We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.
Position Overview
Our organization is modernizing customer identity and access management to support secure, seamless authentication across all digital channels. We are seeking a Staff IAM Engineer to serve as the technical lead for our Customer Identity and Access Management (CIAM) platform team in Hyderabad, India. You will design and implement customer identity solutions using the Ping x ForgeRock Identity Platform, while balancing hands-on technical execution with team-level leadership. You'll guide daily design decisions, sprint delivery, and technical quality standards—ensuring our CIAM capabilities are secure, scalable, and deliver measurable business value across web, mobile, and API channels. This role is critical to enabling frictionless customer experiences while maintaining enterprise-grade security and compliance.
Key Responsibilities
You'll design and evolve CIAM patterns—updating existing ones to meet business objectives and building new ones that strengthen security or drive value—while reviewing code, guiding sprint cadence, unblocking your team, and making daily decisions that keep momentum.
TECHNICAL LEADERSHIP & TEAM GUIDANCE
Own CIAM design and implementation decisions for the team, guiding user story creation and refinement to ensure technical clarity and feasibility.
Help refine features into well-defined user stories and technical spikes; ensure stories are sized and scoped appropriately for team velocity and sprint capacity.
Guide sprint planning and backlog refinement, leading technical trade-off discussions that balance security, performance, and delivery timelines.
Write and review policy scripts, API integration code, and orchestration logic to implement identity flows and custom abstractions.
Provide hands-on code and configuration reviews, ensuring delivery aligns with definition of done, security standards, and engineering best practices.
CIAM PLATFORM DESIGN & IMPLEMENTATION
Design and implement CIAM capabilities using Ping x ForgeRock products, including authentication flows (OAuth 2.0, OIDC, SAML), MFA, password less authentication, adaptive/risk-based authentication, identity federation, and user journey orchestration.
Configure and customize identity flows using Ping policies, orchestration rules, policy scripts, and SDKs to meet functional requirements.
Design, develop, and own a custom abstraction layer that simplifies Ping Identity integration, enabling application teams to implement secure identity patterns without deep platform expertise.
Own end-to-end integrations with web/mobile applications, backend APIs, and API gateways.
Evolve existing patterns to meet changing objectives.
SECURITY & COMPLIANCE
Embed security by design in all CIAM implementations; partner with security teams on threat modeling, design reviews, fraud detection, and anomaly detection strategies.
Own non-functional requirements including performance targets, system resiliency, and availability SLAs.
DEVOPS, RELIABILITY & INCIDENT RESPONSE
Implement and maintain CI/CD pipelines for CIAM configuration and code using GitHub Actions, Jenkins, or similar tools.
Promote configuration-as-code and Infrastructure-as-Code (IaC) practices across CIAM delivery.
Support automated testing, logging, monitoring, and alerting for identity services to enable rapid incident detection.
Troubleshoot production issues and lead incident resolution in collaboration with SRE and platform teams, working toward rapid response times.
MENTORING, EXPERTISE & STRATEGIC ALIGNMENT
Mentor CIAM engineers and application developers on identity patterns, security best practices, and Ping platform capabilities through code reviews, pair sessions, and knowledge-sharing.
Serve as the CIAM technical authority for the Agile team, making feature/integration-level design decisions that unblock team members and keep momentum.
Create and maintain CIAM architecture documentation, integration guides, and decision records to support team knowledge and onboarding.
Collaborate with enterprise architects and product teams to align team-level CIAM solutions with broader organizational strategy and roadmaps.
Coordinate with Ping Identity vendor teams for platform guidance, technical support, and issue escalation as needed.
Required Qualifications
CORE IAM & CIAM EXPERTISE
7–10+ years of professional experience in identity and access management (IAM), with a strong focus on Customer IAM (CIAM) design and implementation.
Hands-on experience with Ping Identity PingOne, ForgeRock, or similar IAM/CIAM platforms designing, configuring, and deploying CIAM solutions in production.
Deep knowledge of authentication and authorization standards: OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and REST API security patterns.
Proficiency in MFA, passwordless authentication strategies, identity federation, and risk-based authentication policies.
Experience deploying and managing CIAM solutions in cloud environments (AWS or GCP).
PLATFORM & ABSTRACTION LAYER DEVELOPMENT
Proven experience designing and maintaining custom integration layers (SDKs, abstraction layers, or API wrappers) that simplify platform integration for downstream consumers.
Hands-on development and scripting proficiency in JavaScript, Java, Groovy, Python, or similar languages.
DEVOPS, SECURITY & RELIABILITY
Experience designing and maintaining CI/CD pipelines using modern tools (GitHub Actions, Jenkins, or equivalent).
Familiarity with configuration-as-code and Infrastructure-as-Code (IaC) practices for identity platforms.
Strong understanding of application security principles, authentication/authorization threat models, and secure coding practices.
TEAM LEADERSHIP & COMMUNICATION
Proven experience working as a Senior or Lead Engineer, balancing hands-on technical execution with team leadership, mentoring, and technical decision-making in Agile environments.
Excellent communication and stakeholder management skills with Product Owners, Security teams, Enterprise Architects, and Engineering partners.
Demonstrated ability to lead technical discussions, resolve design trade-offs, and influence technical decisions across teams.
Preferred Qualifications
Experience migrating identity solutions from on-premises IAM platforms to cloud-based SaaS CIAM platforms.
Hands-on experience with ForgeRock Identity Cloud or other SaaS IAM platforms.
Experience designing and supporting mobile identity use cases (native apps, token lifecycle management, device trust).
Familiarity with API gateways, Web Application Firewalls (WAFs), and fraud detection/anomaly detection tools.
Relevant certifications: Ping Identity, ForgeRock, Cloud (AWS/GCP), or Information Security certifications.
Experience coordinating with IAM vendor teams for technical support, platform guidance, and strategic alignment.
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together.
Applicants
are
advised to research the bonafides of the prospective employer independently. We do NOT
endorse any
requests for money payments and strictly advice against sharing personal or bank related
information. We
also recommend you visit Security Advice for more information. If you suspect any fraud
or
malpractice,
email us at abuse@talentmate.com.
You have successfully saved for this job. Please check
saved
jobs
list
Applied
You have successfully applied for this job. Please check
applied
jobs list
Do you want to share the
link?
Please click any of the below options to share the job
details.
Report this job
Success
Successfully updated
Success
Successfully updated
Thank you
Reported Successfully.
Copied
This job link has been copied to clipboard!
Apply Job
Your application for Staff Engineer - Infrastructure
has been successfully submitted!
To increase your chances of getting shortlisted, we recommend completing your profile.
Employers prioritize candidates with full profiles, and a completed profile could set you apart in the
selection process.
Why complete your profile?
Higher Visibility: Complete profiles are more likely to be viewed by employers.
Better Match: Showcase your skills and experience to improve your fit.
Stand Out: Highlight your full potential to make a stronger impression.
Complete your profile now to give your application the best chance!