Lead Cloud Identity Engineer

Koch

Atlanta (GA)

Hybrid

USD 170,000 - 230,000

Full time

38 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical benefits
Dental and vision
Retirement plan

Job summary

Koch is seeking a Lead Cloud Identity Engineer to join its global engineering team. You will shape IAM architecture across platforms, implement SSO, MFA, and risk-based auth, and drive governance for identity patterns.

As lead developer for IAM platforms, you will build connectors, APIs, and orchestration flows, plus automate lifecycle using Terraform and CI/CD. Hybrid in-office role with global exposure and collaboration across Koch businesses.

Qualifications

  • Extensive, hands-on experience owning identity platforms at scale.
  • Deep protocol-level expertise across SAML, OAuth2/OIDC, SCIM, FIDO2.
  • Strong cloud identity architecture across Azure, AWS, or GCP.

Responsibilities

  • Set IAM architecture & standards with reusable SSO/federation patterns.
  • Lead design governance for identity reviews and pattern adoption.
  • Build authentication and federation including MFA and risk-based auth.
  • Operate and enhance PingOne/Identity orchestration platforms.
  • Lead development for identity platforms with connectors and APIs.
  • Design RBAC/ABAC/PBAC models and IGA workflows.
  • Lead end-to-end JML automation integrating HRIS, ITSM, SCIM.
  • Manage Terraform-based identity configuration with CI/CD.
  • Implement least privilege and continuous verification; monitor and respond.
  • Escalate auth outages and drive post-incident hardening.

Skills

SAML
OAuth2/OIDC
SCIM
FIDO2/passkeys
LDAP
Kerberos
Python
TypeScript

Tools

Azure Entra ID
AWS IAM
Google Cloud Identity
Terraform
PingOne DaVinci
Okta Workflows
SailPoint IdentityNow/IdentityIQ

Job description

Your Job

We have an exciting opportunity to hire a Lead Cloud Identity Engineer to join our already skilled engineering team. This individual will be a part of a global team that manages authentication and identity tools and procedures for Koch Industries. Working closely with global colleagues, as well as customers, will provide significant global exposure.

We have an exciting opportunity to hire a Lead Cloud Identity Engineer to join our already skilled engineering team. This individual will be a part of a global team that manages authentication and identity tools and procedures for Koch Industries. Working closely with global colleagues, as well as customers, will provide significant global exposure.

Our Team

The Koch Technology Identity team provides modern Identity solutions and services for all Koch businesses. We are responsible for the entire enterprise in designing innovative services, creating, and sharing best practices, and providing support for our services.

Location

This role can be located in Wichita, KS / Atlanta, GA / Plano, TX and requires an in office presence with flexibility.

This role is not eligible for VISA sponsorship.
What You Will Do
  • Set IAM architecture & standards: Define reusable patterns for SSO/federation, authorization models, privileged access, and workload/machine identity.
  • Lead design governance: Run identity design reviews for new applications and major platform changes; approve patterns, manage exceptions, and drive adoption.
  • Build authentication & federation: Design and implement SAML2, OAuth2/OIDC, WS-Fed, and FIDO2/passkeys, including adaptive/risk-based auth, conditional access, and MFA.
  • Engineer IAM platforms: Operate and enhance enterprise identity services (PingOne / PingOne DaVinci or equivalent orchestration platforms).
  • Lead developer for IAM platforms: Serve as lead developer driving hands-on code development to build, extend, and maintain new and existing identity platforms, including custom connectors, APIs, and orchestration flows.
  • Design authorization & governance: Build scalable RBAC/ABAC/PBAC models, entitlement catalogs, role engineering, and access request workflows (IGA).
  • Automate identity lifecycle: Lead and design end-to-end JML automation integrating HRIS, ITSM, directories, and apps via SCIM and event-driven pipelines.
  • Identity as Code: Manage identity configuration/policy using Terraform and CI/CD with testing, version control, and deployment discipline.
  • Zero Trust & Detection: Implement least privilege and continuous verification; integrate ITDR-style monitoring, logging, alerting, SLOs, and rapid revocation.
  • Incident leadership: Act as escalation for auth outages, federation issues, and credential compromise; lead RCA and post-incident hardening.
  • Influence & mentoring: Partner globally with architects, developers, and security; coach engineers through reviews, playbooks, and training.
Who You Are (Basic Qualifications)
  • Extensive experience owning identity platforms at scale, with deep protocol-level expertise across SAML, OAuth2/OIDC, SCIM, FIDO2/passkeys, LDAP, and Kerberos.
  • Hands-on architecture across Azure Entra ID, AWS IAM, or Google Cloud Identity, including cross-cloud federation and hybrid identity patterns.
  • Practical experience designing and building infrastructure across Azure, AWS, or GCP.
  • Strong coding skills in Python and/or TypeScript, with API integrations, Git, CI/CD, and automated testing. Delivery of identity configuration as versioned, testable code using Terraform or similar technologies.
  • Hands-on experience integrating diverse applications with enterprise governance platforms; design and delivery of JML automation, RBAC/ABAC/PBAC models and access workflows integrating HRIS → IAM → downstream apps via SCIM and event-driven pipelines.
What Will Put You Ahead
  • Experience building multi-step user journeys for Workforce, CIAM, and partner ecosystems using platforms such as PingOne DaVinci or Okta Workflows.
  • Hands-on development and design experience with SailPoint IdentityNow/IdentityIQ (or equivalent).
  • Real-time detection and response to identity-based threats, integrating signals from IdPs, directories, and SIEM/SOAR platforms.
Hiring Philosophy

