Sr Engineer, CIAM at Optimum | Bethpage, NY, US | Rezi

Sr Engineer, CIAM at Optimum

Sr Engineer, CIAM

Optimum · Bethpage, NY, US

1 weeks ago

Sr Engineer, CIAM

Optimum · Bethpage, NY, US

10 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Senior IAM Engineer is the technical anchor of the Customer IAM team, owning the platform architecture, defining standards, designing automation, and providing technical leadership. This role involves making consequential decisions on Customer Identity Engine configuration, authentication policy design, IaC strategy, and security control architecture, with significant influence over the team's technical trajectory.

Responsibilities

  • Own the architecture and design of the enterprise customer identity platform, including authentication policy frameworks, authorization models, and identity lifecycle standards.
  • Define and enforce integration standards across identity protocols (OAuth 2.0, OpenID Connect, SAML, SCIM), ensuring consistency and scalability across all applications.
  • Establish governance practices for platform configuration, including naming standards, policy structures, and change management controls.
  • Lead the evaluation and adoption of new identity capabilities and platform features aligned to enterprise security and scalability goals.
  • Lead the technical design of enterprise authentication modernization initiatives, defining integration patterns and reference architectures for application teams.
  • Develop and maintain standardized migration frameworks for onboarding applications to modern CIAM solutions.
  • Define token design, scope models, and session management strategies aligned to security and business requirements.
  • Drive adoption of advanced authentication capabilities, including phishing-resistant and passwordless authentication.
  • Identify and resolve cross-cutting architectural challenges impacting identity integrations across the application portfolio.
  • Own the IAM developer experience, including integration guides, reference architectures, code samples, and reusable implementation patterns.
  • Build and maintain reference implementations demonstrating best practices for authentication flows, token validation, and session management.
  • Design and improve onboarding processes and self-service capabilities for application teams integrating with the CIAM platform.
  • Lead architecture reviews for complex or high-risk integrations, providing clear, standards-based guidance and decision rationale.
  • Foster a community of practice to promote identity best practices and knowledge sharing across engineering teams.
  • Conduct threat modeling for the CIAM platform and application integrations, identifying risks and designing appropriate controls.
  • Define and maintain identity security standards, including authentication assurance levels, MFA requirements, and session policies.
  • Design and tune identity-related monitoring and detection capabilities, including integration with SIEM tools.
  • Lead security design reviews for identity workflows, integrations, and custom services to ensure adherence to best practices.
  • Support vulnerability management by assessing risks, prioritizing remediation, and driving resolution across the platform.

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience).
  • 6+ years of experience in Identity & Access Management, security engineering, or a related technical field.
  • Strong hands-on experience designing and operating CIAM or identity provider platforms at scale.
  • Deep understanding of identity standards and protocols (OAuth 2.0, OpenID Connect, SAML, SCIM, FIDO2/WebAuthn).
  • Experience leading authentication modernization or large-scale IAM integration initiatives.
  • Proficiency in at least one modern programming language (e.g., JavaScript, Python, Java, Go) for building integrations and automation.
  • Experience implementing Infrastructure-as-Code and CI/CD practices for platform configuration.
  • Proven ability to perform threat modeling, security reviews, and produce clear technical guidance.
  • Experience working with compliance frameworks (e.g., SOX, SOC 2, PCI) and supporting audit activities.
  • Demonstrated ability to mentor engineers and influence technical direction across teams.
  • Applicants must be authorized to work for ANY employer in the U.S.
  • Do not provide visa sponsorship for employment.

Skills

  • Identity & Access Management
  • Security Engineering
  • CIAM
  • Identity Provider Platforms
  • OAuth 2.0
  • OpenID Connect
  • SAML
  • SCIM
  • FIDO2/WebAuthn
  • JavaScript
  • Python
  • Java
  • Go
  • Infrastructure-as-Code
  • CI/CD
  • Threat Modeling
  • Security Reviews
  • SOX
  • SOC 2
  • PCI

Location

  • New York

Work Type

  • Full-time

Experience Level

  • Senior
  • 6+ years

Education Level

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience)

Salary/Compensations

  • $100,246.00 - $164,689.00 / year

Benefits

  • Competitive pay

About the Company

  • Optimum is a leader in the fast-paced world of connectivity, empowering lives, fueling businesses, and driving innovation.
  • Connectivity is now longer a luxury, but a necessity.
  • A career at Optimum means you'll be enabling progress and enhancing lives by providing reliable, high-speed connectivity solutions that keep the world connected.
  • Our successes, now and in the future, are powered by our amazing product, a commitment to our people and culture, and the connections we make in our communities.
  • At Optimum, every action and interaction we take part in, is driven by our three Guiding Principles: Do What’s Right, Drive One Optimum, and Make It Happen.
  • Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them.
  • It’s all part of the bigger picture of “Be The Difference” where each employee knows they have the power to enact real change, share new ideas, and understand that learning never stop.

Equal Opportunity

  • We are an Equal Opportunity Employer committed to recruiting, hiring and promoting qualified people of all backgrounds regardless of gender, race, color, creed, national origin, religion, age, marital status, pregnancy, physical or mental disability, sexual orientation, gender identity, military or veteran status, or any other basis protected by federal, state, or local law.
  • The Company collects personal information about its applicants for employment that may include personal identifiers, professional or employment related information, photos, education information and/or protected classifications under federal and state law. This information is collected for employment purposes, including identification, work authorization, FCRA-compliant background screening, human resource administration and compliance with federal, state and local law.
  • Applicants for employment with The Company will never be asked to provide money (even if reimbursable) as part of the job application or hiring process. Please review our Fraud FAQ for further details.