Senior Authentication, SSO/MFA & CIAM SME Lead

PepsiCo Deutschland GmbH

Plano (TX)

On-site

USD 111,000 - 185,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
Disability insurance
Dependent Care Reimbursement Accounts
Employee Assistance Program (EAP)
Insurance (Life/Accident)
Defined Contribution Retirement Plan

Job summary

PepsiCo hires an Authentication, SSO/MFA and CIAM SME/Architect to lead secure identity solutions across workforce, partner, and customer use cases. The role requires hands-on design, implementation, and governance of modern authentication across hybrid environments, with close collaboration to enterprise architects, cybersecurity, and business teams.

Based in Plano, TX, the candidate will mentor engineers, drive DevOps practices, and deliver scalable IAM capabilities including Okta and related

Qualifications

  • 15+ years of IT experience with enterprise IAM, cybersecurity, architecture, or application security.
  • 10+ years hands-on experience in authentication, SSO, MFA, federation, and access management.
  • 7+ years with Okta or comparable identity platforms such as Ping, Microsoft Entra ID, ForgeRock, SiteMinder.
  • Strong knowledge of SAML, OAuth 2.0, OIDC, JWT, LDAP, API security and modern authentication flows.
  • Experience integrating SaaS/cloud/on-prem apps with SSO/MFA solutions.

Responsibilities

  • Serve as the senior SME/Architect for Authentication, SSO, MFA, federation, and CIAM across enterprise platforms.
  • Design secure authentication patterns for cloud, on-prem, mobile, API, B2B, workforce and customer apps.
  • Lead technical architecture for SSO integrations (SAML, OAuth 2.0, OIDC, WS-Federation).
  • Define MFA/adaptive authentication strategies including risk-based access and passwordless options.
  • Architect CIAM solutions for customer registration, login, consent, profiling, social login, and secure API access.
  • Translate business requirements into secure, scalable IAM solutions with cross-team partnership.
  • Provide hands-on leadership for complex integrations, RCA, production support, and platform stability.
  • Develop reference designs, standards, and playbooks for authentication capabilities.
  • Drive platform modernization, automation, and roadmap for IAM services (Okta).
  • Ensure governance, auditing, logging, and compliance through secure authentication controls.

Skills

SAML
OAuth 2.0
OIDC
CIAM
Zero trust
Passwordless
Security architecture
Scripting (PowerShell/Python/JS)
Agile/DevOps

Education

BS/BA degree

Tools

Okta
PingFederate
SiteMinder
ForgeRock
Azure AD B2C

Job description

Overview

The Authentication, SSO/MFA and CIAM SME/Architect will serve as a senior technical leader within the IAM organization, responsible for defining, architecting, designing, and delivering secure authentication and access management solutions across workforce, partner, and customer identity use cases.

This role requires deep hands-on expertise in modern authentication, SSO federation, MFA, passwordless authentication, CIAM, and identity security across hybrid on-premises and cloud environments. The candidate will partner with enterprise architects, cybersecurity, infrastructure, application, and business teams to deliver scalable solutions that improve security, reduce risk, support compliance, and enable business outcomes.

This role is based out of Plano, Texas and requires coming into the office.

Responsibilities
  • Serve as the senior SME/Architect for Authentication, SSO, MFA, passwordless, federation, and CIAM capabilities across enterprise IAM platforms.
  • Design and solution secure authentication patterns for cloud, SaaS, on-premises, mobile, API, B2B, workforce, and customer-facing applications.
  • Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns.
  • Define MFA and adaptive authentication strategies, including risk-based access, device trust, step-up authentication, passwordless, and phishing-resistant authentication options.
  • Architect CIAM solutions supporting customer registration, login, profile management, consent, progressive profiling, social login, account recovery, and secure API access.
  • Partner with application, cybersecurity, privacy, infrastructure, legal, and business teams to translate business requirements into secure, scalable IAM solutions.
  • Assess current authentication implementations and recommend improvements aligned with security standards, regulatory requirements, zero trust principles, and enterprise architecture guidelines.
  • Provide hands-on technical leadership for complex integrations, troubleshooting, root cause analysis, production support, and platform stability.
  • Develop reusable architecture patterns, reference designs, integration standards, decision records, and implementation playbooks for authentication and CIAM capabilities.
  • Drive platform modernization, automation, and roadmap execution for IAM authentication services, including Okta and related identity platforms.
  • Support governance, risk reduction, audit readiness, and operational controls by ensuring authentication solutions meet security, compliance, logging, monitoring, and access policy requirements.
  • Mentor engineers and delivery teams, provide technical reviews, and enable knowledge transfer across internal and external stakeholders.
  • Champion Agile and DevOps practices, including automation, CI/CD, infrastructure as code, monitoring, and reliable change delivery.

Compensation and Benefits:

  • The expected compensation range for this position is between $110,700 - $185,250.
  • Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
  • Bonus based on performance and eligibility target payout is 12% of annual salary paid out annually.
  • Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
  • In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications

Minimum Qualifications:

  • 15+ years of overall IT experience, with significant experience in enterprise IAM, cybersecurity, architecture, or application security.
  • 10+ years of hands-on experience architecting, designing, and delivering authentication, SSO, MFA, federation, and access management solutions.
  • 7+ years of hands-on experience with Okta or comparable identity platforms such as Ping, Microsoft Entra ID, ForgeRock, SiteMinder, or similar technologies.
  • Strong working knowledge of SAML, OAuth 2.0, OIDC, JWT, SCIM, LDAP, Kerberos, API security, session management, token lifecycle, and modern authentication flows.
  • Proven experience integrating SaaS, cloud, mobile, API, legacy, and on-premises applications with enterprise SSO and MFA solutions.
  • Hands-on scripting or development experience using PowerShell, Python, Java, JavaScript, Node.js, REST APIs, or similar technologies.
  • Experience with troubleshooting complex authentication issues across browsers, certificates, DNS, network, proxy, load balancers, directories, APIs, and cloud components.
  • Experience working with Agile and DevOps tools, automation practices, release management, and production support processes.
  • Okta Certified Administrator required or strongly preferred; Okta Certified Consultant, Developer, Professional, or equivalent IAM certification preferred.
  • BS/BA degree or equivalent practical experience.

