Identity Management Engineering Lead | Shape the Future of Digital Identity 🚀

Location
Contract Type
Full-time
Salary
130 000 - 190 000 Kč
Work from home
Partial work from home
Published
Reference
1001407-1
Job description

Step into a pivotal position as Lead CIAM Engineer, driving the evolution of a cutting-edge digital platform. Your mission? Modernize and transform our digital ecosystem to deliver a world-class customer experience. You’ll collaborate closely with engineering and product teams, fostering a culture of innovation and teamwork at the heart of everything we do. 🌍✨

What You’ll Do

🔐 Lead Identity & Access Management (IAM) – Own the design and implementation of secure, scalable identity solutions.

🔄 Architect Seamless Authentication – Build and optimize Single Sign-On (SSO), OAuth2, OIDC, PKI, and PSD2 SCA flows.

💻 Hands-On Development – Code in JavaScript or Java, crafting extensible IAM APIs for smooth integration across internal and external apps.

🛡 Embed Security in DevSecOps – Partner with security, compliance, and engineering teams to champion identity-first principles.

🌐 Innovate with Ping Solutions – Implement custom PingAM authentication trees, PingGateway SSO routes, dynamic proxies, and PingIDM data links.

📈 Drive Continuous Improvement – Stay ahead of industry trends, contribute to tech communities, and elevate our IAM capabilities.

What’s In It For You?

🌍 Impact at Scale – Your work will shape a next-gen digital identity platform used by millions.

🏆 Leadership & Influence – Drive strategy, mentor talent, and set technical direction.

💡 Innovation Culture – Work with cutting-edge tech in a collaborative, forward-thinking environment.

🏢 Location: Prague office – a hub for digital transformation.

📈 Career Growth – Opportunities to lead multi-year projects and guide technical vision.

Requirements

What We’re Looking For

✅ Proven IAM Expertise – Broad experience across the IAM domain with a strong engineering background.

✅ Deep Knowledge of Authentication Protocols – OAuth2, OIDC, PKI, PSD2 SCA, possession-based authentication.

✅ Coding Skills – Solid experience in JavaScript or Java, with the ability to design robust IAM APIs.

✅ Bonus Points For:

PingAM custom authentication trees & adaptive authentication.

PingGateway SSO routes and dynamic proxies.

PingIDM data link implementations.

✅ Strategic Thinker – Ability to influence architecture, manage risk, and align with business objectives.

Benefits

Annual bonus

25 days of holiday

Sick leave benefit

Private medical clinic membership

Multisport card

Flexible working hours

Possibility of working from home

Technical trainings, soft skills training, financial markets trainings

Other notes
For more related job opportunities visit https://www.grafton.cz/en/job-search