Federated Authentication Engineer - OESIS Framewor
Core
Design and implement OAuth2, OIDC, and SAML 2.0 authentication flows for third-party enterprise platforms and embedded SDKs.
Role type
Senior Identity and Access Engineering IC
Builds
Secure multi-tenant credential storage, token lifecycle management, and passthrough authentication architectures for OEM/SDK products.
Domain
Cybersecurity / Identity and Access Management (IAM)
Deliverable
production ML models | product features
Required skills
OAuth2, OIDC, SAML 2.0, SCIM, Microsoft Entra ID, Graph API, token lifecycle management, secrets management, mutual TLS, certificate-based authentication, API client setup, least-privilege scope design
Preferred skills
Passthrough/delegated authentication architectures, enterprise IAM tools (Okta, Ping Identity), ZTNA, device posture/compliance, CISSP, OSCP
Technologies
OAuth2, OIDC, SAML 2.0, Microsoft Entra ID, Graph API, CrowdStrike Falcon, JAMF Pro, secrets managers
Responsibilities
Design and implement OAuth2 and OIDC authentication flows for third-party enterprise platforms; Implement SAML 2.0 federation for enterprise SSO passthrough scenarios; Build secure multi-tenant credential and token storage with rotation using secrets managers; Define least-privilege scopes and support certificate-based authentication and mutual TLS; Support customer onboarding through app registration, consent, API client setup, and role or privilege configuration; Implement token refresh, expiry, revocation, and re-authentication logic for long-running query pipelines.
Seniority
Senior, hands-on IC