CIAM Engineer II, IAM Platform Engineering

Cencora
Conshohocken, PA, United States
8 days ago
Apply on myhrabc.wd5.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

JavaScript (Programming Language) Agile Methodology Amazon Web Services User Authentication Microsoft Azure Cloud Computing Cloud Engineering Cyber Security Customer Data Management DevOps Multi-Factor Authentication Federated Identity Management
+25 more
Identity and Access Management Python (Programming Language) OAuth OpenID Ping (Networking Utility) Windows PowerShell Reliability Engineering Openid Connect Azure Active Directory Zero Trust Network Access JSON Web Token Security Assertion Markup Language (SAML) Session Management Security Information and Event Management Single Sign-On Software Engineering Software Vulnerability Management Scripting Google Cloud Okta Customer Identity Access Management Information Technology Api Design Restful APIs Api Management

Job description

Configures, supports, and enhances Customer Identity and Access Management (CIAM) platforms that provide secure, scalable, and seamless authentication, authorization, registration, and profile management capabilities for customer-facing applications and digital experiences. Monitors platform performance, authentication telemetry, and security events to identify, troubleshoot, and resolve complex identity-related issues affecting customer access and user journeys. Develops and maintains API integrations, automation solutions, and identity workflows that enable secure connectivity between customer applications and enterprise identity services. Partners with software engineering, product, security, and architecture teams to implement, test, and optimize modern CIAM capabilities, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), federation, social login, and customer lifecycle management., * Configures, administers, and maintains enterprise CIAM platforms to support secure, reliable, and scalable customer authentication and authorization services.

  • Supports customer registration, account recovery, profile management, consent management, and identity lifecycle processes across digital channels.

  • Implements and manages authentication technologies including Single Sign-On (SSO), Multi-Factor Authentication (MFA), adaptive authentication, Passwordless authentication, and federated identity services.

  • Develops and supports integrations using industry-standard identity protocols such as OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and SCIM.

  • Analyzes authentication logs, customer identity telemetry, security events, and platform performance metrics to troubleshoot user access issues and identify root causes of service disruptions.

  • Designs and maintains API-based integrations between customer-facing applications and centralized identity services to support secure access management and customer onboarding processes.

  • Creates and maintains technical documentation, operational procedures, architecture diagrams, and support runbooks for CIAM platform services and integrations.

  • Collaborates with application development teams to design, test, and validate secure customer identity solutions for new digital products and enhancements.

  • Participates in platform upgrades, patching activities, configuration changes, and release validation efforts to ensure service stability and security.

  • Supports security assessments, vulnerability remediation efforts, audit requests, and compliance activities related to customer identity platforms.

  • Contributes to automation initiatives that improve operational efficiency, provisioning processes, monitoring capabilities, and platform reliability.

  • Assists in evaluating emerging CIAM technologies, authentication methods, and identity security best practices to continuously improve customer security and user experience.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related discipline, or equivalent combination of education and experience.

  • 2+ years of experience supporting Identity and Access Management, Customer Identity and Access Management (CIAM), platform engineering, software development, cloud engineering, or related technical disciplines.

  • Experience supporting identity platforms such as Okta Customer Identity, Auth0, Ping Identity, ForgeRock, Microsoft Entra External ID, or equivalent CIAM solutions.

  • Knowledge of identity and authentication standards including OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and RESTful APIs.

  • Experience troubleshooting authentication, federation, and user access issues in cloud and hybrid environments.

  • Familiarity with scripting or automation technologies such as JavaScript.

  • Understanding of security principles including Zero Trust, authentication, authorization, identity governance, session management, and customer data protection.

Preferred Qualifications

  • Industry certifications such as Certified Identity and Access Manager (CIAM), CISSP, Security+, Microsoft Identity and Access Administrator, Okta Certified Professional, Ping Identity Certification, or equivalent.

  • Experience with cloud platforms including Microsoft Azure, AWS, or Google Cloud.

  • Experience implementing customer-facing identity solutions at enterprise scale.

  • Knowledge of customer privacy regulations and compliance frameworks, including GDPR, CCPA, HIPAA, or similar standards.

  • Experience working in Agile, DevOps, or Site Reliability Engineering (SRE) environments.
  • Familiarity with scripting or automation technologies such as PowerShell, Python, or similar languages.

Success Factors

  • Strong analytical and problem-solving skills.

  • Ability to balance security requirements with customer experience objectives.

  • Effective collaboration across engineering, product, architecture, and cybersecurity teams.

  • Strong verbal and written communication skills.

  • Commitment to operational excellence, platform stability, and continuous improvement., We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora

About the company

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on myhrabc.wd5.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all