Identity Providers, SAML/OIDC federation, SSO onboarding intake and engineering * Strong Authentication & MFA: MFA systems, FIDO2, MFA compliance reporting and exception management * Passwordless ...
Identity Providers, SAML/OIDC federation, SSO onboarding intake and engineering * Strong Authentication & MFA: MFA systems, FIDO2, MFA compliance reporting and exception management * Passwordless ...
Senior Authentication, SSO/MFA & CIAM SME Lead
Plano, TX · On-site
$110K - $185K/yr
Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns. * Define MFA and adaptive ...
Senior Authentication, SSO/MFA & CIAM SME Lead
Plano, TX · On-site
$110K - $185K/yr
Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns. * Define MFA and adaptive ...
Senior Authentication, SSO/MFA & CIAM SME Lead
Plano, TX · On-site
$110K - $170K/yr
Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns. * Define MFA and adaptive ...
Senior Authentication, SSO/MFA & CIAM SME Lead
Plano, TX · On-site
$110K - $170K/yr
Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns. * Define MFA and adaptive ...
Identity Providers, SAML/OIDC federation, SSO onboarding intake and engineering * Strong Authentication & MFA: MFA systems, FIDO2, MFA compliance reporting and exception management * Passwordless ...
Identity Providers, SAML/OIDC federation, SSO onboarding intake and engineering * Strong Authentication & MFA: MFA systems, FIDO2, MFA compliance reporting and exception management * Passwordless ...
Information Security Senior Engineer - Authentication
Dallas, TX · On-site
$105K - $143K/yr
Experience with OAuth2, OpenID Connect, SAML, SCIM and token-based authentication * Experience with PingOne DaVinci to design and build identity orchestration workflows that simplify and streamline ...
Information Security Senior Engineer - Authentication
Dallas, TX · On-site
$105K - $143K/yr
Experience with OAuth2, OpenID Connect, SAML, SCIM and token-based authentication * Experience with PingOne DaVinci to design and build identity orchestration workflows that simplify and streamline ...
Knowledge of authentication protocols such as SAML, OAuth2, OpenID Connect * Experience with hybrid identity solutions, B2B/B2C configurations, and directory synchronization * Familiarity with ...
Knowledge of authentication protocols such as SAML, OAuth2, OpenID Connect * Experience with hybrid identity solutions, B2B/B2C configurations, and directory synchronization * Familiarity with ...
Senior Authentication, SSO/MFA & CIAM SME Lead
$110K - $170K/yr
Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns. * Define MFA and adaptive ...
Senior Authentication, SSO/MFA & CIAM SME Lead
$110K - $170K/yr
Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns. * Define MFA and adaptive ...
Senior Authentication, SSO/MFA & CIAM SME Lead
$110K - $170K/yr
Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns. * Define MFA and adaptive ...
Senior Authentication, SSO/MFA & CIAM SME Lead
$110K - $170K/yr
Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns. * Define MFA and adaptive ...
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services
WV · On-site +1
$96K - $119K/yr
Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication. * Support onboarding and ...
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services
WV · On-site +1
$96K - $119K/yr
Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication. * Support onboarding and ...
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services
Fort George G Meade, MD · On-site
$118K - $147K/yr
Implement and troubleshoot authentication solutions using SAML, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication. * Collaborate in onboarding and integrating ...
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services
Fort George G Meade, MD · On-site
$118K - $147K/yr
Implement and troubleshoot authentication solutions using SAML, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication. * Collaborate in onboarding and integrating ...
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services
Fort George G Meade, MD · On-site
$118K - $147K/yr
Implement and troubleshoot authentication solutions using SAML, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication. * Collaborate in onboarding and integrating ...
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services
Fort George G Meade, MD · On-site
$118K - $147K/yr
Implement and troubleshoot authentication solutions using SAML, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication. * Collaborate in onboarding and integrating ...
Principal Authentication Engineer (IAM) - Vice President
New York, NY · Hybrid
$150K/yr
Own Enterprise Authentication & Federation: implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI (mTLS, cert lifecycle), API auth, and Unix/Linux authentication. Integrate and Customize ...
Principal Authentication Engineer (IAM) - Vice President
New York, NY · Hybrid
$150K/yr
Own Enterprise Authentication & Federation: implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI (mTLS, cert lifecycle), API auth, and Unix/Linux authentication. Integrate and Customize ...
Principal Authentication Engineer (IAM) - Vice President
New York, NY · Hybrid
$150K/yr
Own Enterprise Authentication & Federation : implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI (mTLS, cert lifecycle), API auth, and Unix/Linux authentication. * Integrate and ...
