Turn this role into an interview — a resume and cover letter built around what this employer wants.
Rivago Infotech Inc. seeks a Senior IAM Engineer with deep Ping Identity expertise to design, implement, and support large-scale IAM environments, focusing on SSO, federation, and onboarding across enterprise platforms.
This role requires close collaboration with customers and engineering teams to deliver secure, scalable IAM solutions, including deploying PingFederate and PingAccess in high-availability configurations and integrating with SAML, OAuth, and OIDC protocols.
Location : Mountain View or San Diego, CA (Hybrid)
We are seeking a highly skilled Senior IAM Engineer with deep expertise in Ping Identity solutions and enterprise authentication technologies. The ideal candidate will have hands-on experience designing, implementing, and supporting large-scale Identity and Access Management (IAM) environments, with a strong focus on Single Sign-On (SSO), federation, authentication services, and application onboarding.
This role requires close collaboration with customers, application teams, security stakeholders, and engineering teams to deliver secure, scalable, and reliable IAM solutions across enterprise environments.
Participate and lead the design and deployment of Ping Identity solutions across multiple environments.
Implement PingFederate and PingAccess in clustered and high-availability configurations.
SSO Onboarding and Certificate Renewal: Work with customers to help them onboard their applications to SSO (single sign-on).
Includes:
Consultation: Work with the customer and application vendor to analyze and determine if the application supports industry standard authentication mechanisms such as SAML. Determine the appropriate solution path and elevate non-standard integrations.
Submit proper request document: Follow on with customer to submit the onboarding request for SSO and implement.
Troubleshoot and QA: work at the detailed technical level to resolve issues
Implement changes to existing SSO integrations: Work with customers to analyze and update existing SSO integrations as the customer applications evolve or are upgraded. This could involve after hours work to minimize end-customer impact for production integrations.
Define and enforce PingFederate policies and configurations for SP and IdP roles.
Integrate Ping products with SAML, WS-Federation, OAuth, OpenID Connect, and WS-Trust protocols.
Migrate data and policies from legacy IAM systems to Ping Identity platforms.
Perform performance tuning for high-volume transaction environments.
Integrate IAM systems with Windows and Unix/Linux platforms.
Collaborate with cross-functional teams to ensure seamless IAM integration.
Work with other IAM technologies such as CA SiteMinder.
Manage the consolidation of applications/services between services, including data migration from applications.
Oversee the decommissioning of applications/services replaced by client specific solutions.
Establish and execute validation principles to ensure successful migrations.
Provide daily updates to the core team on progress, roadblocks and items on roadmap.
Create JIRA stories for consultation for candidate application - Publish weekly summary of progress.
Candidate MUST be able to work well with internal and external customers to gather requirements, help them understand what we'll need in order to onboard, and work with Product Management and Scrum Master on status updates and creation of user stories in Jira backlog.
Work with customers to resolve service requests and support tickets.
Assist with test, rollout and support of new Authentication features.
Strongly desired: experience in Ping Access Manager, PingFederate, LDAP, and Unix.
AWS compute, storage, networking, scaling, HA, performance, cost optimization
Scripting and automation - such as CI/CD, Python, CloudWatch, Bash, Splunk, Jenkins, GIT
Comprehensive understanding of Identity and Access Management (IAM) principles and best practices.
Deep proficiency in Ping's Identity Engine platform (features, functionality, integration). PingFederate, PingAccess, PingDirectory, PingOne, PingID
Strong expertise in IDP protocols: SSO, SAML, OIDC, JIT, OAuth, SCIM (understanding appropriate use cases).
Ability to interpret technical specifications and communicate effectively with technical and non-technical audiences.
Development - Python, Java, back end or full stack, database, Spring Boot.
Okta Knowledge is nice to have.