yoinka

Principal Authentication Engineer (IAM) — Vice President

Morgan Stanley

New York, New York, United States of AmericaPrincipal
Apply on company siteFound by Yoinka 3h ago
Location
New York, New York, United States of America
Work model
On-Site
Level
Principal
Posted
20h ago

Skills

AgileAnsibleCI/CDCybersecurityLinuxOAuthPythonTerraform

About this role

{ "jobLocation" : { "@type" : "Place", "address" : { "@type" : "PostalAddress", "addressCountry" : "United States of America", "addressLocality" : "1 New York Plaza" } }, "hiringOrganization" : { "name" : "474 MS Services Group, Inc.", "@type" : "Organization", "sameAs" : "" }, "identifier" : { "name" : "Principal Authentication Engineer (IAM) — Vice President", "@type" : "PropertyValue", "value" : "PT-JR040679" }, "datePosted" : "2026-07-21", "employmentType" : "FULL_TIME", "title" : "Principal Authentication Engineer (IAM) — Vice President", "description" : "We’re seeking someone to join our Authentication Engineering (IAM) team as a Principal Authentication Engineer in Cybersecurity (Identity & Access Management) to design, integrate, and operate standards-based authentication at global scale across hybrid environments—enabling secure, seamless access for our workforce and platforms. What you’ll do in the role Lead Hands-On Authentication Engineering: design, build, integrate, and ship secure, scalable solutions for human and non-human identities (bots, service accounts, applications, agentic systems). Own Enterprise Authentication & Federation: implement and harden OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI (mTLS, cert lifecycle), API auth, and Unix/Linux authentication. Integrate and Customize IAM Platforms: deliver end-to-end integrations across Entra ID, Ping Identity, SailPoint, CyberArk, HashiCorp Vault, HSMs, IDM/LDAP, and RCBI in cloud and hybrid environments. Drive Reliability and Automation at Scale: operate and evolve large-scale IAM estates with HA/DR, performance tuning, IaC (Terraform), config management (Ansible/Puppet/Chef), CI/CD, observability, and safe deployment strategies. Harden and Govern Identity Controls: define and enforce policies for identity lifecycle, authentication, authorization, PAM, and secrets management for human and non-human identities. Assess and Uplift Existing Solutions: identify risks and technical debt, deliver remediation plans, and implement secure-by-default patterns with measurable outcomes. Translate Architecture into Executable Work: break down complex designs into clear epics, stories, runbooks, and pipelines; produce ADRs, standards, and audit-ready documentation to align engineers, SREs, POs, and QA. Partner and Operate Across Teams: collaborate with product/platform leads to scale adoption; participate in on-call, lead RCAs, and drive operational excellence. What you’ll bring to the role Hands-On Principal Engineer (not architect-only): design and implement—comfortable coding, configuring, integrating products, and shipping production outcomes. Deep authentication expertise: OIDC/OAuth2, SAML, SSO, FIDO2/WebAuthn, PKI (CA/RA, mTLS, cert lifecycle), API auth (JWT/mTLS), and Unix/Linux authentication at enterprise scale. IAM platforms & integration mastery: experience with HashiCorp Vault, HSMs, CyberArk, SailPoint, Entra ID, Ping Identity, IDM/LDAP, and RCBI—covering policy design, integration, automation, and migrations. Resiliency and Automation at Scale: proven experience operating IAM/auth services across large, globally distributed environments with multi-region HA/DR, performance tuning, IaC (Terraform), config management (Ansible/Puppet/Chef), CI/CD, observability; strong Shell plus Python/Go. Security & compliance acumen: threat modeling, least privilege, PAM, secrets management, policy-as-code, and auditability for human and non-human identities (including agentic systems). Systems integrator mindset: ability to customize and stitch vendor products and open standards into cohesive, well-documented solutions and APIs. Team enablement & communication: skill in decomposing solutions into clear epics/stories, authoring ADRs/runbooks/standards, conducting reviews, coaching engineers/SREs, and producing clear written documentation to influence stakeholders in an agile squad model. Enterprise & industry savvy: experience navigating

Apply on company site

This listing was discovered and verified by Yoinka 3h ago. Yoinka scrapes company career pages directly, so you apply on the real source — not a stale aggregator copy.

← Back to Yoinka

Principal Authentication Engineer (IAM) — Vice President at Morgan Stanley — New York, New York, United States of America | Yoinka