About this role
We are looking for a Senior Customer Identity and Access Management (CIAM) Engineer to join our Identity Engineering team. In this role, you will design, build, and support secure customer identity solutions using Auth0 and Okta. You will work closely with application development teams to onboard and connect applications to modern identity platforms. You will help support secure sign-in experiences, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), federation, customer registration, and passwordless authentication. This role will also help improve how identity solutions are built and managed through automation. You will use Terraform, GitHub, GitOps, and CI/CD practices to help move identity management from manual processes to a scalable, automated, and developer-friendly platform. The ideal candidate has strong experience with customer identity, authentication, authorization, federation, and modern passwordless technologies.
Responsibilities:
- Partner with application teams to design and build secure integrations with Auth0 and Okta.
- Lead application onboarding, including SSO, MFA, federation, and customer registration.
- Design, build, and support CIAM solutions for millions of customer identities.
- Build and manage identity infrastructure using Terraform, GitHub, and GitOps.
- Create reusable tools, modules, and automated processes to make application onboarding easier.
- Build and support passwordless authentication using passkeys, FIDO2, and WebAuthn.
- Configure authentication policies, adaptive access controls, MFA policies, and customer identity journeys.
- Build federation solutions using OAuth 2.0, OpenID Connect (OIDC), SAML, SCIM, and JWT.
- Work with security, architecture, and development teams to follow enterprise security standards.
- Troubleshoot complex authentication, authorization, identity, and federation issues.
- Support CI/CD pipelines and automated identity platform deployments.
- Help develop identity standards, reference architectures, and engineering best practices.
- Document solution designs, integration patterns, and operating procedures.
- Support modernization efforts focused on automation, self-service capabilities, monitoring, and scalability.
Qualifications:
Required
- Hands-on experience implementing and supporting enterprise-scale Okta and/or Auth0 platforms.
- Strong knowledge of OAuth 2.0, OIDC, SAML, and SCIM.
- Strong experience with federation and Single Sign-On (SSO).
- Experience implementing and supporting Multi-Factor Authentication (MFA).
- Experience designing and deploying passwordless authentication solutions.
- Strong understanding of passkeys, FIDO2/WebAuthn, device-based authentication, and risk-based authentication.
- Experience supporting customer registration and account recovery journeys.
- Experience implementing Infrastructure as Code (IaC) with Terraform.
- Strong experience with GitHub, including Git workflows, pull requests, and code reviews.
- Experience with GitOps deployment models and CI/CD pipelines.
- Experience with monitoring and operational tools such as Splunk, ServiceNow, Jira, or similar platforms.
Preferred
- Experience with Policy as Code and governance automation.
- Experience supporting customer identity platforms in regulated environments.
- Experience building self-service tools for developers and application onboarding.
If you will be working at home occasionally or permanently, the internet connection must be obtained through a cable broadband or fiber optic internet service provider with speeds of at least 10Mbps download/5Mbps upload.
For this position, we anticipate offering an annual salary of 124,600 - 207,600 USD / yearly, depending on relevant factors, including experience and geographic location.
This role is also anticipated to be eligible to participate in an annual bonus plan.
At The Cigna Group, you’ll enjoy a comprehensive range of benefits, with a focus on supporting your whole health. Starting on day one of your employment, you’ll be offered several health-related benefits including medical, vision, dental, and well-being and behavioral health programs. We also offer 401(k), company paid life insurance, tuition reimbursement, a minimum of 18 days of paid time off per year, paid holidays, and leaves of absence. For more details on our employee benefits programs, click here .
About The Cigna Group
Doing something meaningful starts with a simple decision, a commitment to changing lives. At The Cigna Group, we’re dedicated to improving the health and vitality of those we serve. Through our divisions Cigna Healthcare and Evernorth Health Services, we are committed to enhancing the lives of our clients, customers and patients. Join us in driving growth and improving lives.
Qualified applicants will be considered without regard to race, color, age, disability, sex, childbirth (including pregnancy) or related medical conditions including but not limited to lactation, sexual orientation, gender identity or expression, veteran or military status, religion, national origin, ancestry, marital or familial status, genetic information, status with regard to public assistance, citizenship status or any other characteristic protected by applicable equal employment opportunity laws.
If you need a reasonable accommodation to complete the online application process, please email [email protected] for assistance. Please note that this email inbox is dedicated to accommodation requests only and cannot provide application updates or accept resumes.
The Cigna Group has a tobacco-free policy and reserves the right not to hire tobacco/nicotine users in states where that is legally permissible. Candidates in such states who use tobacco/nicotine will not be considered for employment unless they enter a qualifying smoking cessation program prior to the start of their employment. These states include: Alabama, Alaska, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Iowa, Kansas, Maryland, Massachusetts, Michigan, Nebraska, Ohio, Pennsylvania, Texas, Utah, Vermont, and Washington State.
Qualified applicants with criminal histories will be considered for employment in a manner consistent with all federal, state and local ordinances.