hirly

Pru

Lead, Infrastructure Security Engineer - Customer Identity & Access Management

Newark, NJ, USA

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Pru first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Role family
Engineering
Seniority
Lead / management
Country
US
Work mode
On-site / unstated
First seen by hirly
2 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Job Classification:

Technology - Engineering & Cloud

Are you interested in engineering secure, scalable, and intelligent identity platforms that protect millions of customer interactions? The Global Technology Security Services team is building the next generation of Customer Identity and Access Management capabilities through cloud identity platforms, adaptive authentication, fraud and risk detection, software engineering, automation, and modern authorization patterns.

Your Team & Role

As a Lead Infrastructure Security Engineer on our CIAM Team, you will lead, design, develop, test, automate, and support security capabilities across the global CIAM ecosystem, with primary emphasis on PingOne Advanced Identity Cloud, PingOne Protect, customer authentication journeys, CIAM APIs, mobile and web integrations, fraud and risk controls, and platform observability. You will partner with Technical Leads, Product Owners, application engineers, mobile developers, fraud and cyber teams, architects, and delivery professionals to implement secure customer authentication, authorization, registration, account recovery, identity verification, and step-up authentication solutions.

Here is What You Can Expect on a Typical Day

  • Engineer advanced authentication, registration, account recovery, profile management, consent, and step-up MFA journeys using PingOne Advanced Identity Cloud.
  • Develop and maintain custom journeys, custom nodes, JavaScript decision logic, validation rules, scripted policies, OIDC claims logic, API integrations, and reusable CIAM components.
  • Customize and support PingOne AIC Hosted Pages, including branding, localization, frontend behavior, reusable themes, input validation, responsive user experiences, and accessibility compliance.
  • Design and implement PingOne Protect capabilities within customer identity flows, including global and application-specific risk policies, standard and custom predictors, composite risk decisions, group mappings, device signals, behavioral signals, registration velocity, compromised credential indicators, and external fraud intelligence.
  • Develop proactive fraud mitigation patterns that can dynamically allow, challenge, step up, throttle, block, or route a customer transaction for additional verification based on evaluated risk.
  • Ability to work with various teams across the business such as Cyber Fraud and business partners.

The Skills & Expertise You Bring

Qualifications

  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, Information Systems, or a related discipline, or equivalent professional experience demonstrating senior-level architecture and engineering depth.
  • Typically 5 ½ or more years of progressive IAM, security engineering, software engineering, platform engineering, or cloud experience, delivering CIAM solutions leading complex technical designs or global application integrations.
  • Demonstrated ownership of customer-facing identity solutions supporting high-volume web, native mobile, SPA, BFF, API, microservice, partner, call-center, and machine-to-machine channels across multiple regions, environments, and business units.
  • Advanced hands-on expertise with PingOne Advanced Identity Cloud SAAS including journey design, nested journeys, custom and scripted decision nodes, authentication levels, session configuration, hosted pages, identity schemas, managed objects, AM/IDM APIs, application policies, OIDC claims scripts, environment promotion, and production troubleshooting.
  • Hands-on experience integrating PingOne Protect automating fraud detection, adaptive-authentication, device intelligence, behavioral analytics, bot detection, identity verification, and external risk signals; able to create predictors and composite policies, tune thresholds, interpret risk evidence, control false positives, and implement allow, challenge, step-up, throttle, block, or manual-review outcomes.
  • Integrate and troubleshoot Ping journey and device-profiling SDKs in JavaScript, React Native, Android, iOS, and Flutter, including callback rendering, browser and deep-link redirects, PKCE verifier persistence, cookie behavior, device identifiers, CORS/CSP, network failures, application lifecycle transitions, token renewal, and diagnostic logging.
  • Demonstrated ability to design and implement coarse- and fine-grained authorization using least-privilege scopes, granular business roles, entitlements, resource/action models, consent, relationship and contextual attributes, JWT access-token claims, policy decision points, policy enforcement points, obligations, deny-by-default behavior, and domain-service ownership boundaries.
  • Strong production coding capability in at least two of Java, JavaScript/TypeScript, Python, Spring, Node.js, React, PowerShell, or shell, with evidence of writing maintainable modules, tests, API clients, migration utilities, validation tools, pipeline automation, operational scripts, and reusable platform accelerators.
  • Advanced REST API engineering skills, including resource and contract design, HTTP semantics, JSON schemas, pagination, filtering, idempotency, retries, rate limits, webhooks and callbacks, authentication headers, error models, correlation IDs, backward compatibility, mocks, Postman collections, negative testing, and automated contract validation against PingOne AIC and downstream services.
  • Strong Splunk and Dynatrace capability, including SPL, field extraction, nested JSON parsing, dashboards, service-level indicators, transaction correlation, alert design, baseline and threshold tuning, distributed tracing, latency segmentation, root-cause analysis, and privacy-aware handling of tokens, credentials, device data, and customer PII.
  • Experience designing and executing high-volume identity and application migrations with batching, checkpointing, restartability, reconciliation, credential migration, schema mapping, exception queues, audit trails, rollback controls, cutover orchestration, coexistence, performance testing, and post-migration verification.
  • Proven CIAM architecture leadership, including facilitation of discovery and whiteboarding sessions with global application, product, domain-service, fraud, cyber, privacy, cloud, network, operations, and vendor teams; able to uncover missing requirements, distinguish an existing pattern from a net-new pattern, challenge unsafe assumptions, and drive decisions to closure.
  • Demonstrated ability to understand customer and business-service processes—registration, authentication, servicing, profile management, account recovery, consent, identity proofing, fraud review, partner access, entitlement, and downstream data access—and translate them into actors, trust boundaries, service ownership, authentication and authorization flows, API contracts, claims, controls, exceptions, and measurable outcomes.
  • Proven delivery leadership under aggressive timelines: rapidly identify the minimum safe scope, reuse approved patterns, size complexity, sequence dependencies, time-box decisions, expose critical-path risks, define accountable owners, create sprint-ready acceptance criteria, secure architecture approvals, and drive work through testing, operational readiness, production release, and stabilization.
  • Ability to operate independently in ambiguity, develop proof-of-concept code and measurable evidence, compare architecture options, document assumptions and trade-offs, make a clear recommendation, escalate unresolved risk, and remain directly engaged through implementation and production validation.
  • Excellent written, verbal, and executive communication skills, including the ability to lead code and design reviews, challenge senior technical stakeholders constructively, explain complex identity and fraud risks in business terms, define precise ownership boundaries, and communicate decisions, residual risk, delivery status, and required actions without ambiguity.

Preferred evidence of qualificatio

Original posting on Pru's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job