CISO Technical Lead SSO Engineer

Tata Consultancy Services

Irving (TX)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tata Consultancy Services in Irving, TX is seeking an experienced IAM professional to lead the design, deployment, and governance of PingFederate-based SSO across large-scale environments. You will drive secure migration, federation strategies, and integration with Active Directory, Azure AD, and LDAP stores, ensuring high availability and regulatory compliance.

The role emphasizes scripting (PowerShell, Python), troubleshooting, and collaboration with application teams to onboard new apps and

Qualifications

  • Bachelor's degree in computer science, information security, or related field.
  • 5+ years of dedicated experience in Identity and Access Management (IAM), with at least 3 years focused on SSO technologies.
  • Proficiency in designing, implementing, and managing PingFederate in large-scale enterprise environments.
  • Understanding and hands-on experience with identity federation protocols such as SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
  • Experience integrating SSO solutions with various applications and identity stores (e.g., Active Directory, Azure AD, LDAP).
  • Proficiency in scripting languages (e.g., PowerShell, Python) for automation and administration tasks.
  • Excellent analytical, problem-solving, and communication skills, with the ability to articulate complex technical concepts to both technical and non-technical audiences.
  • Required: English fluency (oral and written).

Responsibilities

  • Drive development and execution strategies for the secure separation, migration, and integration of PingFederate instances, configurations, and associated identity stores for divested business units.
  • Plan and implement identity federation solutions to support application access for users transitioning between organizations, ensuring minimal disruption.
  • Manage the lifecycle of federated trusts, connections, and identity providers/service providers in the context of divestiture, including onboarding and offboarding applications.
  • Design, deploy, configure, and maintain high-availability PingFederate environments across various enterprise landscapes.
  • Administer PingFederate connections, policies, adapters, selectors, and authentication methods (e.g., SAML, OAuth, OIDC).
  • Troubleshoot complex SSO authentication, authorization, and federation issues to ensure continuous service availability.
  • Identity & Access Integration: Integrate PingFederate with various identity stores such as Active Directory, Azure Active Directory, and LDAP directories.
  • Collaborate with application owners to onboard new applications and migrate existing ones to the PingFederate SSO platform.
  • Ensure seamless integration with Multi-Factor Authentication (MFA) solutions.
  • Security & Compliance: Implement and enforce security best practices and architectural guidelines for identity federation and SSO solutions.
  • Ensure that SSO configurations comply with corporate security policies, regulatory requirements, and data governance standards during the divestiture process.
  • Conduct regular security reviews and vulnerability assessments of the PingFederate environment.
  • Operational Support & Documentation: Provide expert-level support for SSO-related incidents and requests, often collaborating with cross-functional IT and security teams.
  • Develop and maintain comprehensive documentation, architectural diagrams, runbooks, and standard operating procedures (SOPs) for the SSO infrastructure.

Skills

PingFederate
SSO technologies
Identity and Access Management
SAML 2.0
OAuth 2.0
OIDC
Active Directory
Azure AD
LDAP
PowerShell
Python
Automation scripting
Communication skills
English fluency

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

PowerShell
Python
Active Directory

Job description

Responsibilities
  • Drive development and execution strategies for the secure separation, migration, and integration of PingFederate instances, configurations, and associated identity stores for divested business units.
  • Plan and implement identity federation solutions to support application access for users transitioning between organizations, ensuring minimal disruption.
  • Manage the lifecycle of federated trusts, connections, and identity providers/service providers in the context of divestiture, including onboarding and offboarding applications.
  • Design, deploy, configure, and maintain high-availability PingFederate environments across various enterprise landscapes.
  • Administer PingFederate connections, policies, adapters, selectors, and authentication methods (e.g., SAML, OAuth, OIDC).
  • Troubleshoot complex SSO authentication, authorization, and federation issues to ensure continuous service availability.
  • Identity & Access Integration: Integrate PingFederate with various identity stores such as Active Directory, Azure Active Directory, and LDAP directories.
  • Collaborate with application owners to onboard new applications and migrate existing ones to the PingFederate SSO platform.
  • Ensure seamless integration with Multi-Factor Authentication (MFA) solutions.
  • Security & Compliance: Implement and enforce security best practices and architectural guidelines for identity federation and SSO solutions.
  • Ensure that SSO configurations comply with corporate security policies, regulatory requirements, and data governance standards during the divestiture process.
  • Conduct regular security reviews and vulnerability assessments of the PingFederate environment.
  • Operational Support & Documentation: Provide expert-level support for SSO-related incidents and requests, often collaborating with cross-functional IT and security teams.
  • Develop and maintain comprehensive documentation, architectural diagrams, runbooks, and standard operating procedures (SOPs) for the SSO infrastructure.
Deliverables
  • Secure Divestiture & Federated Identity Transition
  • Resilient PingFederate & SSO Platform Operations
  • Security, Compliance & Operational Excellence
Required Skills / Expertise
  • Bachelor’s degree in computer science, Information Security, or a related technical field, or equivalent practical experience.
  • 5+ years of dedicated experience in Identity and Access Management (IAM), with at least 3 years focused specifically on SSO technologies.
  • Proficiency in designing, implementing, and managing PingFederate in large-scale enterprise environments.
  • Understanding and hands-on experience with identity federation protocols such as SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
  • Experience integrating SSO solutions with various applications and identity stores (e.g., Active Directory, Azure AD, LDAP).
  • Proficiency in scripting languages (e.g., PowerShell, Python) for automation and administration tasks.
  • Excellent analytical, problem-solving, and communication skills, with the ability to articulate complex technical concepts to both technical and non-technical audiences.
  • Required: English fluency (oral and written).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CISO Technical Lead – SSO Engineer
CISO Technical Lead – SSO Engineer

Recutify Inc. • Irving (TX)

On-site
USD 150,000 - 210,000
Senior SSO Architect & PingFederate Lead (Onsite)
Senior SSO Architect & PingFederate Lead (Onsite)

Recutify Inc. • Irving (TX)

On-site
USD 150,000 - 210,000
Senior IAM Engineer: Ping Identity & Cloud SSO Lead
Senior IAM Engineer: Ping Identity & Cloud SSO Lead

Veriipro • McLean (VA)

On-site
Senior PingFederate SSO Architect & Divestiture Lead
Senior PingFederate SSO Architect & Divestiture Lead

Tata Consultancy Services • Irving (TX)

On-site
USD 120,000 - 160,000
Senior Specialist, Lead Zero Trust Identity Security Engineering
Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard • Dallas (TX)

On-site
USD 190,000 - 230,000
PingFederate Identity Engineer
PingFederate Identity Engineer

Quadrant, Inc. • Sterling (VA)

On-site
USD 150,000 - 180,000
Healthcare benefits
Ping Security Analyst
Ping Security Analyst

Veriipro • Seattle (WA)

On-site
USD 85,000 - 120,000
Ping Identity Architect
Ping Identity Architect

Securdi LLP. • United States

Hybrid
USD 120,000 - 160,000
Senior Specialist, Lead Zero Trust Identity Security Engineering
Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard • Malvern (AR)

On-site
USD 120,000 - 190,000
Visa sponsorship
Ping Federate Architect
Ping Federate Architect

Comtech LLC • Minneapolis (MN)

On-site
USD 80,000 - 100,000