Senior Authentication, SSO/MFA & CIAM SME Lead
Job in
Plano, Collin County, Texas, 75024, USA
Listed on 2026-09-11
Listing for:
PepsiCo
Full Time
position Listed on 2026-09-11
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Job Description & How to Apply Below
The Authentication, SSO/MFA and CIAM SME/Architect will serve as a senior technical leader within the IAM organization, responsible for defining, architecting, designing, and delivering secure authentication and access management solutions across workforce, partner, and customer identity use cases.
This role requires deep hands-on expertise in modern authentication, SSO federation, MFA, passwordless authentication, CIAM, and identity security across hybrid on-premises and cloud environments. The candidate will partner with enterprise architects, cybersecurity, infrastructure, application, and business teams to deliver scalable solutions that improve security, reduce risk, support compliance, and enable business outcomes.
This role is based out of Plano, Texas and requires coming into the office.
Responsibilities
- Serve as the senior SME/Architect for Authentication, SSO, MFA, passwordless, federation, and CIAM capabilities across enterprise IAM platforms.
- Design and solution secure authentication patterns for cloud, SaaS, on-premises, mobile, API, B2B, workforce, and customer-facing applications.
- Lead technical architecture for SSO integrations using SAML, OAuth 2.0, OIDC, WS-Federation, header-based authentication, reverse proxy, and legacy application patterns.
- Define MFA and adaptive authentication strategies, including risk-based access, device trust, step-up authentication, passwordless, and phishing-resistant authentication options.
- Architect CIAM solutions supporting customer registration, login, profile management, consent, progressive profiling, social login, account recovery, and secure API access.
- Partner with application, cybersecurity, privacy, infrastructure, legal, and business teams to translate business requirements into secure, scalable IAM solutions.
- Assess current authentication implementations and recommend improvements aligned with security standards, regulatory requirements, zero trust principles, and enterprise architecture guidelines.
- Provide hands-on technical leadership for complex integrations, troubleshooting, root cause analysis, production support, and platform stability.
- Develop reusable architecture patterns, reference designs, integration standards, decision records, and implementation playbooks for authentication and CIAM capabilities.
- Drive platform modernization, automation, and roadmap execution for IAM authentication services, including Okta and related identity platforms.
- Support governance, risk reduction, audit readiness, and operational controls by ensuring authentication solutions meet security, compliance, logging, monitoring, and access policy requirements.
- Mentor engineers and delivery teams, provide technical reviews, and enable knowledge transfer across internal and external stakeholders.
- Champion Agile and Dev Ops practices, including automation, CI/CD, infrastructure as code, monitoring, and reliable change delivery.
- The expected compensation range for this position is between $110,700 - $170,250.
- Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
- Bonus based on performance and eligibility target payout is 12% of annual salary paid out annually.
- Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
- In addition to salary, Pepsi Co offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility:
Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Minimum Qualifications:
- 15+ years of overall IT experience, with significant experience in enterprise IAM, cybersecurity, architecture, or application security.
- 10+ years of hands-on experience architecting, designing, and delivering authentication, SSO, MFA, federation, and access management solutions.
- 7+ years of hands-on experience with Okta or comparable identity platforms such as Ping, Microsoft Entra , Forge Rock, Site Minder, or similar technologies.
- Strong working knowledge of SAML, OAuth 2.0, OIDC, JWT, SCIM, LDAP, Kerberos, API security, session management, token lifecycle, and modern authentication flows.
- Proven experience integrating SaaS, cloud, mobile, API, legacy, and on-premises…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×