Here's a summary of the role:Identity infrastructure is not glamourware. It doesn't get standing ovations at company all-hands. But it is the thing every product in the portfolio depends on, and when it breaks, everyone knows. If you're the kind of PM who finds that genuinely interesting, read on.
This role is for someone who has lived inside SAML flows, argued over PKCE token lifetimes, and knows exactly why SSO bypass lists are a necessary compromise. You'll own the authentication platform that thousands of enterprise customers trust, and you'll shape it alongside engineers who go deep. No surface-level roadmap ownership here.
Here's a breakdown of what you'll do (not all of it, just the important stuff)- Own the product strategy and roadmap for core authentication flows: SAML 2.0, OIDC/OAuth 2.0 with PKCE, MFA enforcement, token lifecycle management, and multi-IdP federation.
- Make product decisions that sit at the intersection of system design, security architecture, and developer experience, working directly with senior engineers on protocol choices and infrastructure trade-offs.
- Drive adoption of platform identity capabilities across internal engineering teams through influence, moving products toward modern API patterns and away from legacy integration surfaces.
- Use AI coding tools (Claude Code, Cursor, or similar) to prototype ideas and validate concepts before you pitch them; this is expected, not optional.
- Track the IAM standards landscape, including passkeys, FIDO2, SCIM, zero-trust, and verifiable credentials, and use that knowledge to sharpen product direction.
- Translate complex authentication concepts (JWT structures, SAML assertions, PKCE handshakes) into clear specs, user stories, and prioritized backlogs for audiences from engineers to executives.
These are the essentials you'll need to get an interview - Hands-on knowledge of SAML 2.0, OIDC, OAuth 2.0, PKCE, JWT, MFA/TOTP, and SSO federation; you've made production decisions with these, not just read about them.
- Experience owning IAM products, developer-facing identity platforms, or authentication infrastructure in a SaaS environment.
- 3 - 7 years of product management experience on technically complex platform or infrastructure products.
- Comfort with access control concepts: RBAC, ABAC, scopes, entitlements, and user provisioning and deprovisioning flows.
- Experience in a platform or shared services context where your customers are internal engineering teams.
- Familiarity with enterprise IdP ecosystems such as Okta, Azure AD, Ping Identity, or Google Workspace.
- An active AI-native work style; you already use AI tools to investigate systems, prototype integrations, and close the feedback loop with engineering faster.
It would be great if you had these too, but we'll support you if you don't - Exposure to GovCloud or regulated multi-region authentication environments.
- Experience conducting technical teardowns of identity platforms (Auth0, Azure Entra ID, Ping Identity) to inform product strategy.
- Familiarity with verifiable credentials, FIDO2/passkeys, or emerging zero-trust IAM patterns.
Pay Range
$131,000-$164,000 CAD
Headquartered in New York, Diligent has offices in Washington D.C., London, Galway, Budapest, Vancouver, Bengaluru, Munich, Singapore and Sydney. To foster strong collaboration and connection, this role will follow a hybrid work model. If you are within a commuting distance to one of our Diligent office locations, you will be expected to
work onsite at least 50% of the time. We believe that in-person engagement helps drive innovation, teamwork, and a strong sense of community.