Identity and Access Management Engineer (SSO and Auth0)

Job Category: Network & Security Job
Job Type: Remote

Job description

A leading organization is seeking an identity and access management engineer to design, implement, and maintain secure authentication and authorization solutions across cloud and enterprise applications. This role focuses on single sign-on integrations, identity provider configuration, and modern authentication protocols to ensure secure and seamless access for users and systems.

The engineer will work across application onboarding, identity platform configuration, and continuous improvement of access controls and security posture. This position requires deep experience with OAuth, OpenID Connect, and identity provider platforms, along with the ability to integrate authentication into backend services and enterprise environments.


Responsibilities

  • Design, implement, and maintain single sign-on integrations for SaaS and internal applications from initial setup through ongoing support
  • Configure and manage identity provider environments, including applications, APIs, connections, roles, permissions, and authentication flows
  • Implement and troubleshoot authentication protocols, including OAuth 2.0 and OpenID Connect flows for user and system-level access
  • Define and enforce secure token usage, including scopes, audiences, lifetimes, storage, and validation practices
  • Partner with application owners and security teams to onboard new applications to centralized authentication systems
  • Monitor authentication activity, investigate incidents, and strengthen identity and access management controls
  • Develop runbooks, implementation guides, and documentation for configuration, troubleshooting, and operational support
  • Support modernization of identity systems, including migration from legacy directory services and integration with identity governance tools

Required experience and skills

  • Strong understanding of identity and access management fundamentals, including authentication, authorization, role-based and attribute-based access control, and least-privilege principles
  • Deep knowledge of OAuth 2.0 and OpenID Connect, including authorization code flow with PKCE, client credentials, token lifecycles, scopes, and consent
  • Hands-on experience configuring identity providers, including application setup, API configuration, credential management, and authentication rules
  • Experience integrating single sign-on across SaaS platforms using OIDC or SAML, including metadata configuration and attribute mapping
  • Ability to implement and validate token-based authentication in backend systems using at least one programming language such as Python, Node.js, Java, or similar
  • Understanding of common authentication security risks and mitigation strategies, including token leakage, redirect vulnerabilities, and misconfigured scopes
  • Familiarity with secure API design, including authentication, encryption, retry handling, and idempotent operations
  • Experience managing identity configurations across multiple environments and supporting deployment automation where applicable
  • Strong troubleshooting skills and ability to monitor authentication systems using logs and observability tools
  • Effective communication skills with the ability to collaborate with technical teams and non-technical stakeholders
  • Strong documentation practices, including creation of clear technical guides and operational procedures

FAQ

1. What are the primary responsibilities of an Identity and Access Management (IAM) Engineer specializing in SSO and Auth0?
An Identity and Access Management Engineer designs, implements, and maintains secure authentication and authorization solutions for enterprise applications. The role focuses on enabling Single Sign-On (SSO), managing user identities, enforcing access policies, integrating identity providers, and protecting organizational resources through modern identity management practices.

2. What is Single Sign-On (SSO), and why is it important?
Single Sign-On (SSO) allows users to access multiple applications using a single set of credentials. It improves user convenience, strengthens security, reduces password fatigue, and simplifies identity management by centralizing authentication across enterprise systems.

3. How is Auth0 used in this role?
Auth0 is an identity platform used to implement authentication, authorization, and user identity management. IAM Engineers configure login flows, integrate applications with identity providers, enforce security policies, manage user directories, and support secure access for web, mobile, and enterprise applications.

4. How does this role contribute to enterprise security?
The engineer protects enterprise systems by implementing identity verification, role-based access controls, multi-factor authentication, secure session management, and least-privilege access principles. These measures reduce the risk of unauthorized access and strengthen the organization’s cybersecurity posture.

5. What authentication and authorization protocols are commonly used?
IAM Engineers commonly work with industry-standard protocols such as OAuth 2.0, OpenID Connect (OIDC), Security Assertion Markup Language (SAML), LDAP, and JSON Web Tokens (JWT). These standards enable secure identity federation and application integration across diverse environments.

6. What role does identity lifecycle management play in this position?
Identity lifecycle management involves provisioning new users, updating permissions, managing role changes, and securely removing access when users leave the organization. Automating these processes helps improve security, compliance, and operational efficiency.

This job is no longer accepting applications.