AdTechTalent
Engineering1 month agoOn-site

TripleLift

Principal Identity and API Architect

identityAPI securityAuth0OAuth 2.0OIDCSAML 2.0JWTOpenFGAAWSAPI GatewayTraefikKongGoJavaPythonprogrammaticIAMReBACRBACABAC

Key details

Salary

€90K – €130K

Employment type

Full-time

Seniority

Senior

Years experience

5-10

Location

London, United Kingdom

Full job description

The Senior/Principal Identity and API Architect will lead the design and ownership of TripleLift’s identity platform and API security strategy within the Exchange team. Responsibilities include architecting tenant models, SSO integrations, machine-to-machine authentication, delegated administration, and API gateway management. The role requires expertise in Auth0 tenant architecture, OAuth 2.0, OIDC, SAML 2.0, JWT, OpenFGA or similar ReBAC systems, and AWS identity and API infrastructure. The architect will lead publisher and demand-side identity integrations, establish security standards, and mentor engineers. Required experience includes 8+ years in software engineering or platform architecture with 4+ years focused on identity/IAM/API security, hands-on Auth0 experience, and proficiency in Go, Java, or Python. Benefits include medical, dental, vision plans, flexible PTO, and 401k with employer match. Salary range is €90,000 to €130,000 EUR. Location is London, England, United Kingdom.

What you'll do

  • Architect and own TripleLift’s end-to-end identity platform including tenant models, SSO integrations, machine-to-machine authentication, and delegated administration
  • Design and implement Auth0 tenant architecture including custom domains, enterprise connections, Actions/Rules, and token lifecycle management
  • Define and enforce OAuth 2.0 and OIDC flows across the Exchange ensuring secure and consistent authentication
  • Build and operate multi-tenant authorization models using OpenFGA or comparable ReBAC systems
  • Own the API gateway layer including rate limiting, scoped token validation, mTLS enforcement, and consistent error semantics
  • Lead publisher-side identity integrations including federated SSO, delegated self-service administration, and integration of first-party data and authenticated traffic signals
  • Lead demand-side identity integrations including DSP and agency API authentication, partner onboarding flows, and identity traceability for audit and fraud detection
  • Manage AWS identity and API infrastructure including IAM roles, cross-account trust, Cognito integration, Secrets Manager, KMS, and STS-based service-to-service auth
  • Establish and maintain identity and API security standards including threat modeling and compliance reviews
  • Serve as internal subject-matter expert on identity and API architecture advising on protocols, vendor evaluation, and regulatory considerations
  • Mentor engineers on identity best practices, OAuth/OIDC protocols, and secure API design

Requirements

  • 8+ years of software engineering or platform architecture experience
  • At least 4 years focused on identity, IAM, or API security
  • 2+ years hands-on production experience with Okta's Auth0
  • Experience with tenant architecture, custom domains, and enterprise connections in Auth0
  • Experience with Actions/Rules/Hooks and Auth0 Management API
  • Experience with OIDC/OAuth 2.0 flows including PKCE, M2M client credentials, and device authorization
  • Experience with token customization, refresh token rotation, and session management
  • Production experience with OpenFGA or comparable ReBAC systems
  • Deep fluency in OAuth 2.0, OpenID Connect, SAML 2.0, JWT, and JWKS
  • Demonstrated AWS identity and API infrastructure experience including IAM roles, policies, cross-account trust, API Gateway, Lambda authorizers, Cognito integration, Secrets Manager, KMS, and STS
  • Experience designing and operating API gateway layers at scale with Traefik, Kong, AWS API Gateway or equivalent
  • Experience with publisher-side identity integrations including federated SSO, multi-tenant identity models, delegated administration, and integration with identity signals
  • Experience with demand-side identity integrations including DSP and agency API authentication, partner onboarding flows, identity traceability, and buyer identity infrastructure
  • Ability to model complex multi-tenant authorization hierarchies using RBAC, ABAC, or ReBAC
  • Proficiency in at least one backend language (Go, Java, or Python preferred)

Tech stack

Auth0OAuth 2.0OIDCSAML 2.0JWTJWKSOpenFGASpiceDBOry KetoAWS IAMAWS API GatewayAWS LambdaAWS CognitoAWS Secrets ManagerAWS KMSSTSTraefikKongGoJavaPython

Benefits

Medical, Dental & Vision PlansFlexible PTO401k with employer match

Apply now

Ready to take the next step in your career? Click the button below to continue to the application process.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.