About the roleAs Sr. Director of Customer Identity and Access Management, you will own the strategy, execution, and maturity of Zillow's customer identity platform. You will lead three engineering teams through frontline Engineering Managers and directly support two Principal Engineers who anchor the technical direction of the platform.
Three programs define the next two years of this org's work:
- Centralized Authentication Platform. Consolidating authentication across Zillow Group's brands and surfaces onto a single, well-instrumented platform built on a commercial IdP that we extend substantially to meet consumer scale and experience requirements.
- Fine-Grained Authorization Platform. Building an authorization service that lets product teams express and evaluate permissions at the resource level, replacing the bespoke and duplicative access logic scattered across applications today.
- Consumer Domain - Centralized Customer and Identity services. Filling out the domain with authoritative customer and identity services so that profile, account, and entitlement data have one owner and one contract rather than a dozen partial copies.
We are looking for a strong, experienced leader. You come from a high-volume software or platform engineering background and you have never fully left it behind. You can earn trust with Principal Engineers, recruit senior talent who could work anywhere, negotiate roadmaps with internal leadership, and then turn around and frame identity investment in business terms for executives to easily understand. You will set multi-year technical roadmaps, own the operational budget and vendor strategy for your organization, and serve as Zillow's senior voice on customer identity, authentication and authorization.
ResponsibilitiesLeadership and Organizational Strategy
- Lead and develop a multi-team organization through frontline Engineering Managers, setting clear direction, healthy team culture, and high-performance expectations at every level.
- Directly support Principal Engineers who help you understand complex systems, anchor architectural decisions, and identify opportunities to innovate and align.
- Take broad strategy and focus areas from senior leadership and transform them into technical strategies, objectives, and tactical plans your teams can execute against.
- Work hand-in-hand with internal and external AI teams and financial platforms to simplify authentication and authorization while adapting our technical solutions to rapidly evolving areas of our business.
- Establish and execute a 2-3 year roadmap for customer identity that is tightly coupled to product and platform engineering priorities across Zillow Group.
- Own workforce planning, org design, hiring, and the development of a bench of future engineering leaders. Maintain premeditated succession plans and growth pathways for managers and ICs alike.
- Manage budget, tooling portfolio, and vendor relationships across your scope, with a clear view of your org's cost profile and its contribution to overall engineering spend.
- Represent CIAM at the executive level. Translate identity architecture and risk into business impact for leadership.
Centralized Authentication Platform
- Own the strategy for consolidating authentication across Zillow Group brands, surfaces, and acquisitions onto a single platform, sequencing migrations so partner teams are never blocked.
- Drive the extension of our commercial Identity Provider into a platform that meets Zillow-specific requirements for consumer experience, scale, and latency, deciding deliberately where to configure the vendor, where to build around it, and where to build our own solutions.
- Ensure authentication is delivered as a first-class platform capability, with SDKs, reference implementations, and documentation that make correct integration the easy path for product engineers.
- Set direction on account security capabilities including MFA, step-up and conditional access, session management, and account recovery, balancing security posture against consumer conversion and friction.
- Partner with Information Security, Privacy, Legal, and Compliance on identity controls, fraud and abuse patterns, and regulatory obligations.
Fine-Grained Authorization Platform
- Lead the design and delivery of a fine-grained authorization platform capable of high-volume, low-latency policy evaluation across Zillow's product surfaces.
- Establish the authorization model, policy authoring experience, and migration path that lets product teams move off bespoke, application-embedded access logic.
- Ensure the platform is instrumented for auditability, so that "who could access what, and when" is an answerable question.
- Drive adoption across partner orgs. Treat integration count and retired bespoke logic as first-class measures of success, not the shipped service alone.
Consumer Domain: Customer and Identity Services
- Grow our nascent Consumer Domain with centralized Customer and Identity services, establishing clear ownership, contracts, and canonical sources of truth for customer and identity data.
- Drive alignment across the domain to eliminate duplicative and partial implementations, reaching across org boundaries where necessary to get the right outcome for Zillow Group.
- Partner with Product, Data, and downstream consuming teams to define service boundaries that hold up as the business evolves.
- Design for correctness in identity resolution, data lifecycle, and privacy obligations from the start rather than as a retrofit.
Quality, Reliability, and Operations
- Remain accountable for execution and quality across your teams through mechanisms - rituals, processes, inspection, reports, metrics, feedback loops - rather than direct involvement in week-to-week delivery.
- Set the quality bar for systems that are in the critical path of nearly every customer interaction. Authentication outages are company outages.
- Own availability, latency, and cost targets for your platform. Ensure adequate investment in technical quality is prioritized alongside feature delivery.
- Ensure sustainable, low-toil on-call practices and a culture of blameless post-incident review with systemic remediation.
This role has been categorized as a Remote position. "Remote" employees do not have a permanent corporate office workplace and, instead, work from a physical location of their choice, which must be identified to the Company. U.S. employees may live in any of the 50 United States, with limited exceptions.
In California, Connecticut, Maryland, Massachusetts, New Jersey, New York, Washington state, and Washington DC the standard base pay range for this role is $292,200.00 - $466,800.00 annually. This base pay range is specific to these locations and may not be applicable to other locations.In Colorado, Hawaii, Illinois, Maine, Minnesota, Nevada, Ohio, Rhode Island, Vermont, and Virginia the standard base pay range for this role is $277,600.00 - $443,400.00 annually. The base pay range is specific to these locations and may not be applicable to other locations.
In addition to a competitive base salary this position is also eligible for equity awards based on factors such as experience, performance and location. Actual amounts will vary depending on experience, performance and location. Employees in this role will not be paid below the salary threshold for exempt employees in the state where they reside.
Who you are- 12+ years of high-volume engineering experience, with at least 5 years leading through managers in a technology organization where engineering velocity is a first-class value.
- Roots in software or platform engineering. You have built platforms that dev teams rely on, and your technical instincts remain sharp enough to engage credibly with Principal Engineers and architects.
- Deep knowledge and experience of identity and access management concepts and best practices: authentication, authorization, multi-factor authentication, conditional access, session and token management.
- Strong working understanding of OAuth 2.0, OpenID Connect, SAML, and JWT, including the failure modes and tradeoffs, not just the specifications.
- Hands-on background with commercial IAM platforms such as Auth0, Okta, or Ping Identity, including the realities of extending them well beyond out-of-the-box configuration.
- Experience delivering platform capabilities consumed by many teams, with a track record of driving adoption and retiring the systems you replace.
- Deep cloud experience (AWS, Google Cloud, Azure, etc.) and experience with large-scale application architectures where performance, reliability, scalability, availability, and security are all binding constraints.
- Demonstrated ability to drive alignment across multiple VP-level orgs and to identify and redress misalignment proactively, acting firmly even when the decision is unpopular.
- Exceptional communication. You tailor your message from junior engineer to executive, you plan ahead for change management, and you own the message rather than relaying it.
- A talent magnet. A reputation for hiring, coaching, and developing engineers and managers, with the credibility to attract senior ICs who have options.
- BS in Computer Science or a related technical field, or equivalent experience.
Standout Experience:
- Experience building or operating a fine-grained or relationship-based authorization system (Zanzibar-style or similar) at production scale.
- Experience leading a migration or consolidation of authentication across multiple brands, acquisitions, or legacy systems.
- Background in high-volume, consumer-scale B2C identity, where conversion and friction are measured alongside security outcomes.
- Familiarity with domain-driven design and the practical work of establishing canonical services in a large, previously decentralized estate.
- Proficiency in at least one backend language (Go, Java, Python, or similar), sufficient to review the designs and code your teams produce.