Preferred Qualifications:

  • Deep experience with Okta Workforce Identity, Okta Customer Identity, Okta Access Gateway, Okta API Access Management, Lifecycle Management, Workflows, Hooks, and Administrative APIs.
  • Strong CIAM architecture experience, including customer onboarding, registration, authentication journeys, account recovery, consent, privacy, profile management, social identity, and fraud/risk controls.
  • Experience designing authentication solutions for B2B, B2C, partner, contractor, and machine-to-machine use cases.
  • Strong understanding of zero trust, least privilege, conditional access, adaptive MFA, phishing-resistant MFA, FIDO2/WebAuthn, passkeys, and passwordless authentication.
  • Experience with Microsoft Entra ID, PingFederate, SiteMinder, ForgeRock, AWS Cognito, Azure AD B2C, or other identity and federation platforms.
  • Experience with privileged access, service accounts, bot accounts, non-human identities, and secure access patterns for automation and integrations.
  • Experience designing and reviewing authentication controls for applications containing confidential, restricted, regulated, or sensitive data.
  • Strong understanding of directory services such as Active Directory, LDAP, Oracle LDAP, and cloud directory services.
  • Experience with API security, REST integrations, custom connectors, SCIM provisioning, identity orchestration, and workflow automation.
  • Experience with monitoring, logging, and troubleshooting using tools such as Splunk, ELK, Prometheus, or similar platforms.
  • Experience with cloud, container, and DevOps technologies such as Azure, AWS, Docker, Kubernetes, Terraform, Ansible, and CI/CD pipelines.
  • Experience with web infrastructure components such as Apache, middleware, certificates, load balancers, WAF, reverse proxy, and Linux/Windows platforms.
  • Security certifications such as CISSP, CCSP, CIAM, or equivalent identity/security certifications are a plus.

Non-Technical skills:

  • Strong communication skills with the ability to explain complex authentication and CIAM concepts to technical teams, business stakeholders, risk partners, and leadership.
  • Ability to influence architecture decisions, challenge assumptions, and drive alignment across application, infrastructure, cybersecurity, privacy, and enterprise architecture teams.
  • Self-starter who can operate with limited direction, own complex technical problems, and drive them to closure.
  • Strong analytical and problem-solving skills with the ability to simplify complex requirements into secure, practical, and scalable solutions.
  • Strong delivery discipline with the ability to balance architecture quality, security requirements, operational stability, and business timelines.
  • Ability to mentor engineers, review technical designs, and raise the overall maturity of the authentication engineering function.
  • Flexible and adaptable, with the ability to manage competing priorities in a fast-paced enterprise environment.
EEO Statement

Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance.

All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age

If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law and EEO is the Law Supplement documents. View PepsiCo EEO Policy.

Please view our Pay Transparency Statement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Authentication, SSO/MFA & CIAM SME Lead
Senior Authentication, SSO/MFA & CIAM SME Lead

PepsiCo • Plano (TX)

On-site
USD 111,000 - 185,000
Medical insurance
Dental
Vision
+4
Senior Identity & Access Management (CIAM) Engineer
Senior Identity & Access Management (CIAM) Engineer

PepsiCo • Plano (TX)

On-site
USD 80,000 - 134,000
Medical, Dental, Vision
Disability Insurance
Paid time off
Cybersecurity Director - IAM Emerging Tech & Solution Design
Cybersecurity Director - IAM Emerging Tech & Solution Design

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 132,000 - 262,000
Medical, Dental, Vision
Disability and Life Insurance
Retirement Plan
+1
Cybersecurity Director - IAM Emerging Tech & Solution Design
Cybersecurity Director - IAM Emerging Tech & Solution Design

Socket.dev • Plano (TX)

On-site
USD 132,000 - 262,000
Long-term incentive
Paid time off
Health benefits
+1
Cybersecurity IAM Senior Principal Engineer
Cybersecurity IAM Senior Principal Engineer

PepsiCo • Plano (TX)

On-site
USD 124,000 - 207,000
Medical
Dental
Vision
+2
Application Security | Application Security Engineer
Application Security | Application Security Engineer

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 80,000 - 134,000
Application Security | Application Security Engineer
Application Security | Application Security Engineer

PepsiCo • Plano (TX)

On-site
USD 80,000 - 134,000
Medical benefits
Dental benefits
Vision benefits
+3
Associate Principal – Non-Human Identity (NHI) Lead
Associate Principal – Non-Human Identity (NHI) Lead

PepsiCo • Plano (TX)

On-site
USD 94,000 - 156,000
Bonus eligibility
Comprehensive benefits package
Paid time off
Associate Principal – Non-Human Identity (NHI) Lead
Associate Principal – Non-Human Identity (NHI) Lead

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 94,000 - 156,000
Bonus 10% of annual salary
Comprehensive benefits
Paid time off
Information Security- Assoc Specialist
Information Security- Assoc Specialist

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 94,000 - 156,000
Medical, Dental, Vision
Paid time off
Parental leave
+1