Lead, Infrastructure Security Engineer - Customer Identity & Access Management

PGIM Ireland

The Ironbound (NJ)

On-site

USD 134,000 - 220,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical benefits (health)
401(k) plan with company match
Pension plan
Wellness programs

Job summary

PGIM is seeking a Lead Infrastructure Security Engineer to drive secure CIAM solutions across global identity platforms. You will design, build, test, automate, and support security capabilities with emphasis on PingOne Advanced Identity Cloud, fraud controls, and adaptive authentication across web and mobile ecosystems.

You will partner with technical leads, product owners, and fraud/cyber teams to implement robust authentication, authorization, and lifecycle flows, while ensuring

Qualifications

  • Bachelor’s degree or equivalent with senior-level IAM/security depth.
  • 5+ years in IAM/security/software/platform/cloud with global scope.
  • Experience delivering CIAM solutions and large-scale app integrations.
  • Hands-on with PingOne Advanced Identity Cloud SAAS and related components.
  • Strong REST API design, security controls, and logging/observability.

Responsibilities

  • Lead design, development, testing, and automation of CIAM security capabilities.
  • Implement secure customer authentication, authorization, and identity proofing workflows.
  • Collaborate with tech leads, product owners, and fraud/cyber teams to balance security and user experience.
  • Develop and maintain custom journeys, nodes, and decision logic within PingOne AIC.
  • Enhance platform observability using Splunk and Dynatrace, and drive production readiness.

Skills

CIAM security
PingOne AIC
Security architecture
REST API design
JavaScript/TypeScript
Leadership
Cloud platforms

Education

Bachelor’s degree in CS/Engineering or related

Tools

PingOne AIC
PingOne Protect
Splunk
Dynatrace
Postman
AWS EKS

Job description

Job Classification: Technology - Engineering & Cloud

Are you interested in engineering secure, scalable, and intelligent identity platforms that protect millions of customer interactions? The Global Technology Security Services team is building the next generation of Customer Identity and Access Management capabilities through cloud identity platforms, adaptive authentication, fraud and risk detection, software engineering, automation, and modern authorization patterns.

Your Team & Role

As a Lead Infrastructure Security Engineer on our CIAM Team, you will lead, design, develop, test, automate, and support security capabilities across the global CIAM ecosystem, with primary emphasis on PingOne Advanced Identity Cloud, PingOne Protect, customer authentication journeys, CIAM APIs, mobile and web integrations, fraud and risk controls, and platform observability. You will partner with Technical Leads, Product Owners, application engineers, mobile developers, fraud and cyber teams, architects, and delivery professionals to implement secure customer authentication, authorization, registration, account recovery, identity verification, and step-up authentication solutions.

Here is What You Can Expect on a Typical Day

Engineer advanced authentication, registration, account recovery, profile management, consent, and step-up MFA journeys using PingOne Advanced Identity Cloud. Develop and maintain custom journeys, custom nodes, JavaScript decision logic, validation rules, scripted policies, OIDC claims logic, API integrations, and reusable CIAM components. Customize and support PingOne AIC Hosted Pages, including branding, localization, frontend behavior, reusable themes, input validation, responsive user experiences, and accessibility compliance. Design and implement PingOne Protect capabilities within customer identity flows, including global and application-specific risk policies, standard and custom predictors, composite risk decisions, group mappings, device signals, behavioral signals, registration velocity, compromised credential indicators, and external fraud intelligence. Develop proactive fraud mitigation patterns that can dynamically allow, challenge, step up, throttle, block, or route a customer transaction for additional verification based on evaluated risk. Ability to work with various teams across the business such as Cyber Fraud and business partners.

