The Senior/Principal Identity and API Architect will lead the design and ownership of TripleLift’s identity platform and API security strategy within the Exchange team. Responsibilities include architecting tenant models, SSO integrations, machine-to-machine authentication, delegated administration, and API gateway management. The role requires expertise in Auth0 tenant architecture, OAuth 2.0, OIDC, SAML 2.0, JWT, OpenFGA or similar ReBAC systems, and AWS identity and API infrastructure. The architect will lead publisher and demand-side identity integrations, establish security standards, and mentor engineers. Required experience includes 8+ years in software engineering or platform architecture with 4+ years focused on identity/IAM/API security, hands-on Auth0 experience, and proficiency in Go, Java, or Python. Benefits include medical, dental, vision plans, flexible PTO, and 401k with employer match. Salary range is €90,000 to €130,000 EUR. Location is London, England, United Kingdom.
What you'll do
Architect and own TripleLift’s end-to-end identity platform including tenant models, SSO integrations, machine-to-machine authentication, and delegated administration
Similar jobs
More roles worth a look
Related opportunities based on specialty and working model so candidates can keep momentum.
Design and implement Auth0 tenant architecture including custom domains, enterprise connections, Actions/Rules, and token lifecycle management
Define and enforce OAuth 2.0 and OIDC flows across the Exchange ensuring secure and consistent authentication
Build and operate multi-tenant authorization models using OpenFGA or comparable ReBAC systems
Own the API gateway layer including rate limiting, scoped token validation, mTLS enforcement, and consistent error semantics
Lead publisher-side identity integrations including federated SSO, delegated self-service administration, and integration of first-party data and authenticated traffic signals
Lead demand-side identity integrations including DSP and agency API authentication, partner onboarding flows, and identity traceability for audit and fraud detection
Manage AWS identity and API infrastructure including IAM roles, cross-account trust, Cognito integration, Secrets Manager, KMS, and STS-based service-to-service auth
Establish and maintain identity and API security standards including threat modeling and compliance reviews
Serve as internal subject-matter expert on identity and API architecture advising on protocols, vendor evaluation, and regulatory considerations
Mentor engineers on identity best practices, OAuth/OIDC protocols, and secure API design
Requirements
8+ years of software engineering or platform architecture experience
At least 4 years focused on identity, IAM, or API security
2+ years hands-on production experience with Okta's Auth0
Experience with tenant architecture, custom domains, and enterprise connections in Auth0
Experience with Actions/Rules/Hooks and Auth0 Management API
Experience with OIDC/OAuth 2.0 flows including PKCE, M2M client credentials, and device authorization
Experience with token customization, refresh token rotation, and session management
Production experience with OpenFGA or comparable ReBAC systems
Deep fluency in OAuth 2.0, OpenID Connect, SAML 2.0, JWT, and JWKS
Demonstrated AWS identity and API infrastructure experience including IAM roles, policies, cross-account trust, API Gateway, Lambda authorizers, Cognito integration, Secrets Manager, KMS, and STS
Experience designing and operating API gateway layers at scale with Traefik, Kong, AWS API Gateway or equivalent
Experience with publisher-side identity integrations including federated SSO, multi-tenant identity models, delegated administration, and integration with identity signals
Experience with demand-side identity integrations including DSP and agency API authentication, partner onboarding flows, identity traceability, and buyer identity infrastructure
Ability to model complex multi-tenant authorization hierarchies using RBAC, ABAC, or ReBAC
Proficiency in at least one backend language (Go, Java, or Python preferred)