SonicJobs Logo
Left arrow iconBack to search

Principal Identity Architect

Publicis Groupe Holdings B.V
Posted 3 months ago, valid for 15 days
Location

Irving, TX 75059, US

Salary

$127,900 - $237,500 per year

Contract type

Full Time

Paid Time Off
Tuition Reimbursement

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Principal Identity Architect at Epsilon will lead the organization's identity modernization program, transitioning from legacy systems to a modern OAuth 2.1/OpenID Connect framework.
  • Candidates should have at least 7 years of experience in identity and access management, with a minimum of 3 years of hands-on experience with OAuth 2.0/OpenID Connect in production environments.
  • The role involves designing secure token flows, mentoring peers, and partnering with various teams to enhance identity governance and observability.
  • The position offers a salary range of $127,900 to $237,500 annually, depending on the candidate's qualifications and experience.
  • Ideal candidates will possess strong communication skills and a solid understanding of cloud-native identity across major platforms like AWS, GCP, or Azure.

Overview

As a Principal Identity Architect, you will lead Epsilon’s identity modernization—transitioning from legacy SAML and long-lived credentials to a modern, OAuth 2.1 / OpenID Connect (OIDC)-first model. You’ll design secure, scalable identity patterns across multi-cloud environments while enabling teams to build with speed and confidence.

 

You’ll partner closely with Security, Cloud, Platform, and Engineering teams to replace API keys and service accounts with scoped, ephemeral machine identities, establish enterprise standards, and deliver secure, developer-friendly integrations.

 

This is a hands-on leadership role for someone who can drive strategy, mentor engineers, and turn architecture into real-world implementations.

Responsibilities

What You’ll Acheive

Modern Identity Architecture

  • Lead adoption of OAuth 2.1 / OIDC; drive migration from SAML and legacy auth
  • Design secure token flows (Auth Code + PKCE, Client Credentials, delegated access)
  • Define standards for token usage, scopes, claims, and lifecycle management
  • Reduce risk from token leakage, replay, and over-permissioning

Machine & Non-Human Identity

  • Replace long-lived credentials with modern machine identity patterns
  • Design M2M authentication for APIs, data pipelines, and platform workloads
  • Partner with teams on service account migration and secrets reduction

Platform & Integration Engineering

  • Build reusable identity patterns across IdPs, API gateways, and cloud platforms
  • Enable secure, scalable access across AWS, Azure, and/or GCP
  • Troubleshoot complex auth issues in hybrid and multi-cloud environments

Security, Governance & Observability

  • Apply Zero Trust principles (least privilege, scoped access)
  • Improve identity logging, monitoring, and audit readiness
  • Establish governance for OAuth apps, scopes, and access policies

Leadership & Delivery

  • Drive identity modernization programs end-to-end
  • Mentor architects and engineers; set technical standards
  • Break down complex initiatives into actionable workstreams
  • Lead incident response and improve operational visibility

Qualifications

Who you Are

What you’ll Bring with you

  • Bachelors or Masters in Computer Science or related field.
  • 7+ years in IAM, security engineering, or platform roles
  • 3+ years hands-on with OAuth 2.0 / OIDC in production
  • Strong expertise in token flows, scopes, claims, and secure design patterns
  • Experience implementing machine identity (M2M, workload identity, etc.)
  • Track record of modernizing identity (SAML → OIDC or similar)
  • Experience with AWS, Azure, or GCP identity services
  • Ability to lead initiatives, influence teams, and deliver at scale

 

How you’ll Stand out from other Talent

  • Experience with API security, data platforms, or service-to-service auth at scale
  • Familiarity with SPIFFE/SPIRE, OPA, or advanced authorization models
  • Experience with Okta, Entra ID (Azure AD), Auth0, or Ping
  • Exposure to AI/agent-based identity patterns
  • Scripting or automation (Python, Bash)

Click here to view how Epsilon transforms marketing with 1 View, 1 Vision, 1 Voice.

Additional Information

When you join Epsilon, we’ll create something EPIC together. We’re a global leader in data and identity, with deep expertise in digital media, clean rooms, customer data platforms, loyalty and marketing services. Positioned at the center of Publicis Groupe, Epsilon helps brands deliver personalized experiences at scale and build lasting customer relationships by unlocking the full potential of data and identity. Epsilon operates in 30+ countries across EMEA, the Americas and APAC, with more than 8,000 employees.

 

Check out a few of these resources to learn more about what makes Epsilon so EPIC:

 

Our Culture: https://www.epsilon.com/us/about-us/our-culture-epsilon

Life at Epsilon: https://www.epsilon.com/us/about-us/epic-blog

 

Epsilon has five values that define our culture and guide us as we create value for our clients, our people and consumers. We seek candidates who align with our company values, demonstrate them and make them meaningful in their day-to-day work:

  • Act with integrity. We are transparent and have the courage to do the right thing.
  • Work together to win together. We believe collaboration is the catalyst that unlocks our full potential.
  • Innovate with purpose. We shape the market with big ideas that drive big outcomes.
  • Respect all voices. We embrace differences and foster a culture of connection and belonging.
  • Empower with accountability. We trust each other to own and deliver on common goals.

 

Because You Matter

As an Epsilon employee, you deserve perks and benefits that put you, your family and your finances first. Our benefits encompass a wide range of offerings, including but not limited to:

  • Time to recharge: Flexible time off (FTO), 14 paid holidays, paid sick time
  • Family well-being: Parental/new child leave, childcare & elder care assistance, adoption assistance
  • Extra perks: Comprehensive health coverage, 401(k), tuition assistance, commuter benefits, professional development, employee recognition, charitable donation matching, health coaching and counseling

Epsilon benefits are subject to eligibility requirements and other terms.

 

Epsilon is an Equal Opportunity Employer. Epsilon’s policy is not to discriminate against any applicant or employee based on actual or perceived race, age, sex or gender (including pregnancy), marital status, national origin, ancestry, citizenship status, mental or physical disability, religion, creed, color, sexual orientation, gender identity or expression (including transgender status), veteran status, genetic information or any other characteristic protected by applicable federal, state or local law. Epsilon also prohibits harassment of applicants and employees based on any of these protected categories. Epsilon will provide accommodations to applicants who need accommodations to complete the application process. Please reach out to LeaveofAbsence@epsilon.com to request an accommodation.

 

For San Francisco Bay and Los Angeles Areas: Epsilon will consider qualified applicants with criminal histories for employment in a manner consistent with the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance and San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance. Applicants with criminal histories are welcome to apply. 

#LI-TG1

 

Compensation Range: USD $127,900.00 - USD $237,500.00/Annually. This is the pay range the Company believes it will pay for this position at the time of this posting. Consistent with applicable law, compensation will be determined based on the skills, qualifications, and experience of the applicant along with the requirements of the position, and the Company reserves the right to modify this pay range at any time. Temporary roles may be eligible to participate in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been met. For regular roles, the Company will offer medical coverage, dental, vision, disability, 401k, and paid time off. The Company anticipates the application deadline for this job posting will be 10/12/2026.



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.