
Principal IAM Engineer, Consultant
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
β’ Provide senior technical guidance for the client's Customer Identity and Access Management (CIAM) platform.
β’ Design and implement secure, scalable identity solutions that support millions of customer interactions in a highly regulated financial services landscape.
β’ Act as the technical authority across engineering, architecture, cybersecurity, product, and delivery teams.
β’ Transform strategic identity initiatives into detailed engineering solutions.
β’ Create engineering-level solution designs that encompass architecture, integration patterns, data flows, security controls, operational readiness, and implementation sequencing.
β’ Collaborate with Product Owners, architects, cybersecurity teams, engineering, and delivery stakeholders to align technical solutions with business objectives.
β’ Manage technical delivery activities by overseeing dependencies, clarifying ownership, resolving obstacles, and ensuring predictable execution.
β’ Offer technical leadership and mentorship to engineering teams.
β’ Identify engineering risks, technical debt, architectural drift, and security vulnerabilities.
β’ Advise Product Owners on backlog prioritization, technical preparedness, engineering complexity, and delivery trade-offs.
β’ Facilitate technical decision-making across multiple teams.
β’ Support delivery governance by escalating recurring issues and overseeing execution quality.
β’ Develop reusable design patterns, technical standards, implementation guidance, and delivery playbooks.
β’ Document technical decisions, assumptions, risks, mitigation strategies, authentication flows, integration patterns, sequence diagrams, token architecture, and implementation guidance.
β’ Enhance collaboration across engineering, cybersecurity, architecture, product management, and vendor partners.
β’ Over 10 years of progressive experience in software engineering or identity engineering, including substantial time at Senior, Lead, Staff, or Principal Engineer levels.
β’ Extensive hands-on experience in designing and implementing enterprise-scale Customer Identity and Access Management (CIAM) solutions.
β’ Expert knowledge of Ping Identity, ForgeRock, Okta Customer Identity/Auth0, or Microsoft Entra External ID.
β’ Proven experience producing engineering-level design documentation for OAuth 2.0, OpenID Connect (OIDC), and SAML federation.
β’ Experience in documenting authentication and authorization processes.
β’ Familiarity with passwordless and MFA architectures.
β’ Knowledge of session and token management.
β’ Proficiency in API security and integration patterns.
β’ Experience creating sequence diagrams, data flows, and implementation designs.
β’ Ability to influence architectural and engineering decisions across multiple delivery teams without direct management authority.
β’ Experience in identifying technical debt, architectural drift, security vulnerabilities, and implementation risks.
β’ Strong understanding of secure software engineering, Zero Trust principles, and cloud-native identity architectures.
β’ Experience supporting high-volume customer-facing identity platforms in banking, credit unions, insurance, fintech, or similarly regulated industries.
β’ Excellent communication skills with the ability to build consensus among engineers, architects, product leaders, and executive stakeholders.
β’ Preferred: experience with large-scale CIAM migrations, consolidations, or modernization initiatives.
β’ Preferred: experience supporting mergers, acquisitions, or identity platform integrations.
β’ Preferred: experience with Azure API Management (APIM), Cosmos DB, F5 Distributed Cloud/Shape, or similar technologies.
β’ Preferred: experience integrating CIAM with customer-facing mobile applications and digital banking platforms.
β’ Preferred: familiarity with fraud prevention and identity risk platforms such as Outseer.
β’ Preferred: experience creating reusable architecture patterns, engineering standards, and technical playbooks.
β’ Preferred: knowledge of Infrastructure as Code, cloud-native architectures, and DevSecOps delivery practices.
β’ Work/life balance and encouragement to pursue other passions, enjoy the outdoors, and spend time with family.
β’ Manageable workload expectations set with clients and consultants.
Green Energy Venture AG
Abacus Group
EXP
Get handpicked remote jobs straight to your inbox weekly.