Corporate Vice President - Head of Authentication Engineering, Identity & Access Management

New York LifeNew York, NY
$147,500 - $211,000Hybrid

About The Position

Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes. Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era - all backed by the stability and purpose of a mutual company built to last. The Head of Authentication Engineering, Identity & Access Management is the senior, hands-on technical leader accountable for the strategy, architecture, engineering, and reliability of New York Life's enterprise authentication capabilities across workforce, application, API, cloud (AWS, Azure, and GCP), and emerging AI agent-based access patterns. This is a builder and technical authority role, not a purely advisory or governance position — you will define the target state, make difficult design decisions, and personally engage in the most complex authentication challenges. This is also a people leadership role: you will directly manage a team of authentication engineers, and are accountable for providing them with day to day guidance, technical oversight, and career development. This leader owns authentication as an end to end capability, including federation, SSO, MFA, passwordless and phishing-resistant authentication, adaptive and continuous authentication, session management, token services, API authorization, and authentication patterns for non human identities and AI enabled systems. User experience is treated as a core engineering outcome, not an afterthought, alongside strong identity assurance. You will need the technical depth to be credible with engineers and architects, and the executive presence to represent Cybersecurity in enterprise governance forums. As the direct manager of the authentication engineering team, you are responsible for staffing, workload allocation, performance management, and ensuring every team member receives the guidance and oversight needed to do their job well.

Requirements

  • Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or equivalent practical experience.
  • 12+ years of progressive experience in identity and access management, security engineering, or platform engineering, including significant leadership of enterprise authentication engineering.
  • 5+ years of experience as a direct people manager of engineers, with a demonstrated track record of hiring, coaching, performance management, and career development, and the ability to provide the guidance and oversight a technical team needs day to day.
  • Expert level knowledge of SAML 2.0, OAuth 2.0, OpenID Connect, federation, SSO, MFA, session security, and token lifecycle management.
  • Deep hands on experience with enterprise federation and access management platforms such as PingFederate, PingAccess, PingOne, or comparable technologies.
  • Demonstrated ability to design authentication journeys that are secure, low friction, and measurable, with a track record of using UX and telemetry data to drive improvement.
  • Proven experience delivering passwordless and phishing resistant authentication at enterprise scale (FIDO2, passkeys, Windows Hello for Business, HYPR, or equivalent).
  • Strong experience with API security and authorization, including gateways, token exchange, delegation, and fine grained authorization.
  • Practical experience with PKI, mTLS, certificate based authentication, and machine or workload authentication across cloud platforms (AWS, Azure, or GCP).
  • Ability to lead technical reviews, make high consequence design decisions, and communicate clearly with engineers, executives, governance bodies, and risk partners.

Nice To Haves

  • Experience modernizing authentication in a regulated financial services or similarly complex enterprise environment.
  • Experience integrating authentication with zero trust network access, cloud platforms (AWS, Azure, GCP), and enterprise device management.
  • Experience securing non human identities, AI agents, agent to agent interactions, delegated access, or MCP enabled systems.
  • Experience with workload identity standards such as SPIFFE/SPIRE and cloud native service identity.
  • Experience with policy as code and fine grained authorization approaches such as OPA, Cedar, ABAC, or relationship based access control.
  • Familiarity with leading edge and emerging web access management (WAM) protocols such as ID-JAG, Shared Signals Framework/CAEP, and Transaction Tokens, and the judgment to help set enterprise direction on their adoption.
  • Relevant certifications such as CISSP, CISM, CCSP, or a cloud security credential (AWS, Azure, or GCP).

Responsibilities

  • Own the enterprise authentication strategy, target architecture, roadmap, and standards across workforce, application, API, cloud (AWS, Azure, GCP), and hybrid environments.
  • Serve as the authoritative design leader for authentication, federation, authorization, session security, and identity assurance, and position the enterprise for passkeys, workload identity, agent identity, and continuous verification.
  • Lead the design and enterprise-scale delivery of phishing-resistant, passwordless authentication (FIDO2, passkeys) and adaptive, risk-based, and continuous authentication models.
  • Architect enterprise federation and SSO using SAML 2.0, OAuth 2.0, and OpenID Connect, and design secure API authorization patterns including token exchange, delegation, and fine grained authorization.
  • Help set NYL's direction on leading edge authentication and authorization protocols, including Identity Assertion Authorization Grant (ID-JAG), Shared Signals Framework/CAEP, and Transaction Tokens, and evaluate where they fit the enterprise roadmap.
  • Treat authentication user experience as a core engineering outcome own end to end journey mapping across devices, platforms, and recovery paths to reduce friction while maintaining strong identity assurance.
  • Apply PKI, mTLS, and certificate based authentication for human and machine access, including workload identity across cloud and hybrid platforms.
  • Own authentication patterns for non human identities and AI enabled systems, including AI agents, agent to agent interactions, and MCP enabled workflows.
  • Use telemetry and testing to identify friction and failure patterns across the authentication journey, and drive continuous, measurable UX improvement.
  • Own the reliability and operational health of authentication services, including availability, scalability, latency, and incident response.
  • Represent IAM and Cybersecurity in Security Review Board and Architecture Review Board forums, and lead technical reviews of authentication flows, cloud identity, and vendor solutions.
  • Serve as the direct people manager for a team of authentication engineers: own hiring, staffing, and workload distribution, conduct regular one on ones and performance reviews, set individual development plans, and provide the hands on technical guidance and day to day oversight needed to raise the team's technical bar.
  • Provide adequate guidance and oversight of the team's work at every stage — from design through delivery — including reviewing designs and code, unblocking engineers on complex problems, and ensuring work meets NYL's security, quality, and delivery standards before it ships.

Benefits

  • leave programs
  • adoption assistance
  • student loan repayment programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service