Principal Authentication Engineer (IAM) - Vice President
New York, NY · Hybrid
$150K/yr
Own Enterprise Authentication & Federation : implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI (mTLS, cert lifecycle), API auth, and Unix/Linux authentication. * Integrate and ...
Principal Authentication Engineer (IAM) - Vice President
New York, NY · On-site
$150K/yr
Own Enterprise Authentication & Federation : implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI (mTLS, cert lifecycle), API auth, and Unix/Linux authentication. * Integrate and ...
Principal Authentication Engineer (IAM) - Vice President
New York, NY · On-site
$150K/yr
Own Enterprise Authentication & Federation : implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI (mTLS, cert lifecycle), API auth, and Unix/Linux authentication. * Integrate and ...
Authentication Engineer (Entra / AD) - 3667093
New York, NY · On-site
$70 - $75/hr
Deep expertise in hybrid identity architecture including Entra Connect, Conditional Access, MFA, and authentication protocols (SAML, OAuth, OIDC) * Advanced PowerShell scripting and automation skills ...
Authentication Engineer (Entra / AD) - 3667093
New York, NY · On-site
$70 - $75/hr
Deep expertise in hybrid identity architecture including Entra Connect, Conditional Access, MFA, and authentication protocols (SAML, OAuth, OIDC) * Advanced PowerShell scripting and automation skills ...
Fullstack Architect
Brooklyn, NY · On-site
... SSO/SAML authentication in Django • Experience writing high-concurrency code, including database query optimization, caching strategies, and async task design. • Experience with end-to-end ...
Fullstack Architect
Brooklyn, NY · On-site
... SSO/SAML authentication in Django • Experience writing high-concurrency code, including database query optimization, caching strategies, and async task design. • Experience with end-to-end ...
OAuth 2.0, OpenID Connect, FIDO2/WebAuthn, SAML, TOTP. * Experience with API authentication patterns (API keys, OAuth client credentials, mTLS), and with authentication for AI agents, MCP servers, or ...
OAuth 2.0, OpenID Connect, FIDO2/WebAuthn, SAML, TOTP. * Experience with API authentication patterns (API keys, OAuth client credentials, mTLS), and with authentication for AI agents, MCP servers, or ...
Lead Engineer - Customer Identity & Authentication (Transmit Security & Apigee)
Atlanta, GA · On-site
Build authentication and registration journeys using Transmit Journey Orchestration ... Configure OIDC, OAuth 2.0, and SAML flows * Manage identity lifecycle: registration, login, step-up ...
Lead Engineer - Customer Identity & Authentication (Transmit Security & Apigee)
Atlanta, GA · On-site
Build authentication and registration journeys using Transmit Journey Orchestration ... Configure OIDC, OAuth 2.0, and SAML flows * Manage identity lifecycle: registration, login, step-up ...
GSFC - .Net Developer
Tucker, GA · On-site
$44/hr
NET Core, C#, Python development, OIDC & SAML authentication, REST APIs, relational databases, and frontend technologies, with a passion for building scalable and secure enterprise web applications.
Quick apply
GSFC - .Net Developer
Tucker, GA · On-site
$44/hr
NET Core, C#, Python development, OIDC & SAML authentication, REST APIs, relational databases, and frontend technologies, with a passion for building scalable and secure enterprise web applications.
Senior Software Engineer (RoR/Go), SSCS: Authentication
$125K - $165K/yr
Security Assertion Markup Language (SAML), Lightweight Directory Access Protocol (LDAP), OpenID ... Help migrate authentication and token management paths from the monolith into GATE while ...
Senior Software Engineer (RoR/Go), SSCS: Authentication
$125K - $165K/yr
Security Assertion Markup Language (SAML), Lightweight Directory Access Protocol (LDAP), OpenID ... Help migrate authentication and token management paths from the monolith into GATE while ...
Saml Authentication information
What cities are hiring for Saml Authentication jobs?
Cities with the most Saml Authentication job openings:
What states have the most Saml Authentication jobs?
States with the most job openings for Saml Authentication jobs include:
What job categories do people searching Saml Authentication jobs look for?
The top searched job categories for Saml Authentication jobs are:
What other helpful pages are available for Saml Authentication?
Other pages related to Saml Authentication:

Head of Workforce Authentication Services, MD
Boston, MA
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 27 days ago
Key responsibilities
Lead the strategic direction, engineering, operations, and compliance of all workforce authentication platforms at State Street.
Serve as the engineering owner for the Workforce Passwordless program, overseeing technical design, vendor assessments, and technology rollout.
Own the end-to-end remediation of audit, regulatory, and penetration-test findings affecting workforce authentication.
Job description
Who we are looking for
Global Cybersecurity (GCS) protects State Street and its clients from the impact of cyber-attacks against systems by understanding the risks these attacks present and mitigating them through a robust, continuously evolving cybersecurity program and control environment.
