Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Federated Authentication Engineer - OESIS Framewor

Home > Other programming jobs

Federated Authentication Engineer - OESIS Framewor in Others new

  • Ho Chi Minh City, Vietnam

Responsibilities

  • Design and implement OAuth2 and OIDC authentication flows for third-party enterprise platforms.
  • Implement SAML 2.0 federation for enterprise SSO passthrough scenarios.
  • Build secure multi-tenant credential and token storage with rotation using secrets managers.
  • Design passthrough authentication so the embedded SDK connects directly to each customer’s device-management tenant without OPSWAT storing or proxying raw credentials.
  • Implement token refresh, expiry, revocation, and re-authentication logic for long-running query pipelines.
  • Define least-privilege scopes and support certificate-based authentication and mutual TLS.
  • Support customer onboarding through app registration, consent, API client setup, and role or privilege configuration.

Requirements

  • At least 3 years of identity and access engineering experience with hands-on OAuth2, OIDC, and SAML 2.0; SCIM is preferred.
  • Direct experience with Microsoft Entra ID app registrations and Graph API authentication flows.
  • Experience implementing OAuth2 client-credentials flows against third-party enterprise APIs such as CrowdStrike Falcon or JAMF Pro.
  • Strong understanding of token lifecycle management, including refresh tokens, expiry, revocation, and scope or claim design.
  • Experience with secrets management and secure credential storage in multi-tenant SaaS environments.
  • Familiarity with certificate-based authentication, mutual TLS, and client certificates.
  • Working knowledge of common authentication vulnerabilities, including token leakage, replay attacks, and scope creep.
  • Experience with passthrough or delegated authentication architectures for OEM or SDK products is preferred.
  • Background with enterprise IAM tools such as Okta, Ping Identity, or Entra ID, or with CIAM, is preferred.
  • Familiarity with ZTNA, device posture or compliance, security certifications such as CISSP or OSCP, cybersecurity, software development, and compliance frameworks is preferred.

Benefits

  • Work with the mission-driven OESIS Framework team on technology that protects critical infrastructure.
  • OPSWAT promotes innovation, collaboration, and continuous development.
  • OPSWAT is an equal opportunity employer committed to a diverse, discrimination-free workplace.

OPSWAT

OPSWAT protects critical infrastructure. Our goal is to eliminate malware and zero-day attacks. We believe that every file and every device pose a threat. Threats must be addressed at all locations at all times—at entry, at exit, and at rest. Our products focus on threat prevention and process cr...

Similar positions

Senior Test Automation Engineer

  • City of New York
  • Full time
  • USA
  • 09/13/2026
  • Brooklyn, NY

Backend Engineer, Security Platform

  • Vannevar
  • Full time
  • USA
  • 09/13/2026
  • Salary: $150k - $215k/yr
  • Remote

Agentic Security Engineer

  • NXP Semiconductors
  • Full time
  • USA
  • 09/13/2026
  • Austin, TX

Sr Application Security Engineer

  • Henry Schein One
  • Full time
  • USA
  • 09/13/2026
  • Salary: $125k-$160k
  • Remote

Senior DevOps Engineer, Infrastructure & Reliabili

  • Worth AI
  • Full time
  • USA
  • 09/13/2026
  • Remote