Identity Provider (IdP) Engineer

Wood River Federal

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, IT, Cybersecurity, or related field.
  • Minimum of six years in Identity, Credential, and Access Management (ICAM) roles.
  • Deep knowledge of PingFederate and associated protocols (OIDC, SAML, OAuth).
  • Experience with PingAccess for web and API security at the gateway level.
  • CompTIA Security+ certification or ability to obtain it within 30 days.
  • Active government security clearance (Secret required).

Responsibilities

  • Design and implement identity-based access control policies following Zero Trust principles.
  • Lead deployment, configuration, and optimization of PingFederate and PingAccess for SSO and ABAC.
  • Manage Identity, Credential, and Access Management lifecycle with automated provisioning and integrations.
  • Collaborate with SOC and Network teams to integrate identity signals into security workflows.
  • Act as a subject matter expert for integrating PingFederate with Zero Trust ecosystem components.
  • Maintain and create authentication policies, including MFA and RBA.
  • Offer guidance and training for onboarding new applications to PingFederate using self-service templates.

Benefits

  • Collaborative work environment within a specialized team focused on Zero Trust Architecture.
  • Opportunity to take on a leadership role with significant responsibilities.
  • Access to cutting-edge technology and tools in identity and access management.
  • Potential for professional development and certifications in cybersecurity.
  • Engagement in high-impact projects that align with national security initiatives.
Full Job Description
Job Description: We are seeking a highly skilled Identity Provider (IdP) Engineer to join our Zero Trust Architecture team. In this role, you will be the one primary architect and administrator for identity services that form the "new perimeter" of our enterprise. You will bridge the gap between traditional networking and modern identity-centric security, ensuring that every access request is fully authenticated, authorized, and encrypted. Core Responsibilities: • Design and implement identity-based access control policies that adhere to Zero Trust principles (Never Trust, Always Verify). • Lead the deployment, configuration, and optimization of PingFederate and PingAccess to provide seamless SSO and attribute-based access control (ABAC). • Manage the full lifecycle of Identity, Credential, and Access Management (ICAM), including automated provisioning and complex directory integrations. • Collaborate with the SOC and Network teams to integrate identity signals into our broader security monitoring and incident response workflows. • Act as the subject matter expert for integrating PingFederate as the core Identity Provider (IdP) with third-party Zero Trust ecosystem components, including Privileged Access Manager (PAM), Master User Record (MUR) and Identity Governance and Administration (IGA). • Create and maintain authentication policies, including Multi-Factor Authentication (MFA) and Risk-Based Authentication (RBA). • Knowledge of directory services (Active Directory, LDAP, Azure AD). • Familiarity with NIST 800-207 Zero Trust Architecture standards. • A security-first mindset with the ability to troubleshoot complex authentication handshakes. • Provide guidance and hands-on training for onboarding new applications into PingFederate using self-service templates, OIDC, and SAML to ensure consistent security standards across the enterprise. Qualifications: • Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related technical field. • Minimum of six (6) years of hands-on experience in ICAM (Identity, Credential, and Access Management) within enterprise or government environments. • Deep proficiency with PingFederate (OIDC, SAML, OAuth protocols). • Strong experience with PingAccess for protecting web applications and APIs at the gateway level. • Active CompTIA Security+ (or equivalent IAT Level II certification) or the ability to obtain within 30 days. • Must possess an active government security clearance (Secret required).

Similar Jobs

More Jobs at Wood River Federal

More Information Technology Jobs

Find similar Identity Provider (IdP) Engineer jobs: