Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France

Los Angeles (CA)

On-site

USD 135,000 - 265,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Deloitte Cyber seeks a seasoned PlainID IAM specialist to lead policy design, integration, and governance for client environments in a role with substantial travel. You will partner with enterprise architects, drive PBAC/ABAC implementations, and guide complex integrations with Okta, MS Entra, and API gateways, while ensuring regulatory compliance and robust audit trails.

You will own policy lifecycle activities, document runbooks and diagrams, and steer go-live readiness, proving strong

Qualifications

  • 7+ years of total experience including hands-on PlainID and access management.
  • 3+ years with PBAC and how it maps to enterprise use cases.
  • 3+ years with complex integrations/connectors for PIP integration.
  • Strong knowledge of compliance including SOX, GDPR, and ISO standards.
  • Experience with identity providers and protocols: OAuth 2.0, OpenID Connect, SAML, JWT.
  • Policy-as-code concepts and reading/writing structured policy logic.
  • Knowledge of APIs/microservices and at least one API gateway (Apigee, Kong, Azure API Management).
  • CAB/change governance, release management, and stakeholder management.
  • Advanced troubleshooting of PlainID integration.
  • Ability to travel 25-50% and potential immigration sponsorship.

Responsibilities

  • Configure and implement the PlainID Authorization Platform within client environments.
  • Lead technical discussions with Enterprise architects and IAM stakeholders.
  • Lead a PBAC team for delivery.
  • Design fine-grained, ABAC policies translating business rules into controls.
  • Integrate PlainID with identity providers, API gateways, microservices, and data platforms.
  • Support full policy lifecycle using policy modeling and policy-as-code.
  • Run requirements sessions to document current-state access patterns and target-state model.
  • Troubleshoot policy conflicts and integration issues across the stack.
  • Lead testing, validation, and go-live activities with access-decision auditing.
  • Produce documentation: policy catalogs, integration diagrams, runbooks.
  • Partner with engagement leads to keep delivery on track and surface risks.
  • Stay current on PlainID roadmap and new capabilities.
  • Establish runbooks, SOPs, knowledge articles, and documentation standards.
  • Lead conversations with stakeholders and vendors to resolve defects and dependencies.

Skills

Policy governance
Stakeholder management
Executive communication

Tools

PlainID
OAuth 2.0
OpenID Connect
SAML
JWT
Apigee
Kong
Azure API Management

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a PlainID professional, you will:

  • Configure and implement the PlainID Authorization Platform within client environments, including policy modelling and decision-point/information-point setup.

  • Lead technical discussions with Enterprise architects and IAM stake holders.

  • Lead a PBAC team for successful and seamless delivery.

  • Design fine-grained, attribute-based access policies (PBAC/ABAC) that translate business rules into technical controls, including row- and column-level data access restrictions where needed.

  • Integrate PlainID with client identity providers (Okta, Microsoft Entra ID, Ping Identity, ForgeRock), API gateways, microservices, and data platforms such as Snowflake or Big Query.

  • Support the full policy lifecycle - authoring, testing, versioning, and deployment - using PlainID's visual policy modeling and policy-as-code capabilities.

  • Run requirements sessions with client stakeholders to document current-state access patterns and design the target-state authorization model.

  • Troubleshoot policy conflicts, integration issues, and authorization-decision errors across the client's technology stack.

  • Lead the testing, validation, and go-live activities, including access-decision auditing and performance checks.

  • Lead the team to produce clear technical documentation - policy catalogs, integration diagrams, runbooks - for both the client and the internal delivery team.

  • Partner with engagement leads and architects to keep delivery on track and surface risks early.

  • Stay current on PlainID's platform roadmap, including emerging capabilities for AI agent and machine-identity authorization.

  • Lead the team to establish and maintain runbooks, SOPs, knowledge articles, and documentation standards for repeatable and governed support operations.

  • Lead the conversation with client stakeholders, internal teams, and third-party vendors to resolve defects, manage dependencies, and improve service outcomes.

Enables trust and safety of online communications and digital products, protecting users, consumers, and patients from harm. Enables clients to provide consumer confidence in knowing with whom they are dealing and ensuring the integrity of access to data.

Qualifications

Required :

  • 7+ years of total experience, including strong hands-on experience in PlainID and access management implementation.
  • 3+ years with access control models - specifically PBAC - and how each maps to real enterprise use cases.
  • 3+ years of experience integrating and supporting complex integrations and connectors for PIP integration.
  • Must have strong knowledge of ensuring compliance with internal and external regulations, including SOX, GDPR, and ISO standards.
  • Experience integrating with identity providers and standard protocols: OAuth 2.0, OpenID Connect, SAML, JWT.
  • Comfort with policy-as-code concepts and reading/writing structured policy logic (e.g., Rego or similar rules-based languages).
  • Working knowledge of APIs and microservices architectures, plus experience with at least one API gateway (Apigee, Kong, Azure API Management, or similar).
  • Proven ownership of CAB/change governance, release management, and stakeholder management.
  • Advanced troubleshooting capability with strong knowledge of PlainID integration.
  • Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.
Preferred
  • Previous consulting or Big 4 experience preferred.
  • Experience with RBAC, ABAC
  • Strong documentation, reporting, and executive communication skills.
  • Ability to manage vendor coordination

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

#CyberDTP27

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • Cincinnati (OH)

On-site
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • Jersey City (NJ)

On-site
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • Minneapolis (MN)

On-site
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • New Orleans (LA)

On-site
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • Indianapolis (IN)

Hybrid
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • Kansas City (MO)

On-site
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • Jacksonville (FL)

On-site
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • Morristown (NJ)

On-site
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • San Antonio (TX)

On-site
USD 135,000 - 265,000
Cyber Identity - PlainID/PBAC Engineering Manager II
Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte France • Costa Mesa (CA)

On-site
USD 135,000 - 265,000