Principal IAM Engineer Consultant
ABOUT KALLES GROUP:
Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes.
While our expertise spans multiple disciplines, our method remains consistent: building trust and relationship with people -- whether you are a client, a consultant, or--in this case--a candidate.
No matter what role you come from--whether you're an executive or just starting your career-you can expect our highest level of attention and respect. We want to find the right fit for each role, but we also want you to find the right fit for your career.
We believe the best way to show you what our team is like is to treat you like you're already a part of it. We hope you'll consider joining our team of experienced professionals who are building their careers at Kalles Group—and having fun while doing it.
WHAT YOU WILL DO:
As a Principal IAM Engineer Consultant, you will provide senior technical leadership for our client's Customer Identity and Access Management (CIAM) platform, helping design and deliver secure, scalable identity capabilities that support millions of customer interactions within a highly regulated financial services environment. Serving as the technical authority across engineering, architecture, cybersecurity, product, and delivery teams, you will transform strategic identity initiatives into detailed engineering solutions while driving engineering quality and technical consistency across the platform.
This is a hands-on engineering leadership role—not a program management or governance position. You will author detailed engineering designs, define secure authentication and integration patterns, guide implementation teams, and help shape the long-term evolution of the organization's customer identity platform. Success requires deep expertise in modern consumer identity technologies, authentication protocols, cloud-native architectures, and the ability to influence technical direction through credibility, collaboration, and sound engineering judgment.
Key Responsibilities:
Develop engineering-level solution designs for CIAM initiatives, including architecture, integration patterns, data flows, security controls, operational readiness, and implementation sequencing
Partner with Product Owners, architects, cybersecurity teams, engineering, and delivery stakeholders to align technical solutions with business priorities
Coordinate technical delivery activities by managing dependencies, clarifying ownership, resolving blockers, and supporting predictable execution
Provide technical leadership and mentoring to engineering teams, reinforcing secure coding practices, documentation standards, and maintainable implementation approaches
Identify engineering risks, technical debt, architecture drift, and security gaps that could impact platform stability or delivery quality
Advise Product Owners on backlog sequencing, technical readiness, engineering complexity, and delivery trade-offs
Facilitate technical decision-making across multiple teams while building alignment on architecture, priorities, and implementation approaches
Support delivery governance by escalating recurring issues, monitoring execution quality, and partnering with leadership to resolve delivery challenges
Develop reusable design patterns, technical standards, implementation guidance, and delivery playbooks that improve consistency across the CIAM program
Document technical decisions, assumptions, risks, and mitigation strategies throughout the delivery lifecycle
Strengthen collaboration across engineering, cybersecurity, architecture, product management, and vendor partners to improve delivery outcomes
Develop detailed engineering design documentation—including authentication flows, integration patterns, sequence diagrams, token architecture, and implementation guidance—to enable consistent, secure delivery across multiple engineering teams.
ABOUT YOU:
Your values:
Integrity: You believe in doing the right thing, even when it's uncomfortable, seemingly inefficient, or costly.
Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations.
YOUR EXPERIENCE:
Required Qualifications
10+ years of progressive software engineering or identity engineering experience, including significant time operating at a Senior, Lead, Staff, or Principal Engineer level
Deep hands-on expertise designing and implementing Customer Identity and Access Management (CIAM) solutions supporting customer-facing applications at enterprise scale
Expert knowledge of modern identity platforms including Ping Identity (PingFederate/PingOne), ForgeRock, Okta Customer Identity/Auth0, or Microsoft Entra External ID
Experience producing engineering-level design documentation including:
OAuth 2.0, OpenID Connect (OIDC), and SAML federation
Authentication and authorization flows
Passwordless and MFA architectures
Session and token management
API security and integration patterns
Sequence diagrams, data flows, and implementation designs
Proven ability to influence architecture and engineering decisions across multiple delivery teams without direct management authority
Experience identifying technical debt, architecture drift, security gaps, and implementation risks while driving practical engineering improvements
Strong understanding of secure software engineering, Zero Trust principles, and cloud-native identity architectures
Experience supporting high-volume customer-facing identity platforms within banking, credit unions, insurance, fintech, or similarly regulated industries
Excellent communication skills with the ability to build consensus across engineers, architects, product leaders, and executive stakeholders while navigating complex organizational environments
Preferred Qualifications
Experience leading or supporting large-scale customer identity platform migrations, consolidations, or modernization initiatives
Experience supporting mergers, acquisitions, or identity platform integrations across multiple organizations
Experience with Azure API Management (APIM), Cosmos DB, F5 Distributed Cloud/Shape, or similar supporting technologies
Experience integrating CIAM solutions with customer-facing mobile applications and digital banking platforms
Familiarity with fraud prevention and identity risk platforms such as Outseer
Experience creating reusable architecture patterns, engineering standards, and technical playbooks
Knowledge of Infrastructure as Code, cloud-native architectures, and DevSecOps delivery practices
WHAT WE OFFER:
The annual salary range for this role is $160,000-$220,000.
Work/life balance – we know there’s more to life than work! We encourage our team to pursue other passions, get outside, and spend time with family. We work with clients and consultants to set expectations for a manageable workload.
LOCATION:
This role is remote
HOW TO APPLY:
Please fill out the form below (including uploading your most recent resume) and we'll be in touch! We know imposter syndrome can be a barrier to many great applicants. We hope you'll still consider applying. That's why we've made the application process as short and simple as possible.
Even if you're not a fit for the role, you can expect to hear back from us! We want you to have the best experience as a candidate, so please feel free to share feedback at any stage of the process to talent@kallesgroup.com.
Kalles Group is an equal-opportunity employer and does not discriminate on the basis of creed, nationality, race, ethnicity, disability, gender, or other protected class.