- Design, develop, and maintain capabilities on the Unified Authentication Platform.
- Integrate enterprise IAM solutions such as Ping Identity, IBM Security Verify Access (ISAM), or similar authentication platforms.
- Develop and implement Passkey (FIDO2/WebAuthn) authentication and associated backend services.
- Build and integrate Multi-Factor Authentication (MFA) capabilities, including adaptive authentication workflows.
- Develop secure REST APIs and integrate authentication services with enterprise applications. Implement and manage OAuth 2.0/OIDC token lifecycle, including token issuance, validation, refresh, and revocation.
- Integrate with enterprise security services, directories, and legacy authentication platforms such as IBM ISAM. Apply secure coding practices and security engineering principles to authentication and authorization services.
- Collaborate with architecture, application, and DevSecOps teams to deliver secure, scalable identity solutions.
Requirements
- Strong experience in Java/Spring Boot (or equivalent backend technologies).
- Experience with Ping Identity, PingFederate, PingOne, IBM ISAM/ISVA, or similar IAM platforms.
- Hands-on experience with OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and token management.
- Experience implementing Passkeys (FIDO2/WebAuthn)
and Multi-Factor Authentication (MFA).
- Strong knowledge of RESTful APIs, API security, and authentication patterns.
- Experience integrating enterprise directories (LDAP/Active Directory) and identity services.
- Valuable understanding of Zero Trust security principles and modern authentication architectures.
Core Competencies
Demonstrates expertise in designing and implementing secure authentication solutions, including Multi-Factor Authentication (MFA) and Passkey (FIDO2/WebAuthn) integration. Proficient in developing REST APIs and managing OAuth 2.0/OIDC token lifecycles while applying secure coding practices.