Lead Cloud Identity Engineer

Koch, Inc.
Atlanta, GA, United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Automation of Tests Microsoft Azure Continuous Integration Human Resources Information System (HRIS) Identity and Access Management Python (Programming Language) Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) OAuth OpenID
+17 more
Role-Based Access Control Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Security Information and Event Management TypeScript Data Logging Google Cloud Okta Power Platform Integration Git Customer Identity Access Management SailPoint Software Coding Terraform Software Version Control Api Management

Job description

  • Set IAM architecture & standards: Define reusable patterns for SSO/federation, authorization models, privileged access, and workload/machine identity.
  • Lead design governance: Run identity design reviews for new applications and major platform changes; approve patterns, manage exceptions, and drive adoption.
  • Build authentication & federation: Design and implement SAML2, OAuth2/OIDC, WS-Fed, and FIDO2/passkeys, including adaptive/risk-based auth, conditional access, and MFA.
  • Engineer IAM platforms: Operate and enhance enterprise identity services (PingOne / PingOne DaVinci or equivalent orchestration platforms).
  • Lead developer for IAM platforms: Serve as lead developer driving hands-on code development to build, extend, and maintain new and existing identity platforms, including custom connectors, APIs, and orchestration flows.
  • Design authorization & governance: Build scalable RBAC/ABAC/PBAC models, entitlement catalogs, role engineering, and access request workflows (IGA).
  • Automate identity lifecycle: Lead and design end-to-end JML automation integrating HRIS, ITSM, directories, and apps via SCIM and event-driven pipelines.
  • Identity as Code: Manage identity configuration/policy using Terraform and CI/CD with testing, version control, and deployment discipline.
  • Zero Trust & Detection: Implement least privilege and continuous verification; integrate ITDR-style monitoring, logging, alerting, SLOs, and rapid revocation.
  • Incident leadership: Act as escalation for auth outages, federation issues, and credential compromise; lead RCA and post-incident hardening.
  • Influence & mentoring: Partner globally with architects, developers, and security; coach engineers through reviews, playbooks, and training.

Requirements

  • Extensive experience owning identity platforms at scale, with deep protocol-level expertise across SAML, OAuth2/OIDC, SCIM, FIDO2/passkeys, LDAP, and Kerberos.
  • Hands-on architecture across Azure Entra ID, AWS IAM, or Google Cloud Identity, including cross-cloud federation and hybrid identity patterns.
  • Practical experience designing and building infrastructure across Azure, AWS, or GCP.
  • Strong coding skills in Python and/or TypeScript, with API integrations, Git, CI/CD, and automated testing. Delivery of identity configuration as versioned, testable code using Terraform or similar technologies.Hands-on experience integrating diverse applications with enterprise governance platforms; design and delivery of JML automation, RBAC/ABAC/PBAC models and access workflows integrating HRIS IAM
  • downstream apps via SCIM and event-driven pipelines., * Experience building multi-step user journeys for Workforce, CIAM, and partner ecosystems using platforms such as PingOne DaVinci or Okta Workflows.
  • Hands-on development and design experience with SailPoint IdentityNow/IdentityIQ (or equivalent).
  • Real-time detection and response to identity-based threats, integrating signals from IdPs, directories, and SIEM/SOAR platforms.

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Paid parental leave
  • AD&D insurance
  • Parental leave
  • Health insurance
  • Vision insurance
  • Health savings account

About the company

We have an exciting opportunity to hire a Lead Cloud Identity Engineer to join our already skilled engineering team. This individual will be a part of a global team that manages authentication and identity tools and procedures for Koch Industries. Working closely with global colleagues, as well as customers, will provide significant global exposure.

Our Team

The Koch Technology Identity team provides modern Identity solutions and services for all Koch businesses. We are responsible for the entire enterprise in designing innovative services, creating, and sharing best practices, and providing support for our services., All Koch companies value diversity of thought, perspectives, aptitudes, experiences, and backgrounds. We are Military Ready and Second Chance employers. Learn more about our hiring philosophy here ., Koch creates and innovates a wide spectrum of products and services that make life better. Our work spans a vast number of industries across the world, including engineered technology, refining, chemicals and polymers, pulp and paper, glass, electronics and many more. Headquartered in Wichita, Kansas, Koch employs about 120,000 employees across the globe.

At Koch, employees are empowered to do what they do best to make life better. Learn how our business philosophy helps employees unleash their potential while creating value for themselves and the company.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all