Padmi

Senior Ping Identity/SSO Architect

Remote · United StatesPosted 1 month ago
Software engineeringUnspecified
Apply at 3B Staffing

Opens the source posting on 3bstaffing.com

Source description

About the role

View original

Job : Senior Ping Identity/SSO architect

Duration: 6+ months

Location: Remote (US-Based)

Key Responsibilities

Own and lead the end-to-end migration from PingFederate to PingOne Workforce, including architecture, planning, and phased execution

Harden the identity environment and reduce platform fragility across the full migration lifecycle

Modernize entitlement management beyond legacy Oracle OES/OIM infrastructure, with a staged plan to replace brittle custom provisioning patterns without disrupting JML (Joiner-Mover-Leaver) automation

Advise on and support passwordless and clinician-friendly authentication initiatives in hybrid environments, including tap-and-go, badge-based workflows, fast user switching, and device-bound credentials

Navigate the real-world constraints of clinical environments, including camera, glove, and mobile limitations that affect authentication choices

Bring healthcare peer examples and reference architectures to inform architecture decisions, not just vendor documentation

Collaborate with internal identity and security teams to ensure continuity of SSO and MFA capabilities throughout the transition

Provide guidance on workstation authentication patterns across mixed internal and external identity populations, including contractors, physicians, vendors, and patients

Evaluate and advise on policy-based access management tools such as PlainID as part of the broader entitlement modernization strategy

Required Qualifications

7+ years of hands-on experience with Ping Identity products including PingFederate, PingOne, PingAccess, and PingDirectory

Must have personally led or owned at least one PingFederate to PingOne Workforce migration from design through production deployment

Demonstrated experience maintaining or redesigning JML automation workflows during a platform transition, without breaking provisioning continuity

Deep expertise in SSO, MFA, and modern identity protocols including SAML, OAuth 2.0, and OIDC

Experience with entitlement modernization and provisioning workflows in complex enterprise environments (Oracle OES/OIM familiarity strongly preferred)

Ability to work across mixed identity populations, including internal employees, external contractors, vendors, physicians, and patients in hybrid environments

Strong communication skills with the ability to present architecture decisions to both technical and non-technical stakeholders, including executive leadership

Healthcare industry experience, particularly in clinical or hospital environments

Preferred Qualifications

  • Direct experience with PlainID or a comparable policy-based access management platform

  • Familiarity with passwordless authentication standards including FIDO2 and WebAuthn

  • Experience designing or advising on clinician workstation authentication in acute care or ambulatory settings

  • Prior exposure to peer healthcare organizations navigating similar Ping migrations, with the ability to facilitate reference conversations

  • Ping Identity certifications (Ping Identity Certified Professional or equivalent)

  • Familiarity with zero trust identity frameworks and how they apply in clinical network environments

One address, no account. We’ll tell you when matching roles go live.

More at 3B Staffing

Related open roles

View all roles