Identity Provider Engineer

Capgemini

San Antonio (TX)

On-site

USD 110,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Capgemini is seeking an Identity Provider (IdP) Engineer to join its Zero Trust Architecture team in the United States. You will architect and administer identity services forming the new perimeter of our enterprise, ensuring fully authenticated and authorized access across systems.

You will lead PingFederate and Ping Access deployments, manage ICAM lifecycle, and collaborate with SOC and Network teams to integrate identity signals into security workflows.

Qualifications

  • Active Secret Government clearance requiring U.S. citizenship.
  • Bachelor's degree in CS/IT/Cybersecurity or related field.
  • Minimum 6 years' ICAM experience in enterprise or government environments.
  • Deep proficiency with PingFederate (OIDC, SAML, OAuth).
  • Strong Ping Access experience protecting web apps and APIs.
  • Active CompTIA Security+ (IAT Level II) certification.

Responsibilities

  • Design and implement identity-based access controls in a Zero Trust framework.
  • Lead deployment and optimization of PingFederate and Ping Access for SSO and ABAC.
  • Manage ICAM lifecycle including automated provisioning and directory integrations.
  • Collaborate with SOC and Network teams to integrate identity signals into security workflows.
  • Provide guidance for onboarding applications with PingFederate, including OIDC and SAML templates.

Skills

ICAM
PingFederate
Ping Access
MFA
SAML/OAuth/OIDC
Zero Trust
Directory services

Education

Bachelor's degree in CS/IT/Cybersecurity

Tools

Active Directory
LDAP
Azure AD

Job description

Capgemini Government Solutions (CGS) LLC seeks a highly skilled Identity Provider (IdP) Engineer to join our Zero Trust Architecture team. In this role, you will be the one primary architect and administrator for identity services that form the "new perimeter" of our enterprise. You will bridge the gap between traditional networking and modern identity-centric security, ensuring that every access request is fully authenticated, authorized, and encrypted.

Job Responsibilities

As Identity Provider (IdP) Engineer, you will be responsible for:

  • Design and implement identity-based access control policies that adhere to Zero Trust principles (Never Trust, Always Verify).
  • Lead the deployment, configuration, and optimization of PingFederate and Ping Access to provide seamless SSO and attribute-based access control (ABAC).
  • Manage the full lifecycle of Identity, Credential, and Access Management (ICAM), including automated provisioning and complex directory integrations.
  • Collaborate with the SOC and Network teams to integrate identity signals into our broader security monitoring and incident response workflows.
  • Act as the subject matter expert for integrating PingFederate as the core Identity Provider (IdP) with third-party Zero Trust ecosystem components, including Privileged Access Manager (PAM), Master User Record (MUR) and Identity Governance and Administration (IGA).
  • Create and maintain authentication policies, including Multi-Factor Authentication (MFA) and Risk-Based Authentication (RBA).
  • Knowledge of directory services (Active Directory, LDAP, Azure AD).
  • Familiarity with NIST 800-207 Zero Trust Architecture standards.
  • A security-first mindset with the ability to troubleshoot complex authentication handshakes.
  • Provide guidance and hands-on training for onboarding new applications into PingFederate using self-service templates, OIDC, and SAML to ensure consistent security standards across the enterprise.
Required Qualifications
  • Have an active Secret Government security clearance that requires U.S. citizenship
  • Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related technical field.
  • Minimum of 6 years of hands-on experience in ICAM (Identity, Credential, and Access Management) within enterprise or government environments.
  • Deep proficiency with PingFederate (OIDC, SAML, OAuth protocols).
  • Strong experience with Ping Access for protecting web applications and APIs at the gateway level.
  • Active CompTIA Security+ (or equivalent IAT Level II certification) to meet compliance requirements
About Capgemini

Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem. The Group reported 2024 global revenues of €22.1 billion.

Get the future you want | www.capgemini.com

Disclaimer

All qualified applicants will be considered for employment based on their skills, and merit.

Please be aware that Capgemini may capture your image (video or screenshot) during the interview process and that image may be used for verification, including during the hiring and onboarding process.

Applicants for employment in the US must have valid work authorization that does not now and/or will not in the future require sponsorship of a visa for employment authorization in the US by Capgemini.

Capgemini discloses salary range information in compliance with state and local pay transparency obligations. The disclosed range represents the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting, although we may ultimately pay more or less than the disclosed range, and the range may be modified in the future. The disclosed range takes into account the wide range of factors that are considered in making compensation decisions including,

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity Provider Engineer with Security Clearance
Identity Provider Engineer with Security Clearance

Capgemini Government Solutions • San Antonio (TX)

On-site
USD 130,000 - 145,000
Identity Provider Engineer
Identity Provider Engineer

Capgemini Government Solutions • San Antonio (TX)

On-site
USD 130,000 - 145,000
Identity Platform (IdP) Engineer
Identity Platform (IdP) Engineer

Capgemini Government Solutions • San Antonio (TX)

On-site
USD 110,000 - 125,000
Paid time off
Medical/dental/vision insurance
401(k)
Zero-Trust Identity Platform Engineer
Zero-Trust Identity Platform Engineer

Capgemini Government Solutions • San Antonio (TX)

On-site
USD 130,000 - 145,000
Zero-Trust Identity Engineer | PingFederate & SSO Specialist
Zero-Trust Identity Engineer | PingFederate & SSO Specialist

Capgemini Government Solutions • San Antonio (TX)

On-site
USD 130,000 - 145,000
Zero Trust IdP Engineer | PingFederate & ICAM Expert
Zero Trust IdP Engineer | PingFederate & ICAM Expert

Capgemini • San Antonio (TX)

On-site
USD 110,000 - 170,000
Identity Governance and Administration (IGA) Engineer
Identity Governance and Administration (IGA) Engineer

Capgemini Government Solutions LLC • San Antonio (TX)

Hybrid
USD 66,000 - 125,000
Governance and Administration (IGA) Engineer
Governance and Administration (IGA) Engineer

Capgemini Government Solutions • San Antonio (TX)

Hybrid
USD 110,000 - 125,000
Identity Platform Architect, Zero Trust & SSO
Identity Platform Architect, Zero Trust & SSO

Capgemini Government Solutions • San Antonio (TX)

On-site
USD 110,000 - 125,000
Paid time off
Medical/dental/vision insurance
401(k)
ICAM Sustainment Analyst
ICAM Sustainment Analyst

Capgemini • San Antonio (TX)

On-site
USD 70,000 - 80,000