The Skills & Expertise You Bring

Qualifications Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, Information Systems, or a related discipline, or equivalent professional experience demonstrating senior-level architecture and engineering depth. Typically 5 ½ or more years of progressive IAM, security engineering, software engineering, platform engineering, or cloud experience, delivering CIAM solutions leading complex technical designs or global application integrations. Demonstrated ownership of customer-facing identity solutions supporting high-volume web, native mobile, SPA, BFF, API, microservice, partner, call-center, and machine-to-machine channels across multiple regions, environments, and business units. Advanced hands‑on expertise with PingOne Advanced Identity Cloud SAAS including journey design, nested journeys, custom and scripted decision nodes, authentication levels, session configuration, hosted pages, identity schemas, managed objects, AM/IDM APIs, application policies, OIDC claims scripts, environment promotion, and production troubleshooting. Hands‑on experience integrating PingOne Protect automating fraud detection, adaptive‑authentication, device intelligence, behavioral analytics, bot detection, identity verification, and external risk signals; able to create predictors and composite policies, tune thresholds, interpret risk evidence, control false positives, and implement allow, challenge, step‑up, throttle, block, or manual‑review outcomes. Integrate and troubleshoot Ping journey and device‑profiling SDKs in JavaScript, React Native, Android, iOS, and Flutter, including callback rendering, browser and deep‑link redirects, PKCE verifier persistence, cookie behavior, device identifiers, CORS/CSP, network failures, application lifecycle transitions, token renewal, and diagnostic logging. Demonstrated ability to design and implement coarse‑and fine‑grained authorization using least-privilege scopes, granular business roles, entitlements, resource/action models, consent, relationship and contextual attributes, JWT access‑token claims, policy decision points, policy enforcement points, obligations, deny‑by‑default behavior, and domain-service ownership boundaries. Strong production coding capability in at least two of Java, JavaScript/TypeScript, Python, Spring, Node.js, React, PowerShell, or shell, with evidence of writing maintainable modules, tests, API clients, migration utilities, validation tools, pipeline automation, operational scripts, and reusable platform accelerators. Advanced REST API engineering skills, including resource and contract design, HTTP semantics, JSON schemas, pagination, filtering, idempotency, retries, rate limits, webhooks and callbacks, authentication headers, error models, correlation IDs, backward compatibility, mocks, Postman collections, negative testing, and automated contract validation against PingOne AIC and downstream services. Strong Splunk and Dynatrace capability, including SPL, field extraction, nested JSON parsing, dashboards, service‑level indicators, transaction correlation, alert design, baseline and threshold tuning, distributed tracing, latency segmentation, root‑cause analysis, and privacy‑aware handling of tokens, credentials, device data, and customer PII. Experience designing and executing high‑volume identity and application migrations with batching, checkpointing, restartability, reconciliation, credential migration, schema mapping, exception queues, audit trails, rollback controls, cutover orchestration, coexistence, performance testing, and post‑migration verification. Proven CIAM architecture leadership, including facilitation of discovery and whiteboarding sessions with global application, product, domain‑service, fraud, cyber, privacy, cloud, network, operations, and vendor teams; able to uncover missing requirements, distinguish an existing pattern from a net‑new pattern, challenge unsafe assumptions, and drive decisions to closure. Demonstrated ability to understand customer and business‑service processes—registration, authentication, servicing, profile management, account recovery, consent, identity proofing, fraud review, partner access, entitlement, and downstream data access—and translate them into actors, trust boundaries, service ownership, authentication and authorization flows, API contracts, claims, controls, exceptions, and measurable outcomes. Proven delivery leadership under aggressive timelines: rapidly identify the minimum safe scope, reuse approved patterns, size complexity, sequence dependencies, time‑box decisions, expose critical‑path risks, define accountable owners, create sprint‑ready acceptance criteria, secure architecture approvals, and drive work through testing, operational readiness, production release, and stabilization. Ability to operate independently in ambiguity, develop proof‑of‑concept code and measurable evidence, compare architecture options, document assumptions and trade‑offs, make a clear recommendation, elevate unresolved risk, and remain directly engaged through implementation and production validation. Excellent written, verbal, and executive communication skills, including the ability to lead code and design reviews, challenge senior technical stakeholders constructively, explain complex identity and fraud risks in business terms, define precise ownership boundaries, and communicate decisions, residual risk, delivery status, and required actions without ambiguity.

