CIAM Principal Engineer- post

💰 $8,960 - $14,336 (Est.) 📍 Chicago

Job Description

Introduction

Welcome to Gallagher - a global community of people who bring bold ideas, deep expertise, and a shared commitment to doing what’s right. We help clients navigate complexity with confidence by empowering businesses, communities, and individuals to thrive. At Gallagher, you’ll find more than a job; you’ll find a culture built on trust, driven by collaboration, and sustained by the belief that we’re better together. Whether you join us in a client-facing role or as part of our brokerage division, our benefits and HR consulting division, or our corporate team, you’ll have the opportunity to grow your career, make an impact, and be part of something bigger. Experience a workplace where you’re encouraged to be yourself, supported to succeed, and inspired to keep learning. That’s what it means to live The Gallagher Way.

Overview

The CIAM Principal Engineer (Ping Identity) serves as the senior technical authority responsible for designing, building, and optimizing secure and scalable customer identity solutions leveraging the Ping Identity platform.
This role combines deep technical expertise in Ping products with strategic architecture leadership, enabling frictionless, secure customer experiences across web, mobile, and API ecosystems. The Principal Engineer partners with enterprise architects, product teams, and cybersecurity leaders to deliver a modern, standards-based CIAM ecosystem aligned with business growth, regulatory requirements, and Zero Trust principles.


How you'll make an impact

Key Responsibilities
Architecture & Design
Lead the architecture and engineering of enterprise-grade CIAM solutions using the Ping Identity suite — including PingOne, PingFederate, PingAccess, PingDirectory, PingVerify, PingAuthorize, DiVinci and PingCentral.
Define reference architectures, design blueprints, and integration patterns for customer authentication, authorization, and identity lifecycle management.
Architect and implement federated identity solutions and single sign-on (SSO) leveraging OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, SCIM, and FIDO2, in partnership with Cyber Architecture Team.
Design for multi-region scalability, high availability, and fault tolerance across hybrid or multi-cloud environments.
Ensure architectures align with Zero Trust principles, privacy-by-design, and global data protection regulations (GDPR, CCPA, etc.).
Engineering & Implementation
Lead hands-on development and integration of Ping Identity components within customer-facing applications and APIs.
Configure and extend PingFederate for token services, authentication policies, and adapter integrations.
Implement PingAccess for API and web session management, policy enforcement, and adaptive access control.
Deploy and tune PingDirectory for large-scale customer identity storage and replication.
Automate CIAM deployment pipelines using PingCentral, Terraform, and CI/CD tools (Jenkins, GitLab CI).
Integrate Ping Identity solutions with customer portals, mobile apps, CRM systems, and marketing platforms.
Develop custom adapters, plugins, and scripts to extend Ping capabilities where required.
Security, Governance & Compliance
Define and enforce identity security standards for authentication flows, token handling, session management, and encryption.
Partner with cybersecurity teams to embed Ping Identity telemetry into SIEM and behavioral analytics systems.
Conduct threat modeling and architecture reviews for all customer identity initiatives.
Maintain compliance with industry and privacy frameworks (NIST CSF, ISO 27001, GDPR, PCI DSS).
Implement adaptive authentication, risk-based access, and fraud detection integrations with Ping’s Intelligent Identity features or third-party tools.
Leadership & Collaboration
Act as the technical lead and subject matter expert (SME) for all Ping-based CIAM initiatives.
Mentor CIAM engineers and developers in Ping Identity best practices and secure identity design.
Collaborate with enterprise and cyber security architects, DevOps, and application teams to embed security-by-design into customer solutions.
Work with vendors and Ping Identity professional services to influence roadmap alignment and solution optimization.
Represent the CIAM team in technical design reviews, architecture boards, and security governance forums.
Innovation & Continuous Improvement
Drive innovation in passwordless authentication, FIDO2/WebAuthn, and decentralized identity using PingOne capabilities.
Evaluate and pilot new Ping Identity cloud-native offerings (e.g., PingOne Advanced Identity Cloud, PingOne Risk, PingOne DaVinci).
Optimize existing Ping deployments for performance, scalability, and maintainability.
Develop a multi-year CIAM technology roadmap that aligns Ping Identity solutions with evolving business and security needs.

