CISO Technical Lead SSO Engineer

Tata Consultancy Services Limited
Irving, TX, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$100,000.0 - $130,000.0
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Active Directory User Authentication Cyber Security Data Governance Multi-Factor Authentication Federated Identity Management Identity and Access Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth OpenID Windows PowerShell
+8 more
Openid Connect Azure Active Directory Runbook Security Assertion Markup Language (SAML) Scripting Pingfederate Information Technology Vulnerability Analysis

Job description

1) CISO Technical Lead - SSO Engineer Services:

  • Divestiture Strategy & Execution:

o Drive development and execution strategies for the secure separation, migration, and integration of PingFederate instances, configurations, and associated identity stores for divested business units. o Plan and implement identity federation solutions to support application access for users transitioning between organizations, ensuring minimal disruption. o Manage the lifecycle of federated trusts, connections, and identity providers/service providers in the context of divestiture, including onboarding and offboarding applications.

  • PingFederate Implementation & Management:

o Design, deploy, configure, and maintain high-availability PingFederate environments across various enterprise landscapes. o Administer PingFederate connections, policies, adapters, selectors, and authentication methods (e.g., SAML, OAuth, OIDC). o Troubleshoot complex SSO authentication, authorization, and federation issues to ensure continuous service availability.

  • Identity & Access Integration:

o Integrate PingFederate with various identity stores such as Active Directory, Azure Active Directory, and LDAP directories. o Collaborate with application owners to onboard new applications and migrate existing ones to the PingFederate SSO platform. o Ensure seamless integration with Multi-Factor Authentication (MFA) solutions.

  • Security & Compliance:

o Implement and enforce security best practices and architectural guidelines for identity federation and SSO solutions. o Ensure that SSO configurations comply with corporate security policies, regulatory requirements, and data governance standards during the divestiture process. o Conduct regular security reviews and vulnerability assessments of the PingFederate environment.

  • Operational Support & Documentation:

o Provide expert-level support for SSO-related incidents and requests, often collaborating with cross-functional IT and security teams. o Develop and maintain comprehensive documentation, architectural diagrams, runbooks, and standard operating procedures (SOPs) for the SSO infrastructure. Deliverables:

  • Secure Divestiture & Federated Identity Transition

  • Resilient PingFederate & SSO Platform Operations

  • Security, Compliance & Operational Excellence

Requirements

  • Bachelor’s degree in computer science, Information Security, or a related technical fi eld, or equivalent practical experience.

  • 5+ years of dedicated experience in Identity and Access Management (IAM), with at least 3 years focused specifically on SSO technologies.

  • Proficiency in designing, implementing, and managing PingFederate in large-scale enterprise environments.

  • Understanding and hands-on experience with identity federation protocols such as SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).

  • Experience integrating SSO solutions with various applications and identity stores (e.g., Active Directory, Azure AD, LDAP).

  • Proficiency in scripting languages (e.g., PowerShell, Python) for automation and administration tasks.

  • Excellent analytical, problem-solving, and communication skills, with the ability to articulate complex technical concepts to both technical and non-technical audiences.

  • Required: English fluency (oral and written)., Qualifications : BACHELOR OF COMPUTER SCIENCE

Benefits & conditions

(part of Tata group) 3.93.9 out of 5 stars Irving, TX $100,000 - $130,000 a year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all