Preferred evidence of qualification: Candidates should be prepared to discuss and demonstrate a production implementation they personally designed and delivered, including a PingOne AIC journey or OAuth client, a complete Ping Identity Gateway route with conditions and Chain filters, an AWS EKS deployment through CI/CD, Route 53 and ALB traffic flow, granular scopes or roles and JWT claims, automated negative tests, observability, failure diagnosis, and the architecture decisions used to balance security, customer experience, reuse, and delivery urgency.

Success in This Role

Success will be measured by the engineer’s ability to deliver secure and reusable CIAM capabilities; reduce fraud exposure and customer friction; automate platform operations; accelerate application onboarding; improve observability and incident resolution; strengthen engineering quality; and convert emerging customer identity risks into actionable technical controls.

You’ll Love Working Here Because You Can

Join a team and culture where your voice matters; where every day, your work transforms our experiences to make lives better. As you put your skills to use, we’ll help you make an even bigger impact with learning experiences that can grow your technical AND leadership capabilities. You’ll be surprised by what this rock-solid organization has in store for you.

What we offer you:

Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $133,600.00 to $220,400.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills. Market competitive base salaries, with a yearly bonus potential at every level.

  • Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave.
  • 401(k) plan with company match (up to 4%).
  • Company‑funded pension plan.
  • Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs.
  • Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.
  • Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs.
  • Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period).
  • Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance.

To find out more about our Total Rewards package, visit Work Life Balance | Prudential Careers. Some of the above benefits may not apply to part-time employees scheduled to work less than 20 hours per week.

Prudential Financial, Inc. of the United States is not affiliated with Prudential plc. which is headquartered in the United Kingdom. Prudential is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender identity, national origin, genetics, disability, marital status, age, veteran status, domestic partner status, medical condition or any other characteristic protected by law.

To maintain the integrity and security of our hiring process, Prudential may use identity verification technologies. Your consent will be obtained before any verification takes place. If you need an accommodation to complete the application process, please email accommodations.hw@prudential.com. If you are experiencing a technical issue with your application or an assessment, please email careers.technicalsupport@prudential.com to request assistance.

Prudential Financial, Inc. (NYSE: PRU), a global financial services leader and premier active global investment manager with approximately $1.4 trillion in assets under management as of Dec. 31, 2023, has operations in the United States, Asia, Europe, and Latin America. Prudential’s diverse and talented employees help make lives better and create financial opportunity for more people by expanding access to investing, insurance, and retirement security. Prudential’s iconic Rock symbol has stood for strength, stability, expertise and innovation for 150 years. For more information please visit news.prudential.com. Our Commitment to an Inclusive Workplace Prudential Financial, Inc. serves its customers in more than 40 countries and territories, and we seek talented, creative individuals from a variety of backgrounds, worldviews, and life circumstances to work with us. We are focused on creating a fully inclusive culture, where all employees feel comfortable bringing their authentic selves to work. We don’t just accept difference—we celebrate it, support it, and thrive on it. At Prudential, employees have a unique opportunity to build their career path by owning their development, their career, and their future. We encourage employees to hone their skills and explore continued opportunities within Prudential.

PGIM, the global asset management business of Prudential Financial, Inc. (NYSE: PRU), is a global investment manager with US $1.3 trillion in assets under management as of Dec. 31, 2023. With offices in 18 countries, PGIM’s businesses offer a range of investment solutions for retail and institutional investors around the world across a broad range of asset classes, including public fixed income, private fixed income, fundamental equity, quantitative equity, real estate, and alternatives. For more information about PGIM, visit pgim.com.

