- Company Name
- Themesoft Inc.
- Job Title
- App Security Architect (SSO/MFA/OKTA Engineer )
- Job Description
-
Job Title: App Security Architect (SSO/MFA/OKTA Engineer)
Role Summary: Design, implement, and manage secure authentication and identity‑management solutions for enterprise applications. Lead integration of SSO, MFA, OKTA, Ping ID, Microsoft Entra ID, and RSA Adaptive Authentication. Conduct security assessments, audit findings, and policy development to align with industry standards and business objectives.
Expectations: Deliver robust, scalable authentication architecture that reduces breach risk while enabling user productivity. Provide guidance on Java security frameworks, secure coding practices, and emerging threat mitigation. Present recommendations for technology采购 and optimal security posture.
Key Responsibilities:
- Design and deploy SSO and MFA solutions across application portfolio.
- Integrate OKTA, Ping ID, Microsoft Entra ID, and RSA Adaptive Authentication with existing infrastructure.
- Conduct periodic security assessments, penetration tests, and vulnerability reviews.
- Develop and enforce security policies, procedures, and compliance frameworks.
- Educate development, operations, and business stakeholders on secure design and threat awareness.
- Evaluate, select, and recommend authentication & identity technologies.
- Troubleshoot and resolve application security incidents and authentication failures.
- Monitor industry trends and incorporate best practices into architecture.
- Collaborate with cross‑functional teams to define security requirements and acceptance criteria.
- Produce technical documentation and configuration guides for stakeholders.
Required Skills:
- Deep expertise in SSO/MFA architectures, OKTA, Ping ID, Microsoft Entra ID, RSA Adaptive Authentication.
- Strong knowledge of Java security frameworks (Spring Security, OWASP ASVS).
- Experience in designing secure application architectures and performing threat modeling.
- Proficiency in identity‑management protocols (SAML, OAuth2/OIDC, OpenID Connect).
- Familiarity with enterprise security standards (ISO 27001, NIST CSF, GDPR, HIPAA).
- Strong communication and training abilities for cross‑team collaboration.
- Ability to analyze security logs, troubleshoot authentication issues, and recommend mitigations.
- Project management skills for coordinating multi‑vendor deployments and stakeholder communication.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Professional certifications: CISSP, CISM, CRISC, or equivalent security architecture qualifications highly preferred.
- OKTA Certified Architect or equivalent Okta certification (e.g., OKTA Certified Administrator).
- Ping Identity Certified Administrator or related Ping ID certification preferred.