> Markdown version of [/jobs/ext/1263854-sso-technical-lead](https://www.wearedevelopers.com/jobs/ext/1263854-sso-technical-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SSO Technical Lead - **Company:** Machinify, Inc. - **Location:** La Grange, KY, United States - **Experience:** Expert - **Salary:** $15,080.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Software Applications, User Authentication, Automation of Tests, Business Systems, Software as a Service, Cyber Security, Information Systems, Multi-Factor Authentication, Identity and Access Management, Python (Programming Language), OAuth, OpenID, Oracle (Applications), Ping (Networking Utility), Windows PowerShell, Azure Active Directory, Salesforce.Com, Security Assertion Markup Language (SAML), SAP (Applications), Single Sign-On, Systems Integration, Workflow Management Systems, Enterprise Software Applications, Okta, Information Technology, Coupa Procurement, DocuSign, Workday, Servicenow - **Published:** July 14, 2026 - **Apply:** https://www.juju.com/job/00000000ggi34e ## About the Role Bachelor's degree in Computer Science, Information Systems, or related field. 5+ years of experience in IT Applications, Identity Management, or System Integration roles. Proven experience implementing SSO usingMicrosoft Entra ID (Azure AD),Okta,Ping, or equivalent. Strong understanding ofSAML 2.0, OAuth 2.0, OIDC, and SCIMstandards. Experience integrating SSO with SaaS and on-premise applications (e.g., Workday, Paycom, Salesforce, SAP, Oracle, ServiceNow, Coupa, DocuSign). Practical knowledge of theNIST Cybersecurity Framework, andHITRUST particularly as it applies to authentication, identity, and access control. Solid understanding oflayered security architectureimplementing defense-in-depth controls across network, application, and identity layers. Demonstrated experience enforcingleast privilege access, role-based permissions, and segregation of duties. Strong troubleshooting skills in authentication flows, certificates, and federation services. Ability to balance hands-on technical work with stakeholder communication, project management, and documentation. Proven ability to work cross-functionally and influence teams in a fast-paced environment. Preferred Skills Familiarity withidentity governance and administration (IGA)frameworks and lifecycle automation. Exposure toAPI-based integrations, automation scripts (PowerShell, Python), or workflow orchestration tools. Experience in ahigh-tech or SaaS environmentsupporting enterprise business systems. Security certifications (CISSP, CISM, or Microsoft Identity and Access certifications) are a plus. ## Description Machinify is modernizing its enterprise systems landscape, and single sign-on (SSO) is at the core of our security and user experience strategy. We are looking for an SSO Technical Lead to drive the design, implementation, and enablement of SSO across all enterprise applications from HR and Finance to Sales and Operations. This is a hands-on technical leadership role that requires strong problem-solving skills, cross-functional collaboration, and the ability to quickly learn and integrate new technologies. You will work closely with business system owners, IT security, and external partners to ensure consistent, secure, and seamless authentication experiences across the company, while aligning with NIST cybersecurity standards, layered defense principles, and least privilege access models. What You'll Do Lead the end-to-end implementationof SSO for all enterprise applications - including HR, Order Management, Operations, Sales, Service, Legal, and Procurement systems. Design and configure identity integrationsusing Entra ID (Azure AD), Okta, or similar identity providers to enable SAML, OIDC, and OAuth-based authentication. Implement layered security controlsthat align with theNIST and HITRUST particularly regarding protection of PHI ( Protected Health Information) and personally identifiable data. Apply least privilege access principlesacross all SSO-enabled applications to ensure users and service accounts have the minimal required access for their roles. Partner cross-functionallywith system owners, InfoSec, and application teams to assess requirements, plan integrations, and execute go-live with secure authentication flows. Standardize and documentSSO integration patterns, metadata exchange, and token policies to ensure scalability, consistency, and auditability. Collaborate with InfoSecto enforce MFA, conditional access, and continuous monitoring for privileged and non-privileged accounts. Maintain and enhance existing SSO configurations, certificates, and policies to support business continuity and compliance with company security policies. Evaluate and onboard new SaaS applications, ensuring that each integration adheres to layered security and least privilege principles. Troubleshoot and resolve SSO integration issuesacross multiple identity providers and environments with a focus on security and operational resilience. Provide mentorship and knowledge sharingwithin the IT Applications and Security teams on identity, access management, and cybersecurity best practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)