All Koch companies value diversity of thought, perspectives, aptitudes, experiences, and backgrounds. We are Military Ready and Second Chance employers.

Who We Are

Koch creates and innovates a wide spectrum of products and services that make life better. Our work spans a vast number of industries across the world, including engineered technology, refining, chemicals and polymers, pulp and paper, glass, electronics and many more. Headquartered in Wichita, Kansas, Koch employs about 120,000 employees across the globe.

At Koch, employees are empowered to do what they do best to make life better. Learn how our business philosophy helps employees unleash their potential while creating value for themselves and the company.

Our Benefits
  • Our benefits plan includes - medical, dental, vision, flexible spending and health savings accounts, life insurance, ADD, disability, retirement, paid vacation/time off, educational assistance, and may also include infertility assistance, paid parental leave and adoption assistance.
  • Specific eligibility criteria is set by the applicable Summary Plan Description, policy or guideline and benefits may vary by geographic region.

Additionally, everyone has individual work and personal needs. We seek to enable the best work environment that helps you and the business work together to produce superior results.

Equal Opportunities

Equal Opportunity Employer, including disability and protected veteran status. Except where prohibited by state law, some offers of employment are conditioned upon successfully passing a drug test. This employer uses E-Verify.

At Koch companies, we are entrepreneurs. This means we openly challenge the status quo, find new ways to create value and get rewarded for our individual contributions. Any compensation range provided for a role is an estimate determined by available market data. The actual amount may be higher or lower than the range provided considering each candidate's knowledge, skills, abilities, and geographic location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cloud Identity Engineer
Lead Cloud Identity Engineer

Koch • Plano (TX)

On-site
USD 140,000 - 190,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Lead Cloud Identity Engineer
Lead Cloud Identity Engineer

Koch • Wichita (KS)

On-site
USD 170,000 - 210,000
Medical benefits
Dental benefits
Retirement plan
+1
Lead Cloud Identity Engineer
Lead Cloud Identity Engineer

Koch Business Solutions, LP • Plano (TX)

Hybrid
USD 110,000 - 150,000
Medical, dental, vision insurance
Flexible spending and health savings accounts
Paid vacation/time off
+1
Lead Cloud Identity Engineer
Lead Cloud Identity Engineer

Koch Business Solutions, LP • Wichita (KS)

On-site
USD 130,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+2
Lead Cloud Identity Engineer
Lead Cloud Identity Engineer

Koch Business Solutions, LP • Atlanta (GA)

On-site
USD 120,000 - 160,000
Medical, dental, and vision insurance
Flexible spending and health savings accounts
Paid parental leave and adoption assistance
Lead Linux Engineer
Lead Linux Engineer

Koch Business Solutions, LP • Atlanta (GA)

On-site
USD 140,000 - 190,000
Competitive benefits
Lead Linux Engineer
Lead Linux Engineer

Koch • Wichita (KS)

On-site
USD 120,000 - 180,000
Collaboration Solutions Engineer
Collaboration Solutions Engineer

Koch Business Solutions, LP • Wichita (KS)

Hybrid
USD 75,000 - 110,000
Lead Linux Engineer
Lead Linux Engineer

Koch Business Solutions, LP • Wichita (KS)

On-site
USD 120,000 - 180,000
Lead Linux Engineer
Lead Linux Engineer

Koch • Plano (TX)

On-site
USD 140,000 - 190,000
Medical, dental, vision
Retirement plan
Paid time off