Job title: Senior IAM Engineer
Work Location: Plano(TX) , Bethpage(NY)
Job Description:
The Senior IAM Engineer will provide senior-level IAM consulting and architecture services supporting customer identity initiatives.
You will provide architecture recommendations and implementation guidance, design the automation that keeps configuration consistent at scale, and enable application development teams to move faster and more securely.
Responsibilities:
1. IAM Platform Architecture & IDP Governance
" Own the architecture of the enterprise IDP tenant as a production platform: org-wide policy design, Identity Engine pipeline configuration, authentication policy hierarchy, and security baseline standards.
" Design and govern the IDP authorization server strategy: authorization server topology, custom scope and claims standards, token lifetime policies, and API access management rules for all integrated applications.
" Develop recommendations concerning IDP integration standards and best practices.
" Assess configuration governance practices and provide recommendations for improvement.
" Evaluate Identity Engine capabilities and provide implementation recommendations: Global Session Policy, authentication policy factors, assurance levels, and authenticator enrollment policy design.
2. Authentication Modernization
" Provide recommendations for the technical design of the enterprise authentication modernization roadmap: define migration patterns, integration reference architectures, and decision frameworks that application teams use to onboard to the IDP.
" Design and own the migration playbook library covering OIDC SPA, OIDC server-side, SAML SP-initiated, embedded widget, and redirect-model integrations including edge cases for legacy SSO federations and custom session stores.
" Architect the OAuth 2.0 token design strategy across the application portfolio: scope taxonomy, token claims standards, audience conventions, and refresh token policies aligned to data classification and risk tiers.
" Drive the adoption of phishing-resistant authentication: design FIDO2/WebAuthn and IDP enrollment policies, relying party configurations, and fallback authenticator strategies.
" Identify cross-cutting technical blockers in the migration program (architectural debt, shared-session anti-patterns, CORS misconfigurations) and facilitate technical discussions and provide recommendations regarding identified issues.
3. Developer Platform & Enablement Engineering
" Develop and maintain project-related documentation and reference materials.
" Build and maintain production-quality reference implementations in two or more languages (Node.js, Java, Python, Go) demonstrating correct OIDC/OAuth 2.0 flows, token validation, session management, and error handling patterns.
" Design the IAM self-service onboarding workflow: intake process, app registration automation, sandbox environment provisioning, and go-live checklist reducing time-to-onboard for new application integrations.
" Perform IAM architecture reviews for complex or high-risk application integrations; produce written architectural guidance and approval decisions with documented rationale.
4. Security Engineering & Threat Modeling
" Conduct threat modeling for the CIAM platform and high-risk application integrations: identify attack surfaces (credential stuffing, token hijacking, redirect URI manipulation, IDP confusion), assess risk, and design compensating controls.
" Design and tune the identity threat detection layer: IDP security policy, behavioral anomaly signals (impossible travel, new device, geolocation deviation), and SIEM integration for identity-specific alert logic.
" Provide recommendations regarding IAM security baseline requirements.
" Lead security-focused design reviews for Workflow automations, Event Hook implementations, and custom identity microservices enforcing least-privilege, input validation, and secrets management practices.
" Assess IAM-related vulnerabilities and provide remediation recommendations.
5. Infrastructure as Code & Platform Engineering
" Design and implement infrastructure-as-code solutions: design and maintain the Terraform module library covering all core platform resources apps, policies, groups, authorization servers, and user schemas.
" Develop CI/CD enhancements and automation capabilities related to project deliverables: automated plan/apply workflows, policy-as-code validation gates (OPA or equivalent), drift detection, and environment promotion (dev staging production).
" Define the IDP configuration testing strategy: contract tests for IDP integrations, policy simulation tests for authentication flows, and regression tests for critical user journeys integrated into the deployment pipeline.
" Build and maintain platform observability: IDP System Log export pipeline, SIEM dashboards for authentication health KPIs, latency percentiles, error rate alerts*** and SLO burn-rate tracking***
" Evaluate and introduce new tooling to the team's platform engineering practice: assess alternatives, run proof-of-concepts, document trade-offs, and drive adoption decisions with the Manager.
6. Compliance, Audit & Risk Leadership
" Develop and maintain documentation supporting compliance requirements. Map platform capabilities to compliance requirements (SOX, SOC 2 Type II, PCI-DSS, CPNI), maintain control descriptions, and ensure evidence artifacts are accurate and audit-ready year-round.
" Lead access certification program design for CIAM: define scope, sampling methodology, evidence collection automation, and remediation workflows for periodic customer-facing access reviews.
" Serve as the IAM subject matter expert in external audits and pen tests: respond to auditor inquiries, coordinate evidence gathering across the team, and negotiate finding severity with assessors based on compensating controls.
" Proactively identify compliance gaps introduced by platform changes or new regulatory guidance; present risk and remediation options to the Manager with implementation estimates.
Qualifications
Required
" 6 years of progressive experience in Identity and Access Management, security engineering, or a closely related technical field.
" 3 years of hands-on, production ownership of the IDP platform at significant scale including Identity Engine, authentication policy design, SCIM provisioning, Workflows, and multi-environment tenant management.
" Expert-level command of identity protocols: OAuth 2.0 (all grant types, token introspection, token revocation), OpenID Connect (all flows, claims, discovery), SAML 2.0, SCIM 2.0, and FIDO2/WebAuthn able to implement, debug, and review at the protocol layer.
" Demonstrated experience designing and implementing as-Code using Terraform module authorship, CI/CD pipeline integration, drift detection, and multi-environment management.
" Experience leading authentication modernization programs or large-scale IAM migrations across a diverse application portfolio.
" Proficiency in at least two modern programming languages (Node.js, Java, Python, or Go) with the ability to write production-quality integration code, automation tooling, and reference implementations.
" Track record of conducting threat modeling, security design reviews, and producing actionable written security guidance for engineering audiences.
" Experience owning IAM-related compliance controls and leading or supporting external audits (SOC 2, SOX, PCI-DSS, or equivalent).
" Demonstrated ability to influence technical direction across teams, and operate effectively with senior stakeholders.
Preferred
" Certifications in customer identity platforms.
" Experience with Customer Identity Engine advanced features: assurance-level step-up, global session policies, device trust integration, and authenticator enrollment policy design.
" Experience building identity observability pipelines: Custom dashboards, SLO burn-rate alerting*** and anomaly detection rules.
" Familiarity with Zero Trust architecture frameworks (NIST SP 800-207) and practical implementation experience via IDP and network/endpoint controls.
" Exposure to adjacent IAM disciplines: Privileged Access Management (PAM), workforce SSO, or B2B federation with external identity providers.
" Experience contributing to open-source IAM tooling, presenting at identity conferences, or publishing technical content on CIAM topics.
" Bachelor's degree or higher in Computer Science, Information Systems, Cybersecurity, or a related field; equivalent professional experience considered.
Custom Fields:
Name: Intake Call Completed
Value: true
Name: Intake Call Requested
Value: true