Job Description
Responsibilities
- Identity and Access Management (IAM): Develop and manage IAM solutions to secure access to internal systems, as well as client and provider integrations with our BaaS platform.
- Authentication Systems: Design and implement secure authentication mechanisms, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and passwordless login, tailored for internal and external users.
- Regulatory Compliance: Ensure IAM processes comply with financial regulations, including PSD2, SOC 2, PCI/DSS, and other relevant standards, enabling secure customer authentication and data privacy.
- Authorization Frameworks: Build and support robust role-based access control (RBAC) and attribute-based access control (ABAC) models to manage permissions for clients, providers, and internal users across a multi-tenant platform.
- Identity Federation: Deploy identity federation protocols such as SAML, OAuth2.0, and OpenID Connect to enable secure integration with third-party applications and services used by clients and providers.
- Platform Security: Secure our Kubernetes and Azure estate workload identity, network policy, admission control, secrets management, and least privilege enforced by default.
- Security as Code: Express controls as infrastructure-as-code and deliver them through GitOps, so that security posture is version-controlled, reviewable, and reproducible rather than manually applied.
- .NET Integration: Leverage .NET expertise to integrate IAM capabilities into our core systems, APIs, and microservices, supporting secure operations across our BaaS platform.
- Incident Response: Investigate and resolve security incidents related to identity or access breaches affecting internal systems, clients, or providers.
- Monitoring and Reporting: Implement and maintain monitoring and detection solutions to identify anomalous behaviours and generate comprehensive reports on identity activities.
- Collaboration: Work closely with engineering, DevOps, and compliance teams to embed IAM and security best practices across our products and services.
What Were Looking For
Essential Requirements
- Bachelors degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- 5+ years of experience in cybersecurity roles, with a focus on identity management.
- Hands-on experience with IAM technologies (e.g., Transmit, Okta, Azure AD, Ping Identity, ForgeRock) in multi-tenant SaaS environments.
- Strong knowledge of financial regulations like PSD2, especially its requirements for Strong Customer Authentication (SCA), and PCI/DSS.
- Deep understanding of identity federation protocols (SAML, OAuth2.0, OpenID Connect) and practical experience with token, scope, and key lifecycle management.
- Proficiency in .NET, with experience integrating IAM capabilities into .NET-based systems and APIs.
- Production experience securing Kubernetes workloads workload identity, RBAC, network policy, and image provenance.
- Hands-on experience with Azure (or AWS/GCP) security services and with infrastructure-as-code using Terraform or OpenTofu.
- Experience with directory services such as Microsoft Entra ID, Active Directory, and LDAP.
- Strong scripting and automation skills (e.g., Python, PowerShell).
Nice to Have
- Security certifications such as CISSP, CCSP, or identity-specific credentials (e.g. Azure Security Engineer Associate).
- Experience working in regulated industries, especially fintech or banking.
- Experience implementing IAM solutions in multi-tenant, API-first platforms like BaaS.
- Familiarity with Zero Trust Architecture principles.
- Experience with API gateway and WAF security patterns (e.g. Kong, Azure Application Gateway) and where authentication belongs in the request path.
- Familiarity with GitOps delivery (ArgoCD, Helm) and embedding security controls into CI/CD pipelines.
- Experience extending an open-source identity provider rather than only configuring one.
Soft Skills That Make a Difference
- Strategic thinking with a bias for action.
- Strong analytical and problem-solving skills.
- Ownership and accountability.
- Ability to adapt to evolving regulatory and technological landscapes.
- Strong communication and collaboration skills to engage with technical and non-technical stakeholders, including clients and providers.
- Curiosity, adaptability, and passion for innovation
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#GraphicDesignJobsOnline
#WebDesignRemoteJobs
#FreelanceGraphicDesigner
#WorkFromHomeDesignJobs
#OnlineWebDesignWork
#RemoteDesignOpportunities
#HireGraphicDesigners
#DigitalDesignCareers
# Dynamicbrand guru