Senior Identity & Access Management (CIAM) Engineer job in Plano

PepsiCo, Inc.
Plano, TX, United States
10 days ago
Apply on jobs.diversity.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$80,200.0 - $134,250.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Microsoft Windows Application Programming Interfaces (APIs) Agile Methodology Amazon Web Services Apache HTTP Server Application Integration Architecture Audit Trail User Authentication Microsoft Azure Business Systems
+64 more
Cloud Computing Configuration Management Cyber Security System Configuration Continuous Integration Cross-Origin Resource Sharing (Ajax Programming) Customer Data Management Linux Middleware Github Identity and Access Management Mobile Application Software Python (Programming Language) Lightweight Directory Access Protocols (LDAP) Node.Js OAuth OpenID Ping (Networking Utility) Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Ansible Prometheus JSON Web Token Runbook Salesforce.Com Security Assertion Markup Language (SAML) SAP (Applications) Session Management Security Information and Event Management SQL Databases Systems Integration User Provisioning Software Web Applications Web Application Frameworks Data Logging Scripting Load Balancing Cloud Platform System Okta ReactJS Spring-boot Software Security Software Troubleshooting Git Siteminder Customer Identity Access Management Single Page Application Kubernetes Information Technology Low Latency Data Management Api Gateway Restful APIs Terraform Splunk Webhooks Devsecops Api Management Docker Jenkins Web Api Microservices

Job description

The Identity Access Management (IAM) Engineer will serve as a hands-on technical resource with strong Customer Identity and Access Management (CIAM) expertise, responsible for implementing, supporting, and improving secure identity solutions for B2B, B2C, and external user populations., * Serve as a hands-on CIAM technical resource for implementation, configuration, integration, and production support.

  • Configure and support CIAM solutions using Okta Customer Identity Cloud/Auth0, Okta, Ping, ForgeRock, or comparable platforms.
  • Build and support customer identity flows including registration, login, MFA, passwordless authentication, social login, consent, profile management, account recovery, and progressive profiling.
  • Support secure application integrations using OAuth 2.0, OpenID Connect, SAML, JWT, SCIM, REST APIs, SDKs, webhooks, and token-based authorization patterns.
  • Implement B2B and B2C identity patterns for web, mobile, portal, API, eCommerce, and partner-facing applications.
  • Configure platform capabilities such as Auth0 Actions, Rules, Hooks, Organizations, Management APIs, Okta Workflows, Identity Engine, Universal Directory, and Lifecycle Management.
  • Develop scripts, workflows, and automation to support identity lifecycle, application onboarding, monitoring, reporting, and operational efficiency.
  • Work with Cybersecurity, API, architecture, digital product, and application teams to support secure authentication and authorization patterns.
  • Participate in CIAM roadmap delivery, platform modernization, migrations, and capability enhancements.
  • Troubleshoot authentication, federation, token, consent, profile, directory, API, latency, and production availability issues.
  • Support monitoring, alerting, logging, audit, and reporting using tools such as Splunk, ELK, Prometheus, or native platform logs.
  • Implement security controls such as adaptive authentication, attack protection, bot protection, risk-based access, identity proofing integrations, and zero trust-aligned policies.
  • Support privacy, regulatory, audit, and compliance requirements related to customer identity, consent, data protection, and access governance.
  • Use DevSecOps practices, CI/CD pipelines, Git-based configuration management, Terraform, Ansible, or similar tools to improve repeatability and reduce manual changes.
  • Create and maintain integration patterns, technical design documents, runbooks, standards, and operational handoff materials.
  • Provide Level 2/Level 3 support, incident support, root cause analysis, and improvement recommendations for CIAM services.
  • Share technical knowledge with team members and contribute to Agile DevOps delivery practices.

Requirements

This role requires solid technical experience in CIAM platforms such as Okta Customer Identity Cloud/Auth0, Okta, Ping, or ForgeRock, with strong hands-on knowledge of OAuth 2.0, OpenID Connect, SAML, JWT, SCIM, API integrations, MFA, passwordless, adaptive authentication, and customer identity lifecycle flows.

The engineer will work on CIAM implementation activities from requirements through production support, including platform configuration, application integration, testing, troubleshooting, documentation, and operational handoff.

The successful candidate should be able to operate independently on technical tasks, support CIAM design discussions, strengthen security controls, and help onboard digital applications while maintaining good user experience and compliance alignment.

Must have strong hands-on configuration, scripting, API integration, troubleshooting, and support experience in CIAM or access management environments., * 8+ years of overall IT experience with hands-on engineering or support background.

