Full job description
Lead Epsilon's identity modernization program by migrating from legacy SAML and long-lived credentials to OAuth 2.1 / OpenID Connect standards. Design secure token flows, machine identity patterns, and integration standards across multi-cloud environments. Partner with Security, Cloud Engineering, Platform, Application, and Data teams to migrate service accounts and API keys to scoped, ephemeral machine identities. Implement authorization server integrations, token scopes, claims usage, and risk reduction strategies. Lead identity observability and governance improvements. Mentor architects and engineers, delegate work, and unblock complex integrations. Responsibilities include driving OAuth/OIDC adoption, designing secure token flows, transitioning to machine identities, supporting AI-assisted authentication, building identity integration capabilities, applying Zero Trust principles, leading SAML to OIDC migration, documenting standards, and leading incident response. Requires 7+ years in identity/access management or security engineering, 3+ years hands-on OAuth/OIDC experience, expertise in OAuth 2.0/2.1, machine identity patterns, cloud-native identity platforms (AWS, GCP, Azure), identity logging and troubleshooting, leadership and mentoring skills. Benefits include flexible time off, paid holidays, sick time, parental leave, childcare assistance, health coverage, 401(k), tuition assistance, commuter benefits, professional development, and more.
What you'll do
- Lead implementation and adoption of enterprise identity standards with an OIDC-first posture
- Design and review secure token flows including authorization code with PKCE, client credentials, and delegated authorization patterns
- Drive transition from long-lived service accounts and API keys to machine identities
- Support identity integration patterns for AI-assisted and automated workloads
- Build and maintain identity integration capabilities across authorization servers and API gateways
- Apply Zero Trust principles and partner with Security on logging, SIEM integration, and compliance
- Drive SAML to OIDC migration and legacy auth modernization
- Create and maintain documented, reusable guides for OAuth applications and integrations
- Lead and drive identity modernization initiatives, mentor architects and engineers
- Improve identity observability and lead incident response for identity platform issues
- Participate in on-call rotation and provide after-hours support
Requirements
- 7+ years of experience in identity and access management, security engineering, or platform/integration roles
- 3+ years hands-on with OAuth 2.0 / OpenID Connect in production environments
- Practical expertise in OAuth 2.0 / 2.1 and OpenID Connect including authorization code + PKCE, client credentials, token refresh, and enterprise integration patterns
- Understanding of ID token vs. access token separation, scope design, claims usage, token lifetime management, and security risks
- Experience implementing machine identity (M2M) patterns and cloud workload identities
- Experience modernizing identity integrations including SAML to OIDC migrations
- Ability to design and deliver reliable identity integrations at scale
- Leadership experience mentoring peers and delegating work
- Working knowledge of cloud-native identity in at least one major platform (AWS, GCP, or Azure)
- Experience with identity logging, troubleshooting, and operational support
- Strong communication and influence skills
- Experience in security-conscious or regulated environments
- Self-directed with strong prioritization skills
Tech stack
OAuth 2.0OAuth 2.1OpenID ConnectPKCESAMLAPI gatewaysAPI managementAWSGCPAzureIAMSPIFFESPIREOPACedarOktaAzure AD / Entra IDAuth0PingPythonBash
Benefits
Flexible time off (FTO)15 paid holidaysPaid sick timeParental/new child leaveChildcare & elder care assistanceAdoption assistanceComprehensive health coverage401(k)Tuition assistanceCommuter benefitsProfessional developmentEmployee recognitionCharitable donation matchingHealth coaching and counseling