> Markdown version of [/jobs/ext/3011652-specialist-lead-zero-trust-identity-security-engineering](https://www.wearedevelopers.com/jobs/ext/3011652-specialist-lead-zero-trust-identity-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Specialist, Lead Zero Trust Identity Security Engineering - **Company:** Vanguard - **Location:** Malvern, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, Active Directory, Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, Data Architecture, DevOps, Identity and Access Management, Information Systems Security Architecture Professional, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Zero Trust Network Access, Security Assertion Markup Language (SAML), Policy as Code, Cloud Platform System, Okta, Cloudformation, Pingfederate, Kubernetes, Deployment Automation, Terraform - **Published:** September 20, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2962346018-2 ## About the Role * Undergraduate degree in a related field or the equivalent combination of training and experience. * 12+ years of experience in Identity & Access Management engineering. * Skilled in using DevOps tools and experience in Policy as code. * Deep hands on expertise with Okta (Workforce Identity, MFA, SSO, policies, lifecycle). * Strong working knowledge of Ping Identity products (PingFederate, PingOne, Ping Directory) or equivalent platforms. * Expert understanding of identity standards: OAuth 2.0, OIDC, SAML Federation and token based security * Proven experience with directory services & LDAP (AD, cloud directories). * Experience building identity platforms in AWS/GCP, including containerized/Kubernetes deployments. * Strong troubleshooting skills for complex authentication and federation failures. * Ability to operate in high visibility, high impact environments. ## Description We are seeking a Senior Lead Identity Engineer to provide technical leadership for our workforce identity platform, with deep expertise in Okta and strong proficiency in standards based identity and access management technologies. This role is responsible for designing, operating, and evolving enterprise scale identity platforms that support high availability, regulatory compliance, and long term resiliency-including multi IdP and directory strategies. The ideal candidate brings 12+ years of identity engineering experience, understands identity as architecture-not just product configuration, and can operate comfortably across engineering, security, infrastructure, and executive stakeholders. Key ResponsibilitiesIdentity Platform Engineering & Leadership * Serve as technical lead for workforce identity platforms, with Okta as the primary IdP and integrations to complementary platforms (e.g., Ping/Entra Identity). * Own end to end identity architecture, including authentication flows, federation, directory integrations, and token issuance. * Lead design reviews and decisions for IdP resiliency, failover, and supplier risk mitigation strategies. * Document existing and new architecture and act as a hands on engineer while also setting technical direction, patterns, and standards. * Strong communication, influence, and stakeholder management skills, with the ability to distill complex identity and security architectures into clear and concise messaging Standards Based Identity & Federation * Design and troubleshoot identity flows using OAuth 2.0 / OIDC SAML 2.0 SCIM JWT / token based auth * Ensure token parity, claim consistency, and issuer abstraction across identity providers to minimize application impact. * Partner with application teams to enable modern authentication without app re architecture. Directory & Identity Data Architecture * Engineer and maintain directory integrations across Active Directory, Okta UD, and cloud directories (e.g., Ping Directory). * Design attribute models, lifecycle management, and group strategies at enterprise scale (thousands of groups, large population sizes). * Support directory deployments in cloud native environments (AWS/GCP, containers, Kubernetes). Cloud, Automation & Reliability * Build and operate identity infrastructure in AWS/GCP/Azure, using: Infrastructure & Policy as Code (Terraform / CloudFormation) Kubernetes & containerized identity services * Automate provisioning, deployment, monitoring, and drift detection for identity platforms. * Support SRE style operational maturity: SLIs/SLOs, alerting, incident response, and runbooks for identity services. Security, Risk & Compliance * Design identity controls aligned to Zero Trust principles and enterprise security policies. * Partner with CSOC, audit, and risk teams on: Control validation Incident response Regulatory and audit requirements (SOX, SOC, internal controls) * Contribute to risk assessments related to supplier dependency, SPOFs, and identity outages. Collaboration & Influence * Work closely with security architecture, infrastructure, application engineering, IAM operations, and vendors. * Influence roadmap decisions through clear technical reasoning and executive ready communication. * Mentor senior and mid level engineers and raise overall identity engineering maturity. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)