Senior Identity & Access Management (CIAM) Engineer

PepsiCoPlano, TX
$80,200 - $134,250Onsite

About The Position

The Identity Access Management (IAM) Engineer will serve as a hands-on technical resource with strong Customer Identity and Access Management (CIAM) expertise, responsible for implementing, supporting, and improving secure identity solutions for B2B, B2C, and external user populations. This role requires solid technical experience in CIAM platforms such as Okta Customer Identity Cloud/Auth0, Okta, Ping, or ForgeRock, with strong hands-on knowledge of OAuth 2.0, OpenID Connect, SAML, JWT, SCIM, API integrations, MFA, passwordless, adaptive authentication, and customer identity lifecycle flows. The engineer will work on CIAM implementation activities from requirements through production support, including platform configuration, application integration, testing, troubleshooting, documentation, and operational handoff. The successful candidate should be able to operate independently on technical tasks, support CIAM design discussions, strengthen security controls, and help onboard digital applications while maintaining good user experience and compliance alignment. Must have strong hands-on configuration, scripting, API integration, troubleshooting, and support experience in CIAM or access management environments. This role is based out of Plano, Texas and requires coming into the office.

Requirements

  • 8+ years of overall IT experience with hands-on engineering or support background.
  • 6+ years of IAM, access management, authentication, federation, or identity engineering experience.
  • 4+ years of hands-on CIAM implementation or support experience for B2B, B2C, external customer, partner, or digital identity use cases.
  • Hands-on experience with Okta Customer Identity Cloud/Auth0, Okta, Ping, ForgeRock, or comparable CIAM platform.
  • Strong working knowledge of OAuth 2.0, OpenID Connect, SAML 2.0, JWT, SCIM, LDAP, REST APIs, SDKs, webhooks, and API security.
  • Hands-on experience configuring CIAM applications, connections, identity providers, login/sign-up flows, redirect URIs, callback URLs, logout URLs, custom domains, and branding.
  • Good understanding of OAuth/OIDC flows including Authorization Code with PKCE, Client Credentials, refresh tokens, scopes, claims, audiences, issuers, token validation, and token lifetime management.
  • Experience integrating CIAM with single-page applications, mobile apps, backend APIs, portals, and partner-facing applications using vendor SDKs, REST APIs, and modern web frameworks.
  • Experience configuring or supporting MFA, passwordless authentication, social login, enterprise federation, user registration, account recovery, profile management, and consent capture.
  • Hands-on experience with custom claims, rules/actions/hooks, API permissions, RBAC, groups/roles, attribute mapping, and user metadata/profile attribute management.
  • Experience troubleshooting CIAM issues related to redirects, SSO sessions, token errors, certificate/metadata mismatches, CORS, API authorization failures, login failures, and user provisioning issues.
  • Understanding of CIAM security controls such as adaptive MFA, bot/credential attack protection, breached password detection, rate limits, tenant logs, suspicious activity monitoring, and audit logging.
  • Hands-on scripting or development experience using Java, JavaScript, Node.js, React, Spring Boot, Python, PowerShell, or similar technologies.
  • Experience with CI/CD, DevSecOps, Git, Terraform, Ansible, Jenkins, GitHub Actions, Azure DevOps, or comparable automation tools.
  • Experience supporting production IAM or CIAM platforms, including monitoring, logging, incident support, root cause analysis, and performance troubleshooting.
  • BS/BA degree in Computer Science, Information Security, Engineering, or equivalent work experience.
  • Okta Certified Administrator preferred; Okta Certified Consultant, Okta Certified Developer, Auth0/Okta Customer Identity Cloud certification, or Ping/ForgeRock certification is a plus.
  • CISSP, CIAM, CISM, or comparable security certification is a plus.

