Director, Identity Architecture
Listed on 2026-07-18
-
Software Development
Backend Developer, Software Architect, DevOps
Job Description
As a Principal Identity Architect, you will lead Epsilon’s identity modernization—transitioning from legacy SAML and long-lived credentials to a modern, OAuth 2.1 / OpenID Connect (OIDC)-first model. You’ll design secure, scalable identity patterns across multi-cloud environments while enabling teams to build with speed and confidence.
You’ll partner closely with Security, Cloud, Platform, and Engineering teams to replace API keys and service accounts with scoped, ephemeral machine identities, establish enterprise standards, and deliver secure, developer-friendly integrations.
This is a hands‑on leadership role for someone who can drive strategy, mentor engineers, and turn architecture into real‑world implementations.
ResponsibilitiesWhat You’ll Achieve
Modern Identity Architecture
- Lead adoption of OAuth 2.1 / OIDC; drive migration from SAML and legacy auth
- Design secure token flows (Auth Code + PKCE, Client Credentials, delegated access)
- Define standards for token usage, scopes, claims, and lifecycle management
- Reduce risk from token leakage, replay, and over‑permissioning
Machine & Non-Human Identity
- Replace long‑lived credentials with modern machine identity patterns
- Design M2M authentication for APIs, data pipelines, and platform workloads
- Partner with teams on service account migration and secrets reduction
Platform & Integration Engineering
- Build reusable identity patterns across IdPs, API gateways, and cloud platforms
- Enable secure, scalable access across AWS, Azure, and/or GCP
- Troubleshoot complex auth issues in hybrid and multi‑cloud environments
Security, Governance & Observability
- Apply Zero Trust principles (least privilege, scoped access)
- Improve identity logging, monitoring, and audit readiness
- Establish governance for OAuth apps, scopes, and access policies
Leadership & Delivery
- Drive identity modernization programs end‑to‑end
- Mentor architects and engineers; set technical standards
- Break down complex initiatives into actionable work streams
- Lead incident response and improve operational visibility
Who you Are
What you’ll Bring with you
- 7+ years in IAM, security engineering, or platform roles
- 3+ years hands‑on with OAuth 2.0 / OIDC in production
- Strong expertise in token flows, scopes, claims, and secure design patterns
- Experience implementing machine identity (M2M, workload identity, etc.)
- Track record of modernizing identity (SAML → OIDC or similar)
- Experience with AWS, Azure, or GCP identity services
- Ability to lead initiatives, influence teams, and deliver at scale
How you’ll Stand out from other Talent
- Experience with API security, data platforms, or service‑to‑service auth at scale
- Familiarity with SPIFFE/SPIRE, OPA, or advanced authorization models
- Experience with Okta, Entra (Azure AD), Auth0, or Ping
- Exposure to AI/agent‑based identity patterns
- Scripting or automation (Python, Bash)
Because You Matter
As an Epsilon employee, you deserve perks and benefits that put you, your family and your finances first. Our benefits encompass a wide range of offerings, including but not limited to the following:
- Time to Recharge:
Flexible time off (FTO), 15 paid holidays - Time to Recover:
Paid sick time - Family Well-Being:
Parental/new child leave, childcare & elder care assistance, adoption assistance - Extra Perks:
Comprehensive health coverage, 401(k), tuition assistance, commuter benefits, professional development, employee recognition, charitable donation matching, health coaching and counseling
Epsilon benefits are subject to eligibility requirements and other terms.
CompensationCompensation Range: USD $ - USD $/Annually. This is the pay range the Company believes it will pay for this position at the time of this posting. Consistent with applicable law, compensation will be determined based on the skills, qualifications, and experience of the applicant along with the requirements of the position, and the Company reserves the right to modify this pay range at any time.
EqualOpportunity
Epsilon is an Equal Opportunity Employer. Epsilon’s policy is not to discriminate against any applicant or employee based on actual or perceived race, age, sex or gender (including pregnancy), marital status, national origin, ancestry, citizenship status, mental or physical disability, religion, creed, color, sexual orientation, gender identity or expression (including transgender status), veteran status, genetic information, or any other characteristic protected by applicable federal, state or local law.
Epsilon also prohibits harassment of applicants and employees based on any of these protected categories. Epsilon will provide accommodations to applicants needing accommodations to complete the application process. Please reach out to to request an accommodation.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).