The Senior/Principal Identity and API Architect will lead the design and ownership of TripleLift's identity infrastructure and API security strategy within the Exchange team. Responsibilities include architecting the identity platform, implementing Auth0 tenant architecture, enforcing OAuth 2.0 and OIDC flows, building multi-tenant authorization models, managing API gateway layers, leading publisher and demand-side identity integrations, managing AWS identity infrastructure, establishing security standards, and mentoring engineers. Requirements include 8+ years software engineering or platform architecture experience with 4+ years in identity/IAM/API security, hands-on experience with Auth0, OAuth 2.0, OIDC, SAML 2.0, JWT, AWS identity services, API gateway technologies, and proficiency in Go, Java, or Python. Benefits include medical, dental, vision plans, flexible PTO, and 401k with employer match. Salary range is $175,000 to $250,000 USD. Location is New York, NY, USA.
What you'll do
Architect and own TripleLift’s end-to-end identity platform including tenant models, SSO integrations, machine-to-machine authentication, and delegated administration
Similar jobs
More roles worth a look
Related opportunities based on specialty and working model so candidates can keep momentum.
Design and implement Auth0 tenant architecture including custom domains, enterprise connections, Actions/Rules, and token lifecycle management
Define and enforce OAuth 2.0 and OIDC flows across the Exchange ensuring secure and consistent authentication
Build and operate multi-tenant authorization models using OpenFGA or comparable ReBAC systems
Own the API gateway layer designing rate limiting, scoped token validation, mTLS enforcement, and consistent error semantics
Lead publisher-side identity integrations including federated SSO, delegated self-service administration, and integration of first-party data and authenticated traffic signals
Lead demand-side identity integrations including DSP and agency API authentication, partner onboarding flows, and identity traceability for audit and fraud detection
Manage AWS identity and API infrastructure including IAM roles, cross-account trust, Cognito integration, Secrets Manager, KMS, and STS-based service-to-service authentication
Establish and maintain identity and API security standards including threat modeling and compliance reviews
Serve as internal subject-matter expert on identity and API architecture advising on protocol selection, vendor evaluation, and regulatory considerations
Mentor engineers on identity best practices, OAuth/OIDC protocol nuances, and secure API design patterns
Requirements
8+ years of software engineering or platform architecture experience, with at least 4 years focused on identity, IAM, or API security
2+ years of hands-on production experience with Okta's Auth0
Experience with tenant architecture, custom domains, and enterprise connections in Auth0
Experience with Actions/Rules/Hooks and the Auth0 Management API
Experience with OIDC/OAuth 2.0 flows including PKCE, M2M client credentials, and device authorization
Experience with token customization, refresh token rotation, and session management
Production experience with OpenFGA or comparable ReBAC systems (e.g., Zanzibar-derived implementations, Ory Keto, SpiceDB)
Deep fluency in OAuth 2.0, OpenID Connect, SAML 2.0, JWT, and JWKS
Demonstrated AWS identity and API infrastructure experience including IAM roles, policies, cross-account trust, API Gateway, Lambda authorizers, Cognito integration, Secrets Manager, KMS, and STS
Experience designing and operating API gateway layers at scale (Traefik, Kong, AWS API Gateway, or equivalent)
Experience with publisher-side identity integrations including federated SSO (SAML 2.0, OIDC), multi-tenant identity models, delegated administration, and integration with publisher identity signals
Experience with demand-side identity integrations including DSP and agency API authentication, partner onboarding flows, identity traceability, and buyer identity infrastructure
Ability to model complex multi-tenant authorization hierarchies using RBAC, ABAC, or ReBAC
Proficiency in at least one backend language (Go, Java, or Python preferred)
Tech stack
Auth0OAuth 2.0OIDCSAML 2.0JWTJWKSOpenFGASpiceDBOry KetoAWS IAMAWS API GatewayLambdaCognitoSecrets ManagerKMSSTSTraefikKongGoJavaPython
Benefits
Medical, Dental & Vision PlansFlexible PTO401k with employer match
Apply now
Ready to take the next step in your career? Click the button below to continue to the application process.