About You

Required:


Typically requires a University Degree and minimum 10 years of prior relevant experience, or equivalent experience.

Preferred:

Experience
10+ years in Identity and Access Management (IAM), including 5+ years specializing in CIAM.
5+ years of direct, hands-on experience implementing Ping Identity solutions in customer-facing environments.
Proven experience designing and deploying PingFederate, PingAccess, and PingDirectory in hybrid or cloud environments.
Expertise in OAuth 2.0, OIDC, SAML, SCIM, FIDO2, and JWT-based identity flows.
Strong understanding of cloud architectures (AWS, Azure, or GCP) and container orchestration (Kubernetes, Docker).
Demonstrated success leading large-scale identity transformation projects or migrations to Ping Identity.
Technical Skills
PingFederate / PingAccess / PingDirectory / PingOne / PingCentral
REST / GraphQL API design and security
SSO and federation standards
Directory services (LDAP, Active Directory, cloud directories)
Application integration using SDKs, APIs, and adapters
Infrastructure-as-Code (Terraform, CloudFormation)
CI/CD tools (Jenkins, GitLab CI/CD, ArgoCD)
Scripting languages: Python, Java, PowerShell, or Groovy
TLS, PKI, and token-based encryption management
Soft Skills
Excellent communication and stakeholder management skills.
Ability to translate complex identity concepts into business-friendly terms.
Strong leadership, mentoring, and influencing abilities across technical teams.
Detail-oriented with a focus on resilience, scalability, and usability.
Passionate about customer experience and continuous improvement.
Certifications (Preferred)
Ping Identity Certified Professional / PingFederate Specialist
CISSP, CISM, or CIAM Professional
Cloud Security certifications (AWS Security Specialty, Azure Security Engineer, etc.)
FIDO2 / WebAuthn implementation experience
Success Metrics
Secure, seamless customer login and registration experiences.
Measurable reduction in authentication friction and abandonment rates.
Increased adoption of strong authentication (MFA, passwordless).
Improved CIAM uptime, performance, and scalability.
Compliance with data protection and privacy regulations.
Accelerated delivery of identity capabilities through automation and CI/CD integration.

Compensation and benefits


We offer a competitive and comprehensive compensation package. The base salary range represents the anticipated low end and high end of the range for this position. The actual compensation will be influenced by a wide range of factors including, but not limited to previous experience, education, pay market/geography, complexity or scope, specialized skill set, lines of business/practice area, supply/demand, and scheduled hours. On top of a competitive salary, great teams and exciting career opportunities, we also offer a wide range of benefits.

Below are the minimum core benefits you’ll get, depending on your job level these benefits may improve:

Medical/dental/vision plans, which start from day one!
Life and accident insurance
401(K) and Roth options
Tax-advantaged accounts (HSA, FSA)
Educational expense reimbursement
Paid parental leave
Other benefits include:
Digital mental health services (Talkspace)
Flexible work hours (availability varies by office and job function)
Training programs
Gallagher Thrive program – elevating your health through challenges, workshops and digital fitness programs for your overall wellbeing
Charitable matching gift program
And more...
The benefits summary above applies to fulltime positions. If you are not applying for a fulltime position, details about benefits will be provided during the selection process.

We value inclusion and diversity

Click Here to review our U.S. Eligibility Requirements

Inclusion and diversity (I&D) is a core part of our business, and it’s embedded into the fabric of our organization. For more than 95 years, Gallagher has led with a commitment to sustainability and to support the communities where we live and work.

Gallagher embraces our employees’ diverse identities, experiences and talents, allowing us to better serve our clients and communities. We see inclusion as a conscious commitment and diversity as a vital strength. By embracing diversity in all its forms, we live out The Gallagher Way to its fullest.

Gallagher believes that all persons are entitled to equal employment opportunity and prohibits any form of discrimination by its managers, employees, vendors or customers based on race, color, religion, creed, gender (including pregnancy status), ****** orientation, gender identity (which includes transgender and other gender non-conforming individuals), gender expression, hair expression, marital status, parental status, age, national origin, ancestry, disability, medical condition, genetic information, veteran or military status, citizenship status, or any other characteristic protected (herein referred to as “protected characteristics”) by applicable federal, state, or local laws.

