Skip to main content
Tallo logoTallo logo
Apply for this opportunity

This job application is on an outside website. Be sure to review the job posting there to verify it's the same.

Lead Cloud Identity Engineer

Job

Koch

Wichita, KS (In Person)

Full-Time

Posted 2 weeks ago (Updated 1 week ago) • Actively hiring

Expires 6/22/2026

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
82
out of 100
Average of individual scores

Were these scores useful?

Skill Insights

Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.

Job Description

Your Job We have an exciting opportunity to hire a Lead Cloud Identity Engineer to join our already skilled engineering team. This individual will be a part of a global team that manages authentication and identity tools and procedures for Koch Industries. Working closely with global colleagues, as well as customers, will provide significant global exposure. Our Team The Koch Technology Identity team provides modern Identity solutions and services for all Koch businesses. We are responsible for the entire enterprise in designing innovative services, creating, and sharing best practices, and providing support for our services.
Location:
This role requires an in office presence with flexibility in Wichita, KS / Atlanta, GA / or Plano, TX This role is not eligible for VISA sponsorship What You Will Do
  • Set IAM architecture & standards: Define reusable patterns for SSO/federation, authorization models, privileged access, and workload/machine identity.
  • Lead design governance: Run identity design reviews for new applications and major platform changes; approve patterns, manage exceptions, and drive adoption.
  • Build authentication & federation: Design and implement SAML2, OAuth2/OIDC, WS-Fed, and FIDO2/passkeys, including adaptive/risk-based auth, conditional access, and MFA.
  • Engineer IAM platforms: Operate and enhance enterprise identity services (PingOne / PingOne DaVinci or equivalent orchestration platforms).
  • Lead developer for IAM platforms: Serve as lead developer driving hands-on code development to build, extend, and maintain new and existing identity platforms, including custom connectors, APIs, and orchestration flows.
  • Design authorization & governance: Build scalable
RBAC/ABAC/PBAC
models, entitlement catalogs, role engineering, and access request workflows (IGA).
  • Automate identity lifecycle: Lead and design end-to-end JML automation integrating HRIS, ITSM, directories, and apps via SCIM and event-driven pipelines.
  • Identity as
Code:
Manage identity configuration/policy using Terraform and CI/CD with testing, version control, and deployment discipline.
    Zero Trust & Detection:
    Implement least privilege and continuous verification; integrate ITDR-style monitoring, logging, alerting, SLOs, and rapid revocation.
    • Incident leadership: Act as escalation for auth outages, federation issues, and credential compromise; lead RCA and post-incident hardening.
    • Influence & mentoring: Partner globally with architects, developers, and security; coach engineers through reviews, playbooks, and training. Who You Are (Basic Qualifications)
    • Extensive experience owning identity platforms at scale, with deep protocol-level expertise across SAML, OAuth2/OIDC, SCIM, FIDO2/passkeys, LDAP, and Kerberos.
    • Hands-on architecture across Azure Entra ID, AWS IAM, or Google Cloud Identity, including cross-cloud federation and hybrid identity patterns.
    • Practical experience .
    ..