We use essential cookies

Please Accept our Privacy Policy

Senior SSO/IAM Engineer

TEKsystems

Denver, CO 80201 • $93.00 / hr • 9/29/2026

Job Description

Job Description
Senior SSO Engineer (Ping Identity)

Location: Denver, CO (Onsite), Jacksonville, FL, Chicago, IL, Charlotte, NC, Addison, TX, and DC

Work Model: 5 days onsite with flexibility once established in the role

Employment Type: 18-Month Contract

Client: Bank of America

Start Date: October 2026

Pay Rate: Up to $93/hour Depending on Experience

About the Role

We are seeking an experienced Senior SSO Engineer with deep expertise in Ping Identity technologies to support a large-scale enterprise authentication environment. This role will focus on designing, implementing, maintaining, and enhancing authentication and access management services that support critical business and security initiatives.

The ideal candidate will bring hands-on experience with PingFederate, PingAccess, and PingDirectory, along with extensive knowledge of modern authentication standards such as SAML, OAuth, OIDC, MFA, and FIDO2.

What You'll DoAuthentication & Identity Engineering
  • Design and implement enterprise authentication solutions using PingFederate, PingAccess, PingDirectory, and related technologies.
  • Collaborate with Identity and Authentication teams to deliver secure and scalable IAM solutions.
  • Contribute to architectural discussions and provide technical expertise for strategic identity initiatives.
  • Identify opportunities to improve authentication services, security controls, and operational processes.
Integration & Implementation
  • Lead application integrations utilizing SAML, OAuth, OpenID Connect (OIDC), MFA, and FIDO2 standards.
  • Configure, customize, and integrate authentication solutions across enterprise applications and platforms.
  • Provide subject matter expertise to SSO Engineering and SSO Integration teams.
  • Develop and manage authentication policies, including policy fragments and advanced access rules.
Security & Compliance
  • Ensure authentication platforms align with enterprise security standards and industry best practices.
  • Support security assessments, vulnerability reviews, and risk mitigation activities related to IAM systems.
  • Contribute to Zero Trust and identity modernization initiatives.
Troubleshooting & Support
  • Investigate and resolve authentication-related issues including:
    • Authentication failures
    • Token management issues
    • Access and authorization challenges
    • MFA and FIDO2 integration issues
  • Perform advanced root cause analysis and implement sustainable solutions.
  • Provide Senior-level technical guidance to engineering teams and stakeholders.
Documentation & Knowledge Sharing
  • Create and maintain technical documentation, implementation procedures, and operational runbooks.
  • Utilize Jira, Confluence, Horizon, or similar platforms to document processes and solutions.
  • Support knowledge transfer and mentorship within the IAM organization.
Required Qualifications
  • 5+ years of hands-on experience supporting enterprise Authentication Services environments.
  • 5+ years of experience with:
    • PingFederate
    • PingAccess
    • PingDirectory
  • 5+ years integrating applications using:
    • SAML
    • OAuth
    • OpenID Connect (OIDC)
    • FIDO2
  • Strong experience creating and implementing authentication and authorization policies.
  • Deep understanding of Single Sign-On (SSO) technologies and enterprise authentication architectures.
  • Excellent troubleshooting, analytical, and problem-solving skills.
  • Strong written and verbal communication skills.
  • Ability to work independently and collaborate with cross-functional teams.
Preferred Qualifications
  • Experience with policy fragments within Ping Identity solutions.
  • Experience supporting large-scale banking, financial services, or highly regulated environments.
  • Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience).
Why Join This Opportunity?
  • Work within a massive enterprise identity environment.
  • Exposure to Senior leadership and strategic security initiatives.
  • Contribute to Zero Trust and modern identity transformation programs.
  • Support critical cybersecurity and regulatory compliance objectives.
  • Opportunity for professional growth within a mature security organization.
Interview Process
  1. Microsoft Teams video interview
  2. In-person interview with the local team
Compensation
  • Contract Rate: $93/hour
  • Duration: 18 months

We reserve the right to pay above or below the posted wage based on factors unrelated to sex, race, or any other protected classification.

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms.This temporary role may be eligible for the following:

  • Medical, dental & vision
  • 401(k)/Roth
  • Insurance (Basic/Supplemental Life & AD&D)
  • Short and long-term disability
  • Health & Dependent Care Spending Accounts (HSA & DCFSA)
  • Transportation benefits
  • Employee Assistance Program
  • Time Off/Leave (PTO, Vacation or Sick Leave)
Job Type & Location

This is a Contract position based out of Denver, CO.

Pay and Benefits

The pay range for this position is $93.00 - $93.00/hr.

Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: Medical, dental & vision Critical Illness, Accident, and Hospital 401(k) Retirement Plan Pre-tax and Roth post-tax contributions available Life Insurance (Voluntary Life & AD&D for the employee and dependents) Short and long-term disability Health Spending Account (HSA) Transportation benefits Employee Assistance Program Time Off/Leave (PTO, Vacation or Sick Leave)

Workplace Type

This is a fully onsite position in Denver,CO.

Application Deadline

This position is anticipated to close on Oct 2, 2026.

About TEKsystems

We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.

The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

About TEKsystems and TEKsystems Global Services

Were a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. Were a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. Were strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. Were building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.

The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.

Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.