Reporting to the Head of Identity & Access Management, the Head of Workforce Authentication Services, MD will lead the strategic direction, engineering, operations and compliance posture of all workforce authentication platforms at State Street. This role consolidates capabilities currently distributed across two towers into a single, accountable engineering and operations leadership role.
Why this role is important to us
The successful candidate will also serve as the engineering leader for the Workforce Passwordless program, owning the end-to-end technical execution and the elimination of password-dependent authentication protocols across the enterprise.
What you will be responsible for
Scope of Platforms and Services
The role owns engineering, operations, resilience and compliance for the workforce authentication platform stack, including but not limited to:
Directory & Identity Plane: Active Directory (on-premises forests, domain controllers, Kerberos, Group Policy), Microsoft Entra ID, Entra Connect, Cloud Kerberos Trust, Conditional Access
Federation & SSO: Identity Providers, SAML/OIDC federation, SSO onboarding intake and engineering
Strong Authentication & MFA: MFA systems, FIDO2, MFA compliance reporting and exception management
Passwordless Program (Workforce): Engineering leadership across the full passwordless roadmap - vendor assessments, CA policy design, OS/endpoint integration and other touch points in the technology stack.
Resilience & Operations: 24x7 run of authentication services, DR/BCP, capacity, patching, DC exit programs, vulnerability and pen-test finding remediation across the authentication estate
Key Responsibilities
Strategic Leadership
Develop and execute a single, unified Workforce Authentication strategy that consolidates all authentication services into one engineering and operations function with one accountable leader.
Define the multi-year target architecture for authentication aligned to State Street's Technology and Security strategies
Partner with the Heads of CIAM, Privileged & Infrastructure Access, IGA, and IAM Oversight to ensure a coherent, end-to-end IAM operating model.
Engineering Leadership - Workforce Passwordless
Serve as the engineering owner of the Workforce Passwordless program, accountable for delivery against EC-committed milestones and the financial plan.
Lead the technical design and rollout of supporting technologies required to enable transition to passwordless authentication.
Drive vendor and product assessments and lead comparative POCs aligned to State Street use cases.
Standards, Compliance & Lines of Defence
Own the Authentication compliance with IAM Standard (Account Authentication, Password Parameters, MFA, Federation/SSO, Session Management) and ensure alignment to NIST SP 800-53, NIST SP 800-63B, DORA, BAIT, UK PRA SS1/21, MAS TRM, HKMA SPM and APRA CPS 234.
Support assurance compliance with the Second Line of Defence (Technology Risk Management), Third Line (Corporate Audit) and External Auditors (E&Y) - including evidence ownership, RCSA control mapping, and finding remediation.
Provide a support and data for compliance management across the workforce authentication environment: control design, control testing readiness, KRI/KPI reporting to the IAM Governance Council, Cybersecurity Risk Committee (CRC) and Technology Risk Committee (TRC).
Remediation & Audit/Pen-Test Findings
Own end-to-end remediation of all audit, regulatory and penetration-test findings affecting workforce authentication.
Resilience & Operations of Critical Systems
Accountable for the availability, performance and resilience of Tier-0 authentication services including DR posture, recovery testing, capacity management, and major-incident command for authentication outages.
Own the operational interface for Authentication Services with key partners including End User Computing, Platform Engineering, Production Management, Network and the regional IT heads.
People & Operating Model
Lead a globally distributed team across; evolve the operating model in line with the IAM portfolio management framework.
Drive talent strategy, succession, and a culture of engineering excellence, multi-disciplinary delivery and accountable ownership.
What we value
These skills will help you succeed in this role
15+ years in technology / engineering / security roles, with at least 8 years leading large-scale authentication engineering and operations functions ideally in a regulated financial services environment.
Deep, hands-on technical depth across Active Directory, Microsoft Entra ID, Kerberos, LDAP, SAML, OIDC, FIDO2/WebAuthn, MFA, and federation platforms.
Proven track record of regulator-facing and audit-facing accountability, with the ability to defend control design and enhancement plans to PRA, FCA, DORA, MAS, HKMA, APRA and internal/external audit.
Experience operating Tier-0 critical services with strict availability, DR and resilience SLAs.
Education & Preferred Qualifications
Experience consolidating previously siloed identity/authentication towers into a single accountable function.
Experience leading globally distributed teams across US, EMEA and India.
Bachelors Degree in Cyber Security or related technical discipline
Salary Range:
$170,000 - $282,500 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.
About State StreetAcross the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
About State Street Global Advisors
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
1,001 - 5,000 Employees
Headquarters location
Boston, MA, US
Year founded
1978