Corporate Vice President - Access Management & Authentication Engineer
About the role
The Access Management & Authentication Lead Engineer is a senior, hands-on technical leader responsible for the design, engineering, and governance of enterprise-wide authentication, federation, and web access management (WAM) capabilities across New York Life. This role serves as the technical authority for access management and authentication, including single sign-on (SSO), federation, modern and passwordless authentication, multi-factor authentication (MFA), API authorization, and secure session management.
Responsibilities
- Lead the design, engineering, and evolution of enterprise web access management (WAM) and authentication platforms supporting workforce and application access.
- Architect and expand single sign-on (SSO) and federation services using industry-standard identity and authorization protocols.
- Define and implement modern authentication strategies, including passwordless, phishing-resistant, and strong customer authentication approaches.
- Design and govern multi-factor authentication (MFA) frameworks, including adaptive, risk-based, and step-up authentication models.
- Engineer secure session management and token lifecycle controls, ensuring appropriate re-authentication, session integrity, and privilege enforcement.
- Design and integrate API authorization and access control patterns, aligning OAuth-based authorization with API gateways and platform services.
- Apply public key infrastructure (PKI) and cryptographic trust models to authentication, federation, and service-to-service access.
- Establish reusable authentication and access management patterns, guardrails, and reference architectures across web, mobile, API, and cloud environments.
- Serve as the technical authority for access management and authentication, advising architecture reviews, security assessments, and engineering teams on secure design decisions.
Security Assessments
- Perform security assessments of applications, cloud workloads, identity architectures, and vendor solutions, with a primary focus on IAM, cloud identity, and non-human identity risks.
- Serve as a senior technical contributor within the Security Review Board (SRB), leading identity-focused reviews and influencing secure architecture decisions.
- Conduct deep technical analysis of authentication flows, authorization models, role and attribute design, privilege paths, and non-human identity usage.
- Identify security gaps and risks related to IGA, PAM, WAM, MFA, cloud IAM, and workload identity, and recommend remediation strategies.
- Support the Information Security exception lifecycle, including risk analysis and documentation, evaluation of compensating controls, reassessment and expiration management.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience.
- 10+ years of experience in Identity & Access Management, with deep specialization in access management, authentication, and federation technologies.
- Proven experience designing, engineering, and operating enterprise Web Access Management (WAM) platforms supporting large-scale workforce and application authentication.
- Hands-on experience with enterprise federation and access management platforms, such as PingFederate, PingProtect, or similar technologies.
- Expert-level knowledge of authentication, authorization, and federation protocols, including SAML 2.0, OAuth 2.0, and OpenID Connect.
Qualifications
- Strong experience architecting and scaling single sign-on (SSO) and federated identity solutions across web, mobile, API, and cloud-native environments.
- Demonstrated experience implementing modern authentication approaches, including passwordless and phishing-resistant authentication methods.
- Deep understanding of multi-factor authentication (MFA) models, including adaptive, risk-based, and step-up authentication strategies.
- Understanding of the Linux OS and LDAP.
- Hands-on experience with API authorization and access control, including OAuth-based authorization flows and integration with API gateways or platform services.
Preferred Qualifications
- Proven experience delivering phishing-resistant, passwordless authentication at enterprise scale, including passkeys, FIDO2, and hardware-backed authenticators.
- Hands-on experience with adaptive, continuous, or risk-based authentication models, incorporating behavioral, device, and contextual signals.
- Strong understanding of Zero Trust access principles applied to workforce, application, and API authentication and authorization.
- Experience securing modern API and distributed architectures, including OAuth token exchange, delegation, and fine-grained authorization patterns.
Benefits
We provide a full package of benefits for employees – and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs.
Pay
Salary Range: $147,500-$211,000. Overtime eligible: Exempt. Discretionary bonus eligible: Yes. Actual base salary will be determined based on several factors but not limited to individual’s experience, skills, qualifications, and job location.