Cyber Identity - PlainID/PBAC Senior Engineering Management Specialist/Senior Consultant

Deloitte T.T.L.
Seattle, WA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$105,400.0 - $207,800.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) BigQuery Software Documentation Data Security Identity and Access Management OAuth Ping (Networking Utility) Role-Based Access Control Release Management Openid Connect Azure Active Directory JSON Web Token
+12 more
Security Assertion Markup Language (SAML) Systems Integration Management of Software Versions Okta Snowflake Apigee Data Management Virtual Agents Api Gateway Api Management Service Stack Microservices

Job description

As an experienced PlainID professional at Deloitte Consulting, you will be responsible for delivering high-quality work products within defined timelines while providing technical leadership to the PlainID team. This role combines deep technical ownership with engineering expertise and governance.

Work you’ll do

As a PlainID professional, you will:

  • Configure and implement the PlainID Authorization Platform within client environments, including policy modelling and decision-point/information-point setup.
  • Lead the technical discussions with Enterprise architects and IAM stake holders.
  • Design fine-grained, attribute-based access policies (PBAC/ABAC) that translate business rules into technical controls, including row- and column-level data access restrictions where needed.
  • Integrate PlainID with client identity providers (Okta, Microsoft Entra ID, Ping Identity, ForgeRock), API gateways, microservices, and data platforms such as Snowflake or Big Query.
  • Support the full policy lifecycle - authoring, testing, versioning, and deployment - using PlainID’s visual policy modeling and policy-as-code capabilities.
  • Run requirements sessions with client stakeholders to document current-state access patterns and design the target-state authorization model.
  • Troubleshoot policy conflicts, integration issues, and authorization-decision errors across the client’s technology stack.
  • Support testing, validation, and go-live activities, including access-decision auditing and performance checks.
  • Produce clear technical documentation - policy catalogs, integration diagrams, runbooks - for both the client and the internal delivery team.
  • Partner with engagement leads and architects to keep delivery on track and surface risks early.
  • Stay current on PlainID’s platform roadmap, including emerging capabilities for AI agent and machine-identity authorization.
  • Establish and maintain runbooks, SOPs, knowledge articles, and documentation standards for repeatable and governed support operations.Coordinate with client stakeholders, internal teams, and third-party vendors to resolve defects, manage dependencies, and improve service outcomes.

The Team

Enables trust and safety of online communications and digital products, protecting users, consumers, and patients from harm. Enables clients to provide consumer confidence in knowing with whom they are dealing and ensuring the integrity of access to data.

Requirements

Required :

  • 4+ years of total experience, including strong hands-on experience in PlainID implementation.

  • 3+ years with access control models - specifically PBAC - and how each maps to real enterprise use cases.

  • 3+ years of experience integrating and supporting complex integrations and connectors for PIP integration.

  • Must have strong knowledge of ensuring compliance with internal and external regulations, including SOX, GDPR, and ISO standards.

  • Experience integrating with identity providers and standard protocols: OAuth 2.0, OpenID Connect, SAML, JWT.

  • Comfort with policy-as-code concepts and reading/writing structured policy logic (e.g., Rego or similar rules-based languages).

  • Working knowledge of APIs and microservices architectures, plus experience with at least one API gateway (Apigee, Kong, Azure API Management, or similar).

  • Proven ownership of CAB/change governance, release management, and stake holder management.

  • Advanced troubleshooting capability with strong knowledge of PlainID integration.

  • Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred :

  • Previous consulting or Big 4 experience preferred.
  • Experience with RBAC, ABAC
  • Strong documentation, reporting, and executive communication skills.
  • Ability to manage vendor coordination

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

About the company

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · World Congress 2021

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

56 sec

Navigating compensation parity and exploring technical consulting opportunities

Marcin Olichwirowicz Marcin Olichwirowicz · World Congress 2026 Europe

Videos

See all

Related articles

See all