About The Position

The Principal Security Engineer is responsible for working with the infosec team to define and architect PROS' Customer Identity Management (CIAM) strategy and roadmap. This role will serve as the technical leader for customer authentication, authorization, identity lifecycle management, federation, and identity governance across all customer-facing products and platforms. The individual will establish the vision, architecture, standards, and operating model that enable secure, scalable, and frictionless customer access while supporting PROS' growth, multi-tenant cloud platform strategy, and evolving regulatory requirements. Success in this role will result in a unified customer identity platform across PROS products, simplified authentication and authorization experiences, improved customer onboarding and user administration capabilities, and consistent enforcement of access control policies. This leader will strengthen auditability and compliance readiness while building the identity foundation needed to support future AI agents, APIs, and partner integrations.

Requirements

  • 10+ years of security engineering or platform engineering experience.
  • 5+ years designing and implementing enterprise IAM or CIAM solutions.
  • Deep expertise with: OAuth 2.0, OpenID Connect, SAML, Identity Federation, MFA, RBAC / ABAC, Zero Trust architectures.
  • Experience with cloud-native platforms and SaaS architectures.
  • Experience integrating identity platforms such as Auth0, Okta, Entra ID, Ping Identity, ForgeRock, or similar technologies.
  • Strong understanding of security architecture, threat modeling, and secure software development practices.
  • Excellent communication skills and ability to influence architecture decisions across engineering organizations.

Nice To Haves

  • Bachelor’s Degree in Computer Science, Engineering, Cybersecurity, or a related field.
  • Understand core AI concepts and apply them ethically to enhance productivity, insights, and decision-making.
  • Craft effective prompts to optimize the quality and relevance of AI-generated outputs.
  • Explore and apply agentic AI systems, using or managing autonomous agents to streamline workflows and automate tasks.
  • Leverage AI tools to boost efficiency, creativity, and innovation in their daily work.
  • Stay curious and adaptable, continuously experimenting with AI-driven solutions to elevate team performance and customer impact.

Responsibilities

  • Define and own the long-term Customer Identity Management strategy and architecture.
  • Lead the design and implementation of customer authentication and authorization services across the PROS platform.
  • Establish standards for: Single Sign-On (SSO), Multi-Factor Authentication (MFA), Identity Federation (SAML, OIDC, OAuth 2.0), Role-Based and Attribute-Based Access Control, Customer Identity Lifecycle Management.
  • Develop a unified identity architecture supporting multiple products, tenants, and customer organizations.
  • Serve as the technical lead for CIAM platform selection, integration, deployment, and operational governance.
  • Partner with product and engineering leaders to incorporate identity capabilities into new platform and product initiatives.
  • Establish security controls, monitoring, logging, and audit capabilities for identity-related services.
  • Lead threat modeling, risk assessments, and security reviews focused on identity and access management.
  • Define identity governance policies and ensure alignment with regulatory and customer security requirements.
  • Drive adoption of industry best practices and zero-trust security principles across customer-facing systems.
  • Work closely with Security Operations, Product Security, Platform Engineering, Compliance, and Customer Success teams to continuously improve the identity ecosystem.
  • Mentor engineers and architects and act as the organization's subject matter expert for identity and access management.

Benefits

  • flexible ways of working
  • continuous learning
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service