08 Oct
|
Coforge
|
Chennai
2499 - PING ID CIAM Architect
Senior CIAM / IAM Solution Architect – Identity Broker (Ping Identity)
We are specifically looking for a senior hands-on CIAM / IAM Solution Architect with robust Ping Identity and federation experience. The candidate should have proven experience designing Identity Broker architectures using OIDC/OAuth2/SAML and integrating multiple existing Identity Providers and applications. This is not primarily an Entra ID or infrastructure role. Strong PingFederate experience would be a major advantage.
Key Responsibilities
- Drive and refine the solution architecture for the groupwide Identity Broker / CIAM platform
- Design secure and scalable identity federation patterns across existing Identity Providers and customer-facing applications
- Define and implement federation flows based on OIDC, OAuth 2.0 and SAML
- Design Home Realm Discovery, identity linking, claims normalization and token management
- Support the technical evaluation and prototype implementation of PingFederate and PingDirectory
- Define integration patterns between the Identity Broker, existing IdPs and customer-facing applications
- Design the identity data layer, including minimal customer identity attributes, identity mappings and linked accounts
- Define approaches for JIT provisioning, SCIM-based provisioning and identity synchronization
- Design for high availability, regional redundancy, failover and resilience
- Ensure compliance with security architecture principles for authentication, sessions, tokens and identity data
- Support the implementation of the initial LifeTrack prototype / pilot
- Work closely with application teams and Business Unit IT teams to onboard additional applications and Identity Providers
- Translate business and customer-access requirements into scalable technical architecture and implementation patterns
- Produce architecture documentation, integration specifications and technical decision papers
- Support architecture reviews and technical decision gates
- Provide hands-on technical guidance to developers, integration engineers and project stakeholders
The project specifically foresees the broker handling federation, routing, claims/token normalization and minimal identity linking, while authentication, credentials and MFA remain with existing IdPs.
Required Skills & Experience
Must Have
- 8+ years of professional experience in Identity & Access Management (IAM), security architecture or related areas
- Strong hands-on experience in Customer Identity & Access Management (CIAM)
- Proven experience designing Identity Broker / Federation architectures
- Strong knowledge of:
- OpenID Connect (OIDC)
- OAuth 2.0
- SAML 2.0
- Identity Federation
- SSO
- Token and claims management
- Strong experience with Ping Identity, ideally:
- PingFederate
- PingDirectory
- Experience integrating multiple Identity Providers (IdPs) and applications within complex enterprise environments
- Strong understanding of:
- Identity linking
- Home Realm Discovery
- Claims normalization
- Token issuance and validation
- Session management
- Experience with SCIM, JIT provisioning and user lifecycle integration
- Experience designing highly available and resilient IAM platforms
- Strong understanding of security principles for customer authentication and identity federation
- Experience working in large-scale, distributed enterprise environments
- Ability to communicate architecture decisions to both technical and non-technical stakeholders
Soft-Skills
- Strong analytical and solution-oriented mindset
- Excellent stakeholder management skills
- Comfortable working across multiple business units and technical organizations
- Ability to challenge existing architectural approaches constructively
- Able to work independently and drive technical topics end-to-end
- Excellent communication and documentation skills
- Fluent English
Skills Required:
IAM
Location:
Chennai
Desirable Skills:
ping federate,oidc,Oauth,SAML,SSO
Designation:
SENIOR ENGINEER
📌 SENIOR ENGINEER (Chennai)
🏢 Coforge
📍 Chennai