Ping Identity Engineer
Role details
Job location
Tech stack
Job description
We are seeking an experienced Ping Identity Engineer to design, implement and support enterprise-grade identity and access management (IAM) solutions using the Ping Identity suite. The ideal candidate will have strong expertise in PingFederate, PingAccess, PingDirectory and modern authentication protocols including OAuth 2.0, OIDC and SAML 2.0.
This role will focus on secure federation, SSO enablement, API security and high-availability IAM architecture across enterprise and B2B environments., * Design, configure and support Ping Identity solutions including PingFederate (IdP/SP), PingAccess and PingDirectory.
- Implement secure SSO integrations using SAML 2.0, OAuth 2.0 and OpenID Connect (OIDC).
- Configure PingFederate as both Identity Provider (IdP) and Service Provider (SP) for enterprise and partner integrations.
- Design and implement OAuth2 authorization flows for web, mobile and API-driven applications.
- Integrate Ping platforms with external identity providers (Azure AD, ADFS, third-party IdPs).
- Configure and manage policy enforcement, access control rules and token mappings.
- Implement MFA and adaptive authentication solutions.
- Deploy and maintain high availability (HA), load balancing and disaster recovery (DR) configurations.
- Perform system upgrades, patching and environment hardening.
- Troubleshoot complex authentication, federation and token-related issues.
- Manage X.509 certificates, keystores and truststores for secure communications.
- Collaborate with application, security and infrastructure teams for secure IAM integrations.
- Develop technical documentation, runbooks and architecture diagrams.
Requirements
-
5+ years of IAM experience with at least 3+ years hands-on experience in Ping Identity products.
-
Strong expertise in:
-
PingFederate (IdP/SP configuration)
-
PingAccess
-
PingDirectory
Deep knowledge of:
- OAuth 2.0
- OpenID Connect (OIDC)
- SAML 2.0
- JWT
Experience integrating applications using REST APIs and token-based authentication.
Strong understanding of LDAP, LDAPS and directory replication.
Experience with web/application servers (Apache, Tomcat, Nginx).
Experience managing SSL/TLS and certificate lifecycle (OpenSSL, Keytool).
Strong troubleshooting and root cause analysis skills.