Jobs · Sales · New York

Corporate Vice President - Access Management & Authentication Engineer

New York Life · New York, United States · 6 days ago
Sales$148k/yrFull-time

About the role

The Access Management & Authentication Lead Engineer is a senior, hands-on technical leader responsible for the design, engineering, and governance of enterprise-wide authentication, federation, and web access management (WAM) capabilities across New York Life. This role serves as the technical authority for access management and authentication, including single sign-on (SSO), federation, modern and passwordless authentication, multi-factor authentication (MFA), API authorization, and secure session management.

Responsibilities

  • Lead the design, engineering, and evolution of enterprise web access management (WAM) and authentication platforms supporting workforce and application access.
  • Architect and expand single sign-on (SSO) and federation services using industry-standard identity and authorization protocols.
  • Define and implement modern authentication strategies, including passwordless, phishing-resistant, and strong customer authentication approaches.
  • Design and govern multi-factor authentication (MFA) frameworks, including adaptive, risk-based, and step-up authentication models.
  • Engineer secure session management and token lifecycle controls, ensuring appropriate re-authentication, session integrity, and privilege enforcement.
  • Design and integrate API authorization and access control patterns, aligning OAuth-based authorization with API gateways and platform services.
  • Apply public key infrastructure (PKI) and cryptographic trust models to authentication, federation, and service-to-service access.
  • Establish reusable authentication and access management patterns, guardrails, and reference architectures across web, mobile, API, and cloud environments.
  • Serve as the technical authority for access management and authentication, advising architecture reviews, security assessments, and engineering teams on secure design decisions.

Security Assessments

  • Perform security assessments of applications, cloud workloads, identity architectures, and vendor solutions, with a primary focus on IAM, cloud identity, and non-human identity risks.
  • Serve as a senior technical contributor within the Security Review Board (SRB), leading identity-focused reviews and influencing secure architecture decisions.
  • Conduct deep technical analysis of authentication flows, authorization models, role and attribute design, privilege paths, and non-human identity usage.
  • Identify security gaps and risks related to IGA, PAM, WAM, MFA, cloud IAM, and workload identity, and recommend remediation strategies.
  • Support the Information Security exception lifecycle, including risk analysis and documentation, evaluation of compensating controls, reassessment and expiration management.

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience.
  • 10+ years of experience in Identity & Access Management, with deep specialization in access management, authentication, and federation technologies.
  • Proven experience designing, engineering, and operating enterprise Web Access Management (WAM) platforms supporting large-scale workforce and application authentication.
  • Hands-on experience with enterprise federation and access management platforms, such as PingFederate, PingProtect, or similar technologies.
  • Expert-level knowledge of authentication, authorization, and federation protocols, including SAML 2.0, OAuth 2.0, and OpenID Connect.

Qualifications

  • Strong experience architecting and scaling single sign-on (SSO) and federated identity solutions across web, mobile, API, and cloud-native environments.
  • Demonstrated experience implementing modern authentication approaches, including passwordless and phishing-resistant authentication methods.
  • Deep understanding of multi-factor authentication (MFA) models, including adaptive, risk-based, and step-up authentication strategies.
  • Understanding of the Linux OS and LDAP.
  • Hands-on experience with API authorization and access control, including OAuth-based authorization flows and integration with API gateways or platform services.

Preferred Qualifications

  • Proven experience delivering phishing-resistant, passwordless authentication at enterprise scale, including passkeys, FIDO2, and hardware-backed authenticators.
  • Hands-on experience with adaptive, continuous, or risk-based authentication models, incorporating behavioral, device, and contextual signals.
  • Strong understanding of Zero Trust access principles applied to workforce, application, and API authentication and authorization.
  • Experience securing modern API and distributed architectures, including OAuth token exchange, delegation, and fine-grained authorization patterns.

Benefits

We provide a full package of benefits for employees – and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs.

Pay

Salary Range: $147,500-$211,000. Overtime eligible: Exempt. Discretionary bonus eligible: Yes. Actual base salary will be determined based on several factors but not limited to individual’s experience, skills, qualifications, and job location.

Similar jobs