Nice To Haves

  • Experience implementing enterprise CIAM solutions at scale.
  • Hands-on experience with Okta Customer Identity Cloud/Auth0 capabilities such as Actions, Rules, Hooks, Organizations, Management API, attack protection, log streaming, and custom domains.
  • Experience with Okta Identity Engine, Universal Directory, Lifecycle Management, Workflows, Administrative APIs, and application integration patterns.
  • Exposure to Ping, ForgeRock, SiteMinder, Azure AD/Entra ID, AWS Cognito, or other identity platforms is preferred.
  • Ability to support secure B2B and B2C identity models for large-volume customer environments, including retail, eCommerce, mobile, portal, or partner ecosystems.
  • Good understanding of authentication and authorization patterns including SSO, federation, token exchange, refresh tokens, session management, scopes, claims, consent, and delegated authorization.
  • Understanding of API gateways, microservices, REST integration, reverse proxies, load balancers, headers-based authentication, and secure API access patterns.
  • Experience integrating CIAM with web applications, mobile applications, CRM, Salesforce, SAP, eCommerce platforms, directories, data platforms, or downstream business systems.
  • Awareness of privacy and security requirements such as GDPR, CCPA, consent capture, data minimization, audit logging, and customer data protection.
  • Experience with security controls such as risk-based authentication, adaptive MFA, bot mitigation, credential attack protection, suspicious activity detection, and passwordless authentication.
  • Hands-on experience with Java, Node.js, JavaScript, React, Spring Boot, Python, PowerShell, SQL, and REST API development.
  • Experience deploying or supporting identity solutions in AWS, Azure, or hybrid environments.
  • Exposure to Docker, Kubernetes, Linux, Windows, middleware, Apache, and enterprise infrastructure components.
  • Experience with Splunk, ELK, Prometheus, native CIAM logs, SIEM integrations, or operational dashboards.
  • Experience creating reusable integration patterns, runbooks, standards, and technical documentation.
  • Experience supporting application migrations from legacy IAM platforms to modern CIAM capabilities.
  • Ability to troubleshoot complex issues while continuing to build deeper SME-level expertise.
  • Strong communication skills with the ability to explain CIAM concepts to technical teams, application owners, and security partners.
  • Self-starter who can analyze requirements, identify risks, propose solutions, and complete technical tasks with limited guidance.
  • Strong analytical and problem-solving skills, especially during integration troubleshooting and production support.
  • Ability to balance security, user experience, scalability, performance, compliance, and delivery timelines.
  • Ability to work across global teams, vendors, cybersecurity, architecture, product, and application teams.
  • Good documentation discipline, including integration guides, runbooks, standards, and operational handoff materials.
  • Flexible and able to adapt to changing priorities in a fast-paced enterprise environment.

Responsibilities

  • Serve as a hands-on CIAM technical resource for implementation, configuration, integration, and production support.
  • Configure and support CIAM solutions using Okta Customer Identity Cloud/Auth0, Okta, Ping, ForgeRock, or comparable platforms.
  • Build and support customer identity flows including registration, login, MFA, passwordless authentication, social login, consent, profile management, account recovery, and progressive profiling.
  • Support secure application integrations using OAuth 2.0, OpenID Connect, SAML, JWT, SCIM, REST APIs, SDKs, webhooks, and token-based authorization patterns.
  • Implement B2B and B2C identity patterns for web, mobile, portal, API, eCommerce, and partner-facing applications.
  • Configure platform capabilities such as Auth0 Actions, Rules, Hooks, Organizations, Management APIs, Okta Workflows, Identity Engine, Universal Directory, and Lifecycle Management.
  • Develop scripts, workflows, and automation to support identity lifecycle, application onboarding, monitoring, reporting, and operational efficiency.
  • Work with Cybersecurity, API, architecture, digital product, and application teams to support secure authentication and authorization patterns.
  • Participate in CIAM roadmap delivery, platform modernization, migrations, and capability enhancements.
  • Troubleshoot authentication, federation, token, consent, profile, directory, API, latency, and production availability issues.
  • Support monitoring, alerting, logging, audit, and reporting using tools such as Splunk, ELK, Prometheus, or native platform logs.
  • Implement security controls such as adaptive authentication, attack protection, bot protection, risk-based access, identity proofing integrations, and zero trust-aligned policies.
  • Support privacy, regulatory, audit, and compliance requirements related to customer identity, consent, data protection, and access governance.
  • Use DevSecOps practices, CI/CD pipelines, Git-based configuration management, Terraform, Ansible, or similar tools to improve repeatability and reduce manual changes.
  • Create and maintain integration patterns, technical design documents, runbooks, standards, and operational handoff materials.
  • Provide Level 2/Level 3 support, incident support, root cause analysis, and improvement recommendations for CIAM services.
  • Share technical knowledge with team members and contribute to Agile DevOps delivery practices.

Benefits

  • Paid parental leave
  • Vacation
  • Sick
  • Bereavement
  • Medical
  • Dental
  • Vision
  • Disability
  • Health
  • Dependent Care Reimbursement Accounts
  • Employee Assistance Program (EAP)
  • Accident Insurance
  • Group Legal Insurance
  • Life Insurance
  • Defined Contribution Retirement Plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service