Prudential Financial, Inc. (PFI) of the United States is not affiliated in any manner with Prudential plc, incorporated in the United Kingdom, or with Prudential Assurance Company, a subsidiary of M&G plc, incorporated in the United Kingdom. For more information please visit news.prudential.com.

PGIM Inc. (PGIM) is the principal asset management business of Prudential Financial, Inc. (PFI), a company incorporated and with its principal place of business in the United States. PFI of the United States is not affiliated in any manner with Prudential plc, incorporated in the United Kingdom or with Prudential Assurance Company, a subsidiary of M&G plc, incorporated in the United Kingdom.

Our Commitment to an Inclusive Workplace Prudential Financial, Inc. serves its customers in more than 40 countries and territories, and we seek talented, creative individuals from a variety of backgrounds, worldviews, and life circumstances to work with us. We are focused on creating a fully inclusive culture, where all employees feel comfortable bringing their authentic selves to work. We don’t just accept difference—we celebrate it, support it, and thrive on it. At Prudential, employees have a unique opportunity to build their career path by owning their development, their career, and their future. We encourage employees to hone their skills and explore continued opportunities within Prudential.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead, Infrastructure Security Engineer - Identity Governance
Lead, Infrastructure Security Engineer - Identity Governance

Prudential Annuities Distributors (PAD) • Newark (NJ), Northern (KY)

On-site
USD 134,000 - 220,000
Medical, dental, vision insurance
401(k) with company match
Pension plan
+1
Lead, Network Security Analyst
Lead, Network Security Analyst

Prudential Annuities Distributors (PAD) • Newark (NJ)

On-site
USD 115,000 - 189,000
Medical, dental, vision, life
401(k) with company match
Company-funded pension
+3
Senior Data Engineer
Senior Data Engineer

PGIM Ireland • The Ironbound (NJ)

On-site
USD 104,000 - 172,000
Medical, dental, vision insurance
401(k) plan with company match
Pension plan
+1
Specialist, Network Security Analyst
Specialist, Network Security Analyst

Prudential Annuities Distributors (PAD) • Newark (NJ)

On-site
USD 89,000 - 147,000
Salary range
Medical, dental, vision
401(k) with match
+2
Specialist, Data Loss Prevention(DLP) - Cyber Defense & Response
Specialist, Data Loss Prevention(DLP) - Cyber Defense & Response

PGIM Ireland • The Ironbound (NJ)

On-site
USD 96,000 - 159,000
Medical, dental, vision
401(k) plan with company match
Pension plan
+1
Specialist, Data Security - Cyber Defense & Response
Specialist, Data Security - Cyber Defense & Response

PGIM Ireland • The Ironbound (NJ)

On-site
USD 96,000 - 159,000
Medical insurance
Dental insurance
Vision insurance
+3
Lead, Business Systems Analyst - PGIM Technology (Hybrid - Newark, NJ)
Lead, Business Systems Analyst - PGIM Technology (Hybrid - Newark, NJ)

PGIM Ireland • Newark (NJ)

Hybrid
USD 115,000 - 165,000
401(k) plan with company match
Pension plan
Wellness programs
+1
Lead, Business Systems Analyst - PGIM Technology (Hybrid - Newark, NJ)
Lead, Business Systems Analyst - PGIM Technology (Hybrid - Newark, NJ)

PGIM Ireland • The Ironbound (NJ)

Hybrid
USD 130,000 - 170,000
Market-competitive salary
Annual bonus potential
401(k) with match
+4
Senior UX/ Experience Designer
Senior UX/ Experience Designer

PGIM Ireland • Fort Washington

On-site
USD 89,000 - 147,000
Wellness Programs including up to $1,6
401(k) plan with company match
Pension plan
+2
Senior UX/ Experience Designer
Senior UX/ Experience Designer

Prudential Annuities Distributors (PAD) • United States

On-site
USD 89,000 - 147,000
Competitive base salary
Annual bonus potential
Medical, dental, vision insurance
+6