Senior Specialist, Lead Zero Trust Identity Security Engineering
Vanguard · Dallas, TX · Yesterday
HybridFinanceFull-time
Key Responsibilities
- Serve as technical lead for workforce identity platforms, with Okta as the primary IdP and integrations to complementary platforms (e.g., Ping/Entra Identity).
- Own end-to-end identity architecture, including authentication flows, federation, directory integrations, and token issuance.
- Lead design reviews and decisions for IdP resiliency, failover, and supplier-risk mitigation strategies.
- Document existing and new architecture and act as a hands-on engineer while also setting technical direction, patterns, and standards.
- Strong communication, influence, and stakeholder-management skills, with the ability to distill complex identity and security architectures into clear and concise messaging.
Standards-Based Identity & Federation Design
- Design and troubleshoot identity flows using OAuth 2.0 / OIDC, SAML 2.0, SCIM, JWT / token-based auth.
- Ensure token parity, claim consistency, and issuer abstraction across identity providers to minimize application impact.
- Partner with application teams to enable modern authentication without app re-architecture.
Directory & Identity Data Architecture
- Engineer and maintain directory integrations across Active Directory, Okta UD, and cloud directories (e.g., Ping Directory).
- Design attribute models, lifecycle management, and group strategies at enterprise scale (thousands of groups, large population sizes).
- Support directory deployments in cloud-native environments (AWS/GCP, containers, Kubernetes).
Cloud, Automation & Reliability
- Build and operate identity infrastructure in AWS/GCP/Azure, using: Infrastructure & Policy as Code (Terraform / CloudFormation), Kubernetes & containerized identity services.
- Automate provisioning, deployment, monitoring, and drift detection for identity platforms.
- Support SRE-style operational maturity: SLIs/SLOs, alerting, incident response, and runbooks for identity services.
Security, Risk & Compliance
- Design identity controls aligned to Zero Trust principles and enterprise security policies.
- Partner with CSOC, audit, and risk teams on: Control validation, Incident response, Regulatory and audit requirements (SOX, SOC, internal controls).
- Contribute to risk assessments related to supplier dependency, SPOFs, and identity outages.
Collaboration & Influence
- Work closely with security architecture, infrastructure, application engineering, IAM operations, and vendors.
- Influence roadmap decisions through clear technical reasoning and executive-ready communication.
- Mentor senior and mid-level engineers and raise overall identity engineering maturity.