cloud PCs
- Amazon WorkSpaces in GovCloud
- Build and maintain VDI images, pipelines, and workflows for virtual environments tailored to federal standards.
- Work with Security and Compliance teams to implement frameworks such as NIST 800-53, CIS Benchmarks, and DISA STIGs.
- Utilize Microsoft Intune and Entra ID downstream of Okta to manage device configurations, Conditional Access policies, and extension attributes at scale.
- Leverage PowerShell, Terraform and Microsoft Graph API for automation, infrastructure management, and configuration as code.
- Deploy and update applications via modern tooling: Patch My PC, Chocolatey, Winget, PSADT, etc.
- Maintain endpoint security hygiene and respond to CVEs through patching.
- Partner with internal support teams to triage endpoint issues, maintain service health, and enforce endpoint security.
- Automate provisioning/de-provisioning processes and integrate with enterprise tools using CI/CD (e.g., GitHub Actions).
- Serve as a senior escalation point for Windows-related technical issues across the enterprise.
What you’ll bring to the role
- A passion for endpoint management.
- Proven experience managing Windows environments in federal or regulated industries, including VDI, Windows 365, and AWS WorkSpaces.
- Strong background with Active Directory, Entra ID, Okta, and hybrid identity management.
- Background managing SaaS and identity systems (e.g., SAML, SCIM, OAuth)
- Experience building pipelines with tools like Terraform, GitHub, and CI/CD systems (e.g., GitHub Actions).
- Strong hands-on scripting ability in PowerShell, Python, or Go for automation and remediation tasks.
- Experience deploying and managing devices with Microsoft Intune and Windows Autopilot.
- Familiarity with AWS, AWS GovCloud, Azure, and automation using AWS CLI, AWS Lambda, and Microsoft Graph API, etc.
- Proven record of writing accurate and thorough technical documentation for both fellow engineers and support teams for daily operations.
- A problem-solving mindset with a proactive, automation-first approach to device and infrastructure management.
And extra credit if you have experience in any of the following!
- Experience with Jamf Pro, AutoPkg, and Munki for managing Apple devices.
- Proficiency in Go or other compiled languages for deeper systems automation.
- Certifications such as Okta Certified Professional, Microsoft Endpoint Administrator or similar
- Previous experience working with federal agencies or federal integrators.
#LI-BF1#LI-Onsite
Below is the annual base salary range for candidates located in California, Colorado, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.
The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, New York, and Washington is between:$168,000—$252,000 USDWhat you can look forward to as a Full-Time Okta employee!
- Amazing Benefits
- Making Social Impact
- Developing Talent and Fostering Connection + Community at Okta
Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today! https://www.okta.com/company/careers/.Some roles may require travel to one of our office locations for in-person onboarding.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at https://www.okta.com/privacy-policy/.