Equal employment opportunity will be extended in all aspects of the employer-employee relationship, including, but not limited to, recruitment, hiring, training, promotion, transfer, demotion, compensation, benefits, layoff, and termination. In addition, Gallagher will make reasonable accommodations to known physical or mental limitations of an otherwise qualified person with a disability, unless the accommodation would impose an undue hardship on the operation of our business.

💡 Quick Summary

Seeking a career-building opportunity? The CIAM Principal Engineer- post position is now open for candidates interested in the IT Engineer & Developer Jobs sector. This role in Chicago offers a professional environment and growth potential.

Requirement Snapshot: Candidates should possess basic communication skills, a proactive attitude, and the ability to work in a team. Experience in IT Engineer & Developer Jobs is a plus.

Sponsored

Job Details

Company Name: Gallagher

Frequently Asked Questions

Click the Apply Now button on this page, login or register for free on CallCenterJob.co.in, fill in your name, mobile number, city, and experience, then submit your application. The recruiter will contact you directly.
The expected salary for CIAM Principal Engineer- post in Chicago is $8,960 - $14,336 (Est.) per month. Actual compensation may vary based on experience and negotiation.
No, CIAM Principal Engineer- post is an on-site position based in Chicago. Candidates must be able to commute or relocate to this location.
Basic communication skills, a proactive attitude, and the ability to work in a team are required for CIAM Principal Engineer- post. Previous experience in IT Engineer & Developer Jobs is a plus. Freshers may also apply depending on the employer's requirements.
Yes, CallCenterJob.co.in is completely free for job seekers. Never pay money to apply for any job. If anyone asks for payment to process your application, report it immediately using the "Report this Job" button.

Similar Openings

  • HR Lead

    Resillion is a global company with end-to-end capabilities: no matter your industry, your geographical location, or stage in your digital journey. With offices in North America, Europe, and Asia, Resillion will be by your side. Helping you and your o...

    Full Time / Part Time

    Salary Estimated: 24K to 27K

    Remote

    August 7, 2026


    Apply Now

  • BACKDOOR FOR FRESHERS

    We have openings in Software IT. Front-End Web Developer ,Cyber Security,Java, Dotnet, Testing,Pega,Python, Devops,AWS , SAP ABAP, SAP CRM, SAP FICO, SAP SD and SAP Basis etc, We provide all genuine software IT related jobs through backdoor process, ...

    Full Time / Part Time

    Salary Estimated: 22K to 29K

    Hyderabad, Andhra Pradesh

    August 7, 2026


    Apply Now

  • Junior Fit-Out Engineer / Junior Engineer

    Job Overview We are looking for a Junior Engineer to assist in the execution of interior fit-out projects. The ideal candidate will support site activities, coordinate with vendors and contractors, and ensure that all works are completed within timel...

    Full Time / Part Time

    Salary Estimated: 23K to 28K

    New Delhi, Delhi

    August 7, 2026


    Apply Now

  • IT Support Technician

    No district employee or student shall be subjected to discrimination in employment or any district program or activity on the basis of age, color, disability, gender, gender identity, genetic information, national origin, pregnancy, race, religion, s...

    Full Time / Part Time

    Salary Estimated: 16K to 31K

    South Salt Lake, Utah

    August 7, 2026


    Apply Now

  • Mailroom Lead

    JOB SUMMARY: Under the direction of the Operations Manager this position is responsible for the booking/processing of service maintenance agreements, changes and cancellations and the maintenance of the service tasking data base for the Southern Cali...

    Full Time / Part Time

    Salary Estimated: 18K to 27K

    Remote

    August 7, 2026


    Apply Now

  • Senior Lead Engineer - Development

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor's Degree Travel Percentage : 0%Senior Lead Engineer - Development (C#, ASP.net with MVC) As the world works and lives faster, FIS...

    Full Time / Part Time

    Salary Estimated: 15K to 26K

    Pune, Maharashtra

    August 7, 2026


    Apply Now