Infrastructure Manager (SSO Engineering Manager)

Huntington Bancshares
Dallas, TX, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$93,000.0 - $189,000.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) .NET Framework Architectural Patterns Microsoft Azure Cyber Security Multi-Factor Authentication Identity and Access Management Python (Programming Language) OAuth OpenID Ping (Networking Utility) Windows PowerShell
+12 more
Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) User-Centered Design Scripting Enterprise Software Applications Microsoft Power Automate Customer Identity Access Management Pingfederate Kubernetes Terraform Legacy Systems

Job description

This role will be onsite at our Easton office in Columbus, OH (or in Minnetonka, MN or Dallas, TX or within Huntington Footprint), The Senior Infrastructure Manager (SSO Engineering Manager) is responsible for leading the engineering, delivery, and ongoing operational support of the enterprise Single Sign-On (SSO) platforms supporting both Colleague (Workforce) and Customer (CIAM) authentication. This role manages a team of highly skilled SSO engineers and serves as the technical owner for centralized authentication, federation, and access management services across Azure Entra ID (Azure AD) and Ping Identity platforms. The manager ensures identity services are secure, scalable, resilient, and aligned with enterprise security, Zero Trust, and business strategies for cloud and on-prem applications, * Lead, mentor, and develop the SSO Engineering team, fostering a culture of technical excellence, accountability, and continuous learning.

  • Own end-to-end design, implementation, and support of enterprise SSO services, including SAML, OAuth, OIDC, MFA, RADIUS, and application federation patterns.
  • Oversee migration initiatives transitioning legacy platforms (e.g., IBM TFIM/WebSEAL, App Proxy) to modern architectures leveraging Azure Entra ID and PingFederate, PingDirectory, and PingOne.
  • Establish reusable templates, standards, and patterns for integrating new applications into SSO platforms and improving onboarding efficiency.
  • Partner closely with Cybersecurity, Azure Engineering, CIAM teams, and application owners to align identity solutions with regulatory, security, and Zero Trust requirements.
  • Direct troubleshooting and resolution of complex authentication issues across multi-environment architectures.
  • Drive automation and modernization initiatives (e.g., Power Automate/Logic Apps, infrastructure improvements, federation onboarding workflows).
  • Ensure compliance with enterprise controls, audit standards, and change management procedures.
  • Perform other leadership and technical responsibilities as assigned.

Requirements

  • Bachelor’s Degree or 4+ additional years of equivalent experience
  • 10+ years of related experience in Identity & Access Management or Information Security.
  • 3-5+ years of hands on experience with Ping Identity technologies (PingFederate, PingAccess, PingDirectory, PingOne MFA).
  • 3+ years of experience integrating SSO and MFA solutions with enterprise applications using SAML, OAuth, and OIDC.
  • 3+ years of experience managing or leading technical engineering teams., * Strong understanding of workforce authentication flows, federation patterns, and identity lifecycle processes.
  • Practical experience troubleshooting complex authentication failures in highly regulated or enterprise environments.
  • Experience with Azure AD/Entra ID, Conditional Access, App Registrations, and hybrid identity models.
  • Familiarity with PingOne DaVinci, PingAuthorize, or orchestration frameworks.
  • Experience with CI/CD pipelines, automation, and infrastructure-as-code (e.g., Terraform).
  • Knowledge of RADIUS authentication flows, NPS integrations, and MFA extensions.
  • Strong scripting or development skills (PowerShell, Python, Java, .NET).
  • Experience supporting environments undergoing modernization or legacy identity decommissioning initiatives.
  • Relevant certifications such as Ping Identity, CISSP, CISM, or equivalent.

Benefits & conditions

Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay) Yes

Workplace Type: Office

Our Approach to Office Workplace Type

Certain positions outside our branch network may be eligible for a flexible work arrangement. We’re combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team.

Compensation Range: $93,000 - $189,000 Annual Salary

The compensation range represents the anticipated low and high end of the base compensation range for this position. Actual compensation will vary based on various factors including but not limited to location, experience, and education. Colleagues in this position are also eligible to participate in an applicable incentive compensation plan. In addition, Huntington provides a variety of benefits to colleagues, including health insurance coverage, wellness program, life and disability insurance, retirement savings plan, paid leave programs, paid holidays and paid time off (PTO).

Huntington is an Equal Opportunity Employer.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on huntington.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

Videos

See all

Related articles

See all