Vanguard logo

Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard

Malvern, PAHybridFull-timeNo compensation foundPosted 3mo agoSeen in employer's feed 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Malvern, PAHybrid
Schedule
Full-time
Work Authorization
Visa required • Visa sponsorship

Requirements

Credentials this posting asks for.

Bachelor's degree

Job overview

Vanguard is hiring a Senior Specialist, Lead Zero Trust Identity Security Engineering. The senior specialist will lead workforce identity platform engineering at Vanguard, serving as technical lead for Okta and related integrations, owning end‑to‑end architecture, and guiding design, security, and reliability while communicating complex concepts to stakeholders.

Key focus areas include Serve as technical lead for workforce identity platforms with Okta as primary IdP, Own end‑to‑end identity architecture including authentication flows and token issuance, and Lead design reviews for IdP resiliency, failover, and supplier‑risk mitigation.

Successful candidates bring Undergraduate Degree In Related Field Or Equivalent and 12+ Years Of Experience In Identity & Access Management Engineering. Important skills include Okta, Ping Identity, OAuth 2.0, OpenID Connect, SAML, and SCIM. Preferred (not required): Entra Identity, Communication, Influence, and Stakeholder Management.

Skills & qualifications

RequiredNice to have

Skills

OktaPing IdentityOAuth 2.0OpenID ConnectSAMLSCIMJWTToken-Based AuthActive DirectoryPing DirectoryAWSGCPAzureTerraformAWS CloudFormationKubernetesZero Trust PrinciplesMFASSOLDAPPingFederatePingOneDevOps ToolsPolicy as CodeTroubleshooting Authentication and Federation FailuresOperating in High-Visibility, High-Impact EnvironmentsEntra IdentityCommunicationInfluenceStakeholder ManagementSAML FederationToken-Based SecurityDirectory ServicesTroubleshooting Complex AuthenticationTroubleshooting Federation FailuresOperating in High-Visibility EnvironmentsOperating in High-Impact EnvironmentsTroubleshootingIncident ManagementRisk AssessmentsCoachingAuthentication FlowsFederationDirectory IntegrationsToken IssuanceDesign ReviewsIdP ResiliencyFailoverSupplier-Risk MitigationDocument ArchitectureTechnical DirectionToken ParityClaim ConsistencyIssuer AbstractionModern AuthenticationCloud DirectoriesAttribute ModelsLifecycle ManagementGroup StrategiesContainersInfrastructure as CodeContainerized Identity ServicesAutomated ProvisioningDeployment AutomationMonitoringDrift DetectionSRE-Style Operational MaturitySLIs/SLOsAlertingRunbooksEnterprise Security PoliciesControl ValidationPing Identity ProductsSRE PracticesReliability EngineeringLeadershipSLIsSLOsWorkforce IdentityIdentity FederationZero TrustRisk Assessment

Qualifications

Undergraduate Degree in Related Field12+ Years Experience in Identity & Access Management Engineering

Full job description

Senior Specialist, Lead Zero Trust Identity Security Engineering

Apply (https://vanguard.wd5.myworkdayjobs.com/en-US/vanguard\_external/job/Malvern-PA/Senior-Specialist--Lead-Zero-Trust-Identity-Security-Engineering\_177327-1/apply)

locations

Malvern, PA

Dallas/Ft. Worth, TX

time type

Full time

posted on

Posted 28 Days Ago

job requisition id

177327

Key Responsibilities

Identity Platform Engineering & Leadership

  • Serve as technical lead for workforce identity platforms, with Okta as the primary IdP and integrations to complementary platforms (e.g., Ping/Entra Identity).

  • Own end‑to‑end identity architecture, including authentication flows, federation, directory integrations, and token issuance.

  • Lead design reviews and decisions for IdP resiliency, failover, and supplier‑risk mitigation strategies.

  • Document existing and new architecture and act as a hands‑on engineer while also setting technical direction, patterns, and standards.

  • Strong communication, influence, and stakeholder‑management skills, with the ability to distill complex identity and security architectures into clear and concise messaging

Standards‑Based Identity & Federation

  • Design and troubleshoot identity flows using OAuth 2.0 / OIDC SAML 2.0 SCIM JWT / token‑based auth

  • Ensure token parity, claim consistency, and issuer abstraction across identity providers to minimize application impact.

  • Partner with application teams to enable modern authentication without app re‑architecture.

Directory & Identity Data Architecture

  • Engineer and maintain directory integrations across Active Directory, Okta UD, and cloud directories (e.g., Ping Directory).

  • Design attribute models, lifecycle management, and group strategies at enterprise scale (thousands of groups, large population sizes).

  • Support directory deployments in cloud‑native environments (AWS/GCP, containers, Kubernetes).

Cloud, Automation & Reliability

  • Build and operate identity infrastructure in AWS/GCP/Azure, using: Infrastructure & Policy as Code (Terraform / CloudFormation) Kubernetes & containerized identity services

  • Automate provisioning, deployment, monitoring, and drift detection for identity platforms.

  • Support SRE‑style operational maturity: SLIs/SLOs, alerting, incident response, and runbooks for identity services.

Security, Risk & Compliance

  • Design identity controls aligned to Zero Trust principles and enterprise security policies.

  • Partner with CSOC, audit, and risk teams on: Control validation Incident response Regulatory and audit requirements (SOX, SOC, internal controls)

  • Contribute to risk assessments related to supplier dependency, SPOFs, and identity outages.

Collaboration & Influence

  • Work closely with security architecture, infrastructure, application engineering, IAM operations, and vendors.

  • Influence roadmap decisions through clear technical reasoning and executive‑ready communication.

  • Mentor senior and mid‑level engineers and raise overall identity engineering maturity.

Qualifications

  • Undergraduate degree in a related field or the equivalent combination of training and experience.

  • 12+ yearsof experience in Identity & Access Management engineering.

  • Skilled in using DevOps tools and experience in Policy as code.

  • Deep hands‑on expertise with Okta(Workforce Identity, MFA, SSO, policies, lifecycle).

  • Strong working knowledge ofPing Identityproducts (PingFederate, PingOne, Ping Directory) or equivalent platforms.

  • Expert understanding ofidentity standards: OAuth 2.0, OIDC, SAML Federation and token‑based security

  • Proven experience withdirectory services & LDAP(AD, cloud directories).

  • Experience building identity platforms inAWS/GCP, including containerized/Kubernetes deployments.

  • Strong troubleshooting skills for complex authentication and federation failures.

  • Ability to operate inhigh‑visibility, high‑impact environments.

Special Factors

Sponsorship

Vanguard is offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

You've read the whole posting — now see how you match it.