×
Register Here to Apply for Jobs or Post Jobs. X

Principal, Identity Architect

Job in Irving, Dallas County, Texas, 75084, USA
Listing for: Publicis Groupe
Full Time position
Listed on 2026-07-17
Job specializations:
  • Software Development
    Software Architect, DevOps, Backend Developer
Salary/Wage Range or Industry Benchmark: 127900 - 237500 USD Yearly USD 127900.00 237500.00 YEAR
Job Description & How to Apply Below

Overview

As a Principal Identity Architect, you will lead Epsilon’s identity modernization—transitioning from legacy SAML and long‑lived credentials to a modern, OAuth 2.1 / OpenID Connect (OIDC)-first model. You’ll design secure, scalable identity patterns across multi‑cloud environments while enabling teams to build with speed and confidence.

You’ll partner closely with Security, Cloud, Platform, and Engineering teams to replace API keys and service accounts with scoped, temporary machine identities, establish enterprise standards, and deliver secure, developer‑friendly integrations.

This is a hands‑on leadership role for someone who can drive strategy, mentor engineers, and turn architecture into real‑world implementations.

Responsibilities

What You’ll Achieve

Modern Identity Architecture

  • Lead adoption of OAuth 2.1 / OIDC; drive migration from SAML and legacy auth
  • Design secure token flows (Auth Code + PKCE, Client Credentials, delegated access)
  • Define standards for token usage, scopes, claims, and lifecycle management
  • Reduce risk from token leakage, replay, and over‑permissioning

Machine & Non‑Human Identity

  • Replace long‑lived credentials with modern machine identity patterns
  • Design M2M authentication for APIs, data pipelines, and platform workloads
  • Partner with teams on service account migration and secrets reduction

Platform & Integration Engineering

  • Build reusable identity patterns across IdPs, API gateways, and cloud platforms
  • Enable secure, scalable access across AWS, Azure, and/or GCP
  • Troubleshoot complex auth issues in hybrid and multi‑cloud environments

Security, Governance & Observability

  • Apply Zero Trust principles (least privilege, scoped access)
  • Improve identity logging, monitoring, and audit readiness
  • Establish governance for OAuth apps, scopes, and access policies

Leadership & Delivery

  • Drive identity modernization programs end‑to‑end
  • Mentor architects and engineers; set technical standards
  • Break down complex initiatives into actionable work streams
  • Lead incident response and improve operational visibility
Qualifications

Who you Are

What you’ll Bring with you

  • 7+ years in IAM, security engineering, or platform roles
  • 3+ years hands‑on with OAuth 2.0 / OIDC in production
  • Strong expertise in token flows, scopes, claims, and secure design patterns
  • Experience implementing machine identity (M2M, workload identity, etc.)
  • Track record of modernizing identity (SAML → OIDC or similar)
  • Experience with AWS, Azure, or GCP identity services
  • Ability to lead initiatives, influence teams, and deliver at scale

How you’ll Stand out from other Talent

  • Experience with API security, data platforms, or service‑to‑service auth at scale
  • Familiarity with SPIFFE/SPIRE, OPA, or advanced authorization models
  • Experience with Okta, Entra  (Azure AD), Auth0, or Ping
  • Exposure to AI/agent‑based identity patterns
  • Scripting or automation (Python, Bash)
Benefits
  • Time to Recharge:
    Flexible time off (FTO), 15 paid holidays
  • Time to Recover:
    Paid sick time
  • Family Well‑Being:
    Parental/new child leave, childcare & elder care assistance, adoption assistance
  • Extra Perks:
    Comprehensive health coverage, 401(k), tuition assistance, commuter benefits, professional development, employee recognition, charitable donation matching, health coaching and counseling
Equal Opportunity & Legal Notice

Epsilon is an Equal Opportunity Employer. Epsilon’s policy is not to discriminate against any applicant or employee based on actual or perceived race, age, sex or gender (including pregnancy), marital status, national origin, ancestry, citizenship status, mental or physical disability, religion, creed, color, sexual orientation, gender identity or expression (including transgender status), veteran status, genetic information, or any other characteristic protected by applicable federal, state or local law.

Epsilon also prohibits harassment of applicants and employees based on any of these protected categories. Epsilon will provide accommodations to applicants needing accommodations to complete the application process. Please reach out to  to request an accommodation.

For San Francisco Bay and Los Angeles Areas:
Epsilon will consider for employment qualified applicants with criminal…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary