Job Summary
The Ping Directory Lead Engineer / SME will provide senior technical leadership and hands-on engineering expertise for an enterprise-scale identity directory platform. The role will own the technical strategy, architecture, engineering standards, security, reliability, and lifecycle of the Ping Directory environment. The engineer will design and support highly available directory services using Ping Directory, PingDirectoryProxy, and PingDataSync while leading Active Directory migration, modernization, cloud adoption, automation, and enterprise integrations. The role requires the ability to operate at both architecture and deep technical engineering levels while collaborating with IAM, cybersecurity, infrastructure, cloud, application, and enterprise architecture teams.
Key Responsibilities
• Own the technical strategy, architecture, engineering standards, and lifecycle roadmap for the Ping Directory platform.
• Design, implement, and support Ping Directory, PingDirectoryProxy, and PingDataSync environments.
• Develop and maintain directory schemas, indexes, replication, synchronization, access controls, password policies, and virtual attributes.
• Lead Active Directory migration and modernization initiatives, including dependency discovery, data mapping, coexistence, cutover, validation, and rollback planning.
• Design and implement integrations with identity providers, cloud platforms, privileged access solutions, LDAP/LDAPS, REST APIs, and SCIM consumers.
• Automate infrastructure and configuration using Terraform, Git, Infrastructure as Code, and CI/CD pipelines.
• Support cloud and containerized deployment patterns, including AWS and Kubernetes environments.
• Ensure platform resiliency through capacity planning, performance tuning, monitoring, backup and recovery, disaster recovery, and failover testing.
• Implement and maintain security controls including least privilege, secure LDAP and replication, privileged and non-human identities, audit logging, and SIEM integration.
• Provide senior-level production support, including incident leadership, troubleshooting, root cause analysis, and permanent remediation.
• Lead production changes and releases, ensuring appropriate testing, validation, data integrity, monitoring, and backout procedures.
• Perform platform upgrades, patching, configuration changes, and lifecycle management.
• Develop and maintain architecture documentation, implementation standards, runbooks, recovery procedures, and operational documentation.
• Partner with IAM, cybersecurity, infrastructure, cloud, application, audit, and vendor teams to resolve complex technical issues and drive platform improvements.
• Participate in an on-call rotation for critical incidents, releases, failover events, and recovery exercises.
Required Qualifications
• Extensive enterprise experience with Ping Directory, including architecture, implementation, engineering, and production support.
• Strong hands-on experience with Ping Directory, PingDirectoryProxy, and PingDataSync.
• Deep understanding of LDAP/LDAPS, directory architecture, schema design, indexes, replication, synchronization, access controls, and high availability.
• Proven experience leading large-scale Active Directory migrations, directory modernization, or enterprise LDAP initiatives.
• Experience designing and supporting business-critical, highly available directory platforms.
• Strong experience with directory security, including least privilege, secure replication, privileged and non-human identities, audit logging, and certificate management.
• Hands-on experience with Terraform, Git, Infrastructure as Code, and CI/CD automation.
• Experience with AWS or another major cloud platform and preferably Kubernetes or containerized environments.
• Strong Linux administration and troubleshooting skills.
• Experience with Python, PowerShell, or shell scripting for automation and operational tooling.
• Experience integrating directory services with enterprise IAM technologies and applications.
• Strong production engineering skills, including incident management, root cause analysis, performance tuning, monitoring, backup and recovery, and disaster recovery.
• Ability to serve as a senior technical authority and work effectively across IAM, security, infrastructure, cloud, application, and architecture teams.
• Bachelor's degree in Computer Science, Engineering, Cybersecurity, or a related discipline, or equivalent practical experience.
Preferred Qualifications
• Experience with Okta, Microsoft Entra ID, PingFederate, or other enterprise identity providers.
• Experience with SCIM, REST APIs, identity lifecycle management, and privileged access management (PAM).
• Experience with Splunk or similar SIEM or observability platforms.
• Experience with Java/JVM tuning in support of Ping Directory environments.
• Experience with secrets management and automated certificate lifecycle management.
• Experience designing directory platforms in Kubernetes or cloud-native environments.
• Experience supporting highly regulated environments with significant audit, compliance, and security requirements.
• Experience leading enterprise-wide directory transformation or Active Directory decommissioning programs.
• Strong experience developing technical standards, architecture documentation, implementation guides, and operational runbooks.
Certifications
• Ping Identity or relevant cloud/security certifications are preferred.