Senior Specialist, Lead Zero Trust Identity Security Engineering

$120K — $150K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Undergraduate degree in a related field or equivalent training/experience.
  • 12+ years in Identity & Access Management engineering.
  • DevOps tool familiarity and policy as code experience.
  • Deep hands-on expertise with Okta (Workforce Identity, MFA, SSO, policies, lifecycle).
  • Strong working knowledge of Ping Identity products or equivalents.
  • Expert understanding of identity standards including OAuth 2.0 and SAML.
  • Proven experience with directory services & LDAP (AD, cloud directories).
  • Experience with identity platforms in AWS/GCP, including Kubernetes deployments.
  • Strong troubleshooting skills for authentication and federation issues.

Responsibilities

  • Serve as technical lead for workforce identity platforms with Okta integration.
  • Own end-to-end identity architecture including authentication flows and token issuance.
  • Lead design reviews for IdP resiliency and supplier risk strategies.
  • Document architecture and set technical direction and standards.
  • Design troubleshoot identity flows using key protocols like OAuth 2.0 and SAML.
  • Ensure token parity and compliance across identity providers.
  • Engineer and maintain directory integrations and attribute models.
  • Automate identity infrastructure operations and support SRE-style practices.
  • Design identity controls aligned with Zero Trust principles.
  • Collaborate with teams across security, engineering, and operations.

Benefits

  • Visa sponsorship available for this role.
Full Job Description

Key Responsibilities

Identity Platform Engineering & Leadership

  • Serve as technical lead for workforce identity platforms, with Okta as the primary IdP and integrations to complementary platforms (e.g., Ping/Entra Identity).

  • Own end0end identity architecture, including authentication flows, federation, directory integrations, and token issuance.

  • Lead design reviews and decisions for IdP resiliency, failover, and supplier0risk mitigation strategies.

  • Document existing and new architecture and act as a hands0on engineer while also setting technical direction, patterns, and standards.

  • Strong communication, influence, and stakeholder0management skills, with the ability to distill complex identity and security architectures into clear and concise messaging

Standards0Based Identity & Federation

  • Design and troubleshoot identity flows using OAuth 2.0 / OIDC SAML 2.0 SCIM JWT / token0based auth

  • Ensure token parity, claim consistency, and issuer abstraction across identity providers to minimize application impact.

  • Partner with application teams to enable modern authentication without app re0architecture.

Directory & Identity Data Architecture

  • Engineer and maintain directory integrations across Active Directory, Okta UD, and cloud directories (e.g., Ping Directory).

  • Design attribute models, lifecycle management, and group strategies at enterprise scale (thousands of groups, large population sizes).

  • Support directory deployments in cloud0native environments (AWS/GCP, containers, Kubernetes).

Cloud, Automation & Reliability

  • Build and operate identity infrastructure in AWS/GCP/Azure, using: Infrastructure & Policy as Code (Terraform / CloudFormation) Kubernetes & containerized identity services

  • Automate provisioning, deployment, monitoring, and drift detection for identity platforms.

  • Support SRE0style operational maturity: SLIs/SLOs, alerting, incident response, and runbooks for identity services.

Security, Risk & Compliance

  • Design identity controls aligned to Zero Trust principles and enterprise security policies.

  • Partner with CSOC, audit, and risk teams on: Control validation Incident response Regulatory and audit requirements (SOX, SOC, internal controls)

  • Contribute to risk assessments related to supplier dependency, SPOFs, and identity outages.

Collaboration & Influence

  • Work closely with security architecture, infrastructure, application engineering, IAM operations, and vendors.

  • Influence roadmap decisions through clear technical reasoning and executive0ready communication.

  • Mentor senior and mid0level engineers and raise overall identity engineering maturity.

Qualifications

  • Undergraduate degree in a related field or the equivalent combination of training and experience.

  • 12+ years of experience in Identity & Access Management engineering.

  • Skilled in using DevOps tools and experience in Policy as code.

  • Deep hands0on expertise with Okta (Workforce Identity, MFA, SSO, policies, lifecycle).

  • Strong working knowledge of Ping Identity products (PingFederate, PingOne, Ping Directory) or equivalent platforms.

  • Expert understanding of identity standards: OAuth 2.0, OIDC, SAML Federation and token0based security

  • Proven experience with directory services & LDAP (AD, cloud directories).

  • Experience building identity platforms in AWS/GCP, including containerized/Kubernetes deployments.

  • Strong troubleshooting skills for complex authentication and federation failures.

  • Ability to operate in high0visibility, high0impact environments.

Special Factors

Sponsorship

Vanguard is offering visa sponsorship for this position.

Similar Jobs

More Jobs at

More Information Technology Jobs

Find similar Senior Specialist, Lead Zero Trust Identity Security Engineering jobs: