Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard

Malvern (AR)

On-site

USD 120,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Visa sponsorship

Job summary

Vanguard is seeking a seasoned Identity & Access Management engineer to own end-to-end IAM architecture across Okta and Ping Identity ecosystems. You will lead security‑driven design, integrate with cloud platforms, and mentor engineers while driving standards and reliability.

Applicants should bring 12+ years in IAM engineering, deep Okta and Ping products experience, and strong knowledge of OAuth/OIDC, SAML, and LDAP.

Qualifications

  • Undergraduate degree or equivalent experience.
  • 12+ years of Identity & Access Management engineering experience.
  • Skilled with DevOps tools and Policy as code.
  • Deep hands-on expertise with Okta (Workforce Identity, MFA, SSO, policies, lifecycle).
  • Strong working knowledge of Ping Identity products (PingFederate, PingOne, Ping Directory).
  • Expert understanding of OAuth 2.0, OIDC, SAML Federation and token-based security.
  • Proven experience with directory services & LDAP (AD, cloud directories).
  • Experience building identity platforms in AWS/GCP, including containerized/Kubernetes deployments.
  • Strong troubleshooting for complex authentication and federation failures.
  • Ability to operate in high-visibility, high-impact environments.

Responsibilities

  • Serve as technical lead for workforce identity platforms, with Okta as the primary IdP and integrations to complementary platforms.
  • Own end‑to‑end identity architecture, including authentication flows, federation, directory integrations, and token issuance.
  • Lead design reviews and decisions for IdP resiliency, failover, and supplier‑risk mitigation strategies.
  • Document existing and new architecture and act as a hands‑on engineer while also setting technical direction, patterns, and standards.
  • Strong communication, influence, and stakeholder‑management skills, with the ability to distill complex identity and security architectures into clear and concise messaging.
  • Design and troubleshoot identity flows using OAuth 2.0 / OIDC, SAML 2.0, SCIM, JWT / token‑based auth.
  • Ensure token parity, claim consistency, and issuer abstraction across identity providers to minimize application impact.
  • Partner with application teams to enable modern authentication without app re‑architecture.
  • Engineer and maintain directory integrations across Active Directory, Okta UD, and cloud directories (e.g., Ping Directory).
  • Design attribute models, lifecycle management, and group strategies at enterprise scale (thousands of groups, large population sizes).
  • Support directory deployments in cloud‑native environments (AWS/GCP, containers, Kubernetes).
  • Build and operate identity infrastructure in AWS/GCP/Azure, using Infrastructure & Policy as Code (Terraform / CloudFormation) and Kubernetes & containerized identity services.
  • Automate provisioning, deployment, monitoring, and drift detection for identity platforms.
  • Support SRE‑style operational maturity: SLIs/SLOs, alerting, incident response, and runbooks for identity services.
  • Design identity controls aligned to Zero Trust principles and enterprise security policies.
  • Partner with CSOC, audit, and risk teams on control validation, incident response, and regulatory and audit requirements (SOX, SOC, internal controls).
  • Contribute to risk assessments related to supplier dependency, SPOFs, and identity outages.
  • Work closely with security architecture, infrastructure, application engineering, IAM operations, and vendors.
  • Influence roadmap decisions through clear technical reasoning and executive‑ready communication.
  • Mentor senior and mid‑level engineers and raise overall identity engineering maturity.

Job description

Key Responsibilities
  • Serve as technical lead for workforce identity platforms, with Okta as the primary IdP and integrations to complementary platforms (e.g., Ping/Entra Identity).
  • Own end‑to‑end identity architecture, including authentication flows, federation, directory integrations, and token issuance.
  • Lead design reviews and decisions for IdP resiliency, failover, and supplier‑risk mitigation strategies.
  • Document existing and new architecture and act as a hands‑on engineer while also setting technical direction, patterns, and standards.
  • Strong communication, influence, and stakeholder‑management skills, with the ability to distill complex identity and security architectures into clear and concise messaging.
Standards‑Based Identity & Federation
  • Design and troubleshoot identity flows using OAuth 2.0 / OIDC, SAML 2.0, SCIM, JWT / token‑based auth.
  • Ensure token parity, claim consistency, and issuer abstraction across identity providers to minimize application impact.
  • Partner with application teams to enable modern authentication without app re‑architecture.
Directory & Identity Data Architecture
  • Engineer and maintain directory integrations across Active Directory, Okta UD, and cloud directories (e.g., Ping Directory).
  • Design attribute models, lifecycle management, and group strategies at enterprise scale (thousands of groups, large population sizes).
  • Support directory deployments in cloud‑native environments (AWS/GCP, containers, Kubernetes).
Cloud, Automation & Reliability
  • Build and operate identity infrastructure in AWS/GCP/Azure, using Infrastructure & Policy as Code (Terraform / CloudFormation) and Kubernetes & containerized identity services.
  • Automate provisioning, deployment, monitoring, and drift detection for identity platforms.
  • Support SRE‑style operational maturity: SLIs/SLOs, alerting, incident response, and runbooks for identity services.
Security, Risk & Compliance
  • Design identity controls aligned to Zero Trust principles and enterprise security policies.
  • Partner with CSOC, audit, and risk teams on control validation, incident response, and regulatory and audit requirements (SOX, SOC, internal controls).
  • Contribute to risk assessments related to supplier dependency, SPOFs, and identity outages.
Collaboration & Influence
  • Work closely with security architecture, infrastructure, application engineering, IAM operations, and vendors.
  • Influence roadmap decisions through clear technical reasoning and executive‑ready communication.
  • Mentor senior and mid‑level engineers and raise overall identity engineering maturity.
Qualifications
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • 12+ years of experience in Identity & Access Management engineering.
  • Skilled in using DevOps tools and experience in Policy as code.
  • Deep hands‑on expertise with Okta (Workforce Identity, MFA, SSO, policies, lifecycle).
  • Strong working knowledge of Ping Identity products (PingFederate, PingOne, Ping Directory) or equivalent platforms.
  • Expert understanding of identity standards: OAuth 2.0, OIDC, SAML Federation and token‑based security.
  • Proven experience with directory services & LDAP (AD, cloud directories).
  • Experience building identity platforms in AWS/GCP, including containerized/Kubernetes deployments.
  • Strong troubleshooting skills for complex authentication and federation failures.
  • Ability to operate in high‑visibility, high‑impact environments.
Special Factors
  • Sponsorship: Vanguard is offering visa sponsorship for this position.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Specialist, Lead Zero Trust Identity Security Engineering
Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard • Dallas (TX)

On-site
USD 190,000 - 230,000
Senior Specialist, Lead Zero Trust Identity Security Engineering
Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard • Malvern

Hybrid
USD 150,000 - 190,000
Visa sponsorship
Identity Management Engineer / Architect (R-00197)
Identity Management Engineer / Architect (R-00197)

Socket.dev • United States

Remote
USD 120,000 - 180,000
Competitive salary
Best medical coverage
Premium medical premiums covered by us
+3
Sr Security Engineer
Sr Security Engineer

Adobe • Seattle (WA)

On-site
USD 120,000 - 160,000
Sr. IAM Engineer
Sr. IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
Senior Identity Engineer (MSP)
Senior Identity Engineer (MSP)

Advisory Solutions • United States

On-site
USD 100,000 - 115,000
Health insurance
401(k) with employer match
Sr. Staff IAM Engineer
Sr. Staff IAM Engineer

Jobgether • United States

On-site
USD 180,000 - 230,000
Medical, dental, and vision insurance
FSA/HSA
Flexible PTO
+4
Identity Engineer (USSOCOM-Zero Trust)
Identity Engineer (USSOCOM-Zero Trust)

Kentro • Tampa (FL)

Hybrid
USD 120,000 - 180,000
Health benefits
401(k) with employer match
Education reimbursement
+1
Senior Identity Engineer
Senior Identity Engineer

Tyler Technologies • United States

On-site
USD 140,000 - 200,000
Senior Identity Engineer
Senior Identity Engineer

Tyler-Technologies-29572f8 • Troy (MI)

On-site
USD 110,000 - 140,000