AdTechTalent
Engineering1 month agoHybrid

Epsilon

Principal, Identity Architect

OAuthOpenID ConnectOIDCPKCESAMLidentity managementmachine identityM2Mcloud identityAWSGCPAzureZero TrustsecurityAPI securityidentity governancePythonBashidentity platformauthorizationtoken management

Key details

Salary

$128K – $238K

Employment type

Full-time

Seniority

Senior

Years experience

5-10

Location

Irving, United States

Full job description

Lead Epsilon's identity modernization program by migrating from legacy SAML and long-lived credentials to OAuth 2.1 / OpenID Connect standards. Design secure token flows, machine identity patterns, and integration standards across multi-cloud environments. Partner with Security, Cloud Engineering, Platform, Application, and Data teams to migrate service accounts and API keys to scoped, ephemeral machine identities. Implement authorization server integrations, token scopes, claims usage, and risk reduction strategies. Lead identity observability and governance improvements. Mentor architects and engineers, delegate work, and unblock complex integrations. Responsibilities include driving OAuth/OIDC adoption, designing secure token flows, transitioning to machine identities, supporting AI-assisted authentication, building identity integration capabilities, applying Zero Trust principles, leading SAML to OIDC migration, documenting standards, and leading incident response. Requires 7+ years in identity/access management or security engineering, 3+ years hands-on OAuth/OIDC experience, expertise in OAuth 2.0/2.1, machine identity patterns, cloud-native identity platforms (AWS, GCP, Azure), identity logging and troubleshooting, leadership and mentoring skills. Benefits include flexible time off, paid holidays, sick time, parental leave, childcare assistance, health coverage, 401(k), tuition assistance, commuter benefits, professional development, and more.

What you'll do

  • Lead implementation and adoption of enterprise identity standards with an OIDC-first posture
  • Design and review secure token flows including authorization code with PKCE, client credentials, and delegated authorization patterns
  • Drive transition from long-lived service accounts and API keys to machine identities
  • Support identity integration patterns for AI-assisted and automated workloads
  • Build and maintain identity integration capabilities across authorization servers and API gateways
  • Apply Zero Trust principles and partner with Security on logging, SIEM integration, and compliance
  • Drive SAML to OIDC migration and legacy auth modernization
  • Create and maintain documented, reusable guides for OAuth applications and integrations
  • Lead and drive identity modernization initiatives, mentor architects and engineers
  • Improve identity observability and lead incident response for identity platform issues
  • Participate in on-call rotation and provide after-hours support

Requirements

  • 7+ years of experience in identity and access management, security engineering, or platform/integration roles
  • 3+ years hands-on with OAuth 2.0 / OpenID Connect in production environments
  • Practical expertise in OAuth 2.0 / 2.1 and OpenID Connect including authorization code + PKCE, client credentials, token refresh, and enterprise integration patterns
  • Understanding of ID token vs. access token separation, scope design, claims usage, token lifetime management, and security risks
  • Experience implementing machine identity (M2M) patterns and cloud workload identities
  • Experience modernizing identity integrations including SAML to OIDC migrations
  • Ability to design and deliver reliable identity integrations at scale
  • Leadership experience mentoring peers and delegating work
  • Working knowledge of cloud-native identity in at least one major platform (AWS, GCP, or Azure)
  • Experience with identity logging, troubleshooting, and operational support
  • Strong communication and influence skills
  • Experience in security-conscious or regulated environments
  • Self-directed with strong prioritization skills

Tech stack

OAuth 2.0OAuth 2.1OpenID ConnectPKCESAMLAPI gatewaysAPI managementAWSGCPAzureIAMSPIFFESPIREOPACedarOktaAzure AD / Entra IDAuth0PingPythonBash

Benefits

Flexible time off (FTO)15 paid holidaysPaid sick timeParental/new child leaveChildcare & elder care assistanceAdoption assistanceComprehensive health coverage401(k)Tuition assistanceCommuter benefitsProfessional developmentEmployee recognitionCharitable donation matchingHealth coaching and counseling

Apply now

Ready to take the next step in your career? Click the button below to continue to the application process.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.