Posted on: 09/01/2026
Job Overview :
We are seeking a highly skilled IAM Expert with deep hands-on experience in Auth0 and Kong API Gateway to design, implement, and manage secure identity, authentication, authorization, and API access strategies across cloud-native platforms. This role is critical in enabling secure, scalable, and compliant access for users, services, and APIs in a microservices-driven ecosystem.
You will work closely with platform engineering, application teams, DevSecOps, and compliance stakeholders to ensure best-in-class identity and API security architecture.
Key Responsibilities :
Identity & Access Management (IAM) :
- Design and implement an end-to-end IAM architecture using Auth0 for customer, workforce, and machine-to-machine identities.
- Configure and manage OAuth 2.0, OpenID Connect (OIDC), SAML, and JWT-based authentication flows.
- Implement RBAC, ABAC, and fine-grained authorization models across applications and APIs.
- Manage user lifecycle, federation, social logins, enterprise identity providers, and MFA strategies.
- Customize Auth0 Rules, Actions, Hooks, and Custom Domains to meet business and security requirements.
API Security & Gateway (Kong) :
- Design and manage API security architecture using Kong Gateway (OSS/Enterprise).
- Implement JWT, OAuth2, OIDC, mTLS, API keys, and rate limiting using Kong plugins.
- Integrate Auth0 with Kong to provide centralized API authentication and authorization.
- Secure north-south and east-west traffic for microservices.
- Implement API policies for throttling, quotas, logging, and abuse prevention.
Cloud & Microservices Security :
- Secure microservices running on Kubernetes using identity-aware access patterns.
- Implement service-to-service authentication using OAuth2, mTLS, or SPIFFE-like models.
- Integrate IAM with CI/CD pipelines to secure secrets and tokens and enable automated deployments.
- Work across AWS, Azure, or GCP IAM ecosystems and align Auth0/Kong with cloud-native services.
Compliance & Governance :
- Ensure IAM and API security designs comply with HIPAA, SOC 2, ISO 27001, GDPR, or similar standards.
- Define audit logging, access reviews, token rotation, and zero-trust principles.
- Participate in security reviews, threat modeling, and incident response related to identity or API access.
Collaboration & Leadership :
- Act as an IAM subject-matter expert (SME) across engineering teams.
- Provide guidance, documentation, and best practices for developers and DevOps teams.
- Mentor junior engineers on IAM, API security, and zero-trust architecture.
Required Skills & Experience :
Core Technical Skills :
- 6+ years of experience in Identity & Access Management
- Strong hands-on expertise with Auth0 (production-scale deployments)
- Strong hands-on expertise with Kong API Gateway
- Deep understanding of :
1. OAuth 2.0, OIDC, SAML
2. JWT, refresh tokens, token introspection
3. MFA, passwordless authentication, social & enterprise federation
- Experience designing secure API authentication and authorization patterns
Platform & DevOps:
- Experience with Kubernetes, Docker, and microservices architecture
- Familiarity with CI/CD pipelines (GitHub Actions, GitLab CI, Azure DevOps, etc.)
- Experience with Secrets Management (Vault, cloud key vaults, etc.)
- Strong understanding of TLS, mTLS, certificates, and encryption best practices
Cloud & Tools:
- Experience with AWS / Azure / GCP
- Exposure to IAM integration with cloud services
- Logging & monitoring using tools like Prometheus, Grafana, ELK, Datadog, etc.
Good to Have:
- Auth0 certifications or Kong Enterprise experience
- Experience with Zero Trust Architecture
- Knowledge of OPA (Open Policy Agent) or policy-as-code
- Experience with B2B, B2C, or SaaS identity platforms
- Prior experience in healthcare, fintech, or regulated environments
Soft Skills:
- Strong problem-solving and security mindset
- Excellent communication and documentation skills
- Ability to collaborate across engineering, security, and product teams
- Ownership mentality and attention to detail
Additional Requirements:
- Can start immediately
- Accept a background check
- 5+ years of work experience with Kong API Gateway
- 5+ years of work experience with Authentication Systems
Did you find something suspicious?
Posted by
Manjiri Kavatkar
Assistant Manager - HR & Operations at Pscope Technologies Private Limited
Last Active: 9 Jan 2026
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1599465