Cyber Identity - PlainID/PBAC Engineering Manager II
About the role
Join our Deloitte Cyber team to deliver powerful solutions that help clients navigate the ever-changing threat landscape. As an experienced PlainID professional at Deloitte Consulting, you will combine deep technical ownership with engineering expertise, governance, and stakeholder management to deliver PBAC/ABAC authorization tools, including PlainID.
Responsibilities
- Configure and implement the PlainID Authorization Platform within client environments, including policy modelling and decision-point/information-point setup.
- Lead technical discussions with Enterprise architects and IAM stakeholders.
- Lead a PBAC team for successful and seamless delivery.
- Design fine-grained, attribute-based access policies (PBAC/ABAC) that translate business rules into technical controls, including row- and column-level data access restrictions where needed.
- Integrate PlainID with client identity providers (Okta, Microsoft Entra ID, Ping Identity, ForgeRock), API gateways, microservices, and data platforms such as Snowflake or Big Query.
- Support the full policy lifecycle—authoring, testing, versioning, and deployment—using PlainID's visual policy modeling and policy-as-code capabilities.
- Run requirements sessions with client stakeholders to document current-state access patterns and design the target-state authorization model.
- Troubleshoot policy conflicts, integration issues, and authorization-decision errors across the client's technology stack.
- Lead testing, validation, and go-live activities, including access-decision auditing and performance checks.
- Produce clear technical documentation—policy catalogs, integration diagrams, runbooks—for both the client and the internal delivery team.
- Partner with engagement leads and architects to keep delivery on track and surface risks early.
- Stay current on PlainID's platform roadmap, including emerging capabilities for AI agent and machine-identity authorization.
- Establish and maintain runbooks, SOPs, knowledge articles, and documentation standards for repeatable and governed support operations.
- Lead conversations with client stakeholders, internal teams, and third-party vendors to resolve defects, manage dependencies, and improve service outcomes.
Requirements
- 7+ years of total experience, including strong hands-on experience in PlainID and access management implementation.
- 3+ years with access control models—specifically PBAC—and how each maps to real enterprise use cases.
- 3+ years of experience integrating and supporting complex integrations and connectors for PIP integration.
- Strong knowledge of ensuring compliance with internal and external regulations, including SOX, GDPR, and ISO standards.
- Experience integrating with identity providers and standard protocols: OAuth 2.0, OpenID Connect, SAML, JWT.
- Comfort with policy-as-code concepts and reading/writing structured policy logic (e.g., Rego or similar rules-based languages).
- Working knowledge of APIs and microservices architectures, plus experience with at least one API gateway (Apigee, Kong, Azure API Management, or similar).
- Proven ownership of CAB/change governance, release management, and stakeholder management.
- Advanced troubleshooting capability with strong knowledge of PlainID integration.
- Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred Qualifications
- Previous consulting or Big 4 experience.
- Experience with RBAC, ABAC.
- Strong documentation, reporting, and executive communication skills.
- Ability to manage vendor coordination.
Pay
The wage range for this role is $134,500 to $265,100. At Deloitte, it is not typical for an individual to be hired at or near the top of the range, and compensation decisions depend on various factors, including skill sets, experience, training, licensure, certifications, and business needs. You may also be eligible to participate in a discretionary annual incentive program, subject to program rules.