Identity Platform (IdP) Engineer

Capgemini
San Antonio, TX, United States
about 1 month ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$130,000.0 - $145,000.0
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) User Authentication CompTIA Security+ Cyber Security Multi-Factor Authentication Identity and Access Management Lightweight Directory Access Protocols (LDAP) OAuth OpenID Ping (Networking Utility) Azure Active Directory
+5 more
Zero Trust Network Access Security Assertion Markup Language (SAML) Web Applications Pingfederate Information Technology

Job description

Capgemini Government Solutions (CGS) LLC seeks a highly skilled Identity Platform (IdP) Engineer to join our Zero Trust Architecture team. In this role, you will be the one primary architect and administrator for identity services that form the “new perimeter” of our enterprise. You will bridge the gap between traditional networking and modern identity-centric security, ensuring that every access request is fully authenticated, authorized, and encrypted., As Identity Platform (IdP) Engineer, you will be responsible for:

  • Design and implement identity-based access control policies that adhere to Zero Trust principles (Never Trust, Always Verify).
  • Lead the deployment, configuration, and optimization of PingFederate and Ping Access to provide seamless SSO and attribute-based access control (ABAC).
  • Manage the full lifecycle of Identity, Credential, and Access Management (ICAM), including automated provisioning and complex directory integrations.
  • Collaborate with the SOC and Network teams to integrate identity signals into our broader security monitoring and incident response workflows.
  • Act as the subject matter expert for integrating PingFederate as the core Identity Provider (IdP) with third-party Zero Trust ecosystem components, including Privileged Access Manager (PAM), Master User Record (MUR) and Identity Governance and Administration (IGA).
  • Create and maintain authentication policies, including Multi-Factor Authentication (MFA) and Risk-Based Authentication (RBA).
  • Knowledge of directory services (Active Directory, LDAP, Azure AD).
  • Familiarity with NIST 800-207 Zero Trust Architecture standards.
  • A security-first mindset with the ability to troubleshoot complex authentication handshakes.
  • Provide guidance and hands-on training for onboarding new applications into PingFederate using self-service templates, OIDC, and SAML to ensure consistent security standards across the enterprise.

Requirements

  • Have an active Secret Government security clearance that requires U.S. citizenship
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related technical field.
  • Minimum of 6 years of hands-on experience in ICAM (Identity, Credential, and Access Management) within enterprise or government environments.
  • Deep proficiency with PingFederate (OIDC, SAML, OAuth protocols).
  • Strong experience with Ping Access for protecting web applications and APIs at the gateway level.

  • Active CompTIA Security+ (or equivalent IAT Level II certification) to meet compliance requirements

Benefits & conditions

Capgemini discloses salary range information in compliance with state and local pay transparency obligations. The disclosed range represents the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting, although we may ultimately pay more or less than the disclosed range, and the range may be modified in the future. The disclosed range takes into account the wide range of factors that are considered in making compensation decisions including, but not limited to, geographic location, relevant education, qualifications, certifications, experience, skills, seniority, performance, sales or revenue-based metrics, and business or organizational needs. At Capgemini, it is not typical for an individual to be hired at or near the top of the range for their role. The base salary range for the tagged location is $130K-$145K

This role may be eligible for other compensation including variable compensation, bonus, or commission. Full time regular employees are eligible for paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company’s sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.

About the company

Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem. The Group reported 2024 global revenues of 22.1 billion.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

Videos

See all

Related articles

See all