  • 6+ years of IAM, access management, authentication, federation, or identity engineering experience.
  • 4+ years of hands-on CIAM implementation or support experience for B2B, B2C, external customer, partner, or digital identity use cases.
  • Hands-on experience with Okta Customer Identity Cloud/Auth0, Okta, Ping, ForgeRock, or comparable CIAM platform.
  • Strong working knowledge of OAuth 2.0, OpenID Connect, SAML 2.0, JWT, SCIM, LDAP, REST APIs, SDKs, webhooks, and API security.
  • Hands-on experience configuring CIAM applications, connections, identity providers, login/sign-up flows, redirect URIs, callback URLs, logout URLs, custom domains, and branding.
  • Good understanding of OAuth/OIDC flows including Authorization Code with PKCE, Client Credentials, refresh tokens, scopes, claims, audiences, issuers, token validation, and token lifetime management.
  • Experience integrating CIAM with single-page applications, mobile apps, backend APIs, portals, and partner-facing applications using vendor SDKs, REST APIs, and modern web frameworks.
  • Experience configuring or supporting MFA, passwordless authentication, social login, enterprise federation, user registration, account recovery, profile management, and consent capture.
  • Hands-on experience with custom claims, rules/actions/hooks, API permissions, RBAC, groups/roles, attribute mapping, and user metadata/profile attribute management.
  • Experience troubleshooting CIAM issues related to redirects, SSO sessions, token errors, certificate/metadata mismatches, CORS, API authorization failures, login failures, and user provisioning issues.
  • Understanding of CIAM security controls such as adaptive MFA, bot/credential attack protection, breached password detection, rate limits, tenant logs, suspicious activity monitoring, and audit logging.
  • Hands-on scripting or development experience using Java, JavaScript, Node.js, React, Spring Boot, Python, PowerShell, or similar technologies.
  • Experience with CI/CD, DevSecOps, Git, Terraform, Ansible, Jenkins, GitHub Actions, Azure DevOps, or comparable automation tools.
  • Experience supporting production IAM or CIAM platforms, including monitoring, logging, incident support, root cause analysis, and performance troubleshooting.
  • BS/BA degree in Computer Science, Information Security, Engineering, or equivalent work experience.
  • Okta Certified Administrator preferred Okta Certified Consultant, Okta Certified Developer, Auth0/Okta Customer Identity Cloud certification, or Ping/ForgeRock certification is a plus.
  • CISSP, CIAM, CISM, or comparable security certification is a plus.

Preferred Qualifications:

  • Experience implementing enterprise CIAM solutions at scale.
  • Hands-on experience with Okta Customer Identity Cloud/Auth0 capabilities such as Actions, Rules, Hooks, Organizations, Management API, attack protection, log streaming, and custom domains.
  • Experience with Okta Identity Engine, Universal Directory, Lifecycle Management, Workflows, Administrative APIs, and application integration patterns.
  • Exposure to Ping, ForgeRock, SiteMinder, Azure AD/Entra ID, AWS Cognito, or other identity platforms is preferred.
  • Ability to support secure B2B and B2C identity models for large-volume customer environments, including retail, eCommerce, mobile, portal, or partner ecosystems.
  • Good understanding of authentication and authorization patterns including SSO, federation, token exchange, refresh tokens, session management, scopes, claims, consent, and delegated authorization.
  • Understanding of API gateways, microservices, REST integration, reverse proxies, load balancers, headers-based authentication, and secure API access patterns.
  • Experience integrating CIAM with web applications, mobile applications, CRM, Salesforce, SAP, eCommerce platforms, directories, data platforms, or downstream business systems.
  • Awareness of privacy and security requirements such as GDPR, CCPA, consent capture, data minimization, audit logging, and customer data protection.
  • Experience with security controls such as risk-based authentication, adaptive MFA, bot mitigation, credential attack protection, suspicious activity detection, and passwordless authentication.
  • Hands-on experience with Java, Node.js, JavaScript, React, Spring Boot, Python, PowerShell, SQL, and REST API development.
  • Experience deploying or supporting identity solutions in AWS, Azure, or hybrid environments.
  • Exposure to Docker, Kubernetes, Linux, Windows, middleware, Apache, and enterprise infrastructure components.
  • Experience with Splunk, ELK, Prometheus, native CIAM logs, SIEM integrations, or operational dashboards.
  • Experience creating reusable integration patterns, runbooks, standards, and technical documentation.
  • Experience supporting application migrations from legacy IAM platforms to modern CIAM capabilities.
  • Ability to troubleshoot complex issues while continuing to build deeper SME-level expertise.

Non-Technical skills:

  • Strong communication skills with the ability to explain CIAM concepts to technical teams, application owners, and security partners.
  • Self-starter who can analyze requirements, identify risks, propose solutions, and complete technical tasks with limited guidance.
  • Strong analytical and problem-solving skills, especially during integration troubleshooting and production support.
  • Ability to balance security, user experience, scalability, performance, compliance, and delivery timelines.
  • Ability to work across global teams, vendors, cybersecurity, architecture, product, and application teams.
  • Good documentation discipline, including integration guides, runbooks, standards, and operational handoff materials.
  • Flexible and able to adapt to changing priorities in a fast-paced enterprise environment.

Benefits & conditions

  • The expected compensation range for this position is between $80,200 - $134,250.
  • Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
  • Bonus based on performance and eligibility target payout is 8% of annual salary paid out annually.
  • Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
  • In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.diversity.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all