As a Principal Identity Architect, you will lead Epsilon’s identity modernization—transitioning from legacy SAML and long-lived credentials to a modern, OAuth 2.1 / OpenID Connect (OIDC)-first model. You’ll design secure, scalable identity patterns across multi-cloud environments while enabling teams to build with speed and confidence.
You’ll partner closely with Security, Cloud, Platform, and Engineering teams to replace API keys and service accounts with scoped, ephemeral machine identities, establish enterprise standards, and deliver secure, developer-friendly integrations.
This is a hands-on leadership role for someone who can drive strategy, mentor engineers, and turn architecture into real-world implementations.
What You’ll Acheive
Modern Identity Architecture
-
Lead adoption of OAuth 2.1 / OIDC; drive migration from SAML and legacy auth
-
Design secure token flows (Auth Code + PKCE, Client Credentials, delegated access)
-
Define standards for token usage, scopes, claims, and lifecycle management
-
Reduce risk from token leakage, replay, and over-permissioning
Machine & Non-Human Identity
-
Replace long-lived credentials with modern machine identity patterns
-
Design M2M authentication for APIs, data pipelines, and platform workloads
-
Partner with teams on service account migration and secrets reduction
Platform & Integration Engineering
-
Build reusable identity patterns across IdPs, API gateways, and cloud platforms
-
Enable secure, scalable access across AWS, Azure, and/or GCP
-
Troubleshoot complex auth issues in hybrid and multi-cloud environments
Security, Governance & Observability
-
Apply Zero Trust principles (least privilege, scoped access)
-
Improve identity logging, monitoring, and audit readiness
-
Establish governance for OAuth apps, scopes, and access policies
Leadership & Delivery
-
Drive identity modernization programs end-to-end
-
Mentor architects and engineers; set technical standards
-
Break down complex initiatives into actionable workstreams
-
Lead incident response and improve operational visibility
Who you Are
What you’ll Bring with you
-
7+ years in IAM, security engineering, or platform roles
-
3+ years hands-on with OAuth 2.0 / OIDC in production
-
Strong expertise in token flows, scopes, claims, and secure design patterns
-
Experience implementing machine identity (M2M, workload identity, etc.)
-
Track record of modernizing identity (SAML OIDC or similar)
-
Experience with AWS, Azure, or GCP identity services
-
Ability to lead initiatives, influence teams, and deliver at scale
How you’ll Stand out from other Talent
-
Experience with API security, data platforms, or service-to-service auth at scale
-
Familiarity with SPIFFE/SPIRE, OPA, or advanced authorization models
-
Experience with Okta, Entra ID (Azure AD), Auth0, or Ping
-
Exposure to AI/agent-based identity patterns
-
Scripting or automation (Python, Bash)
Click here to view how Epsilon transforms marketing with 1 View, 1 Vision, 1 Voice.