Ping Identity Engineer
- west of england, england, United Kingdom
- £758 - £895 Per Hour
Job Description
Job Title: Senior Ping Identity Engineer
Job Description
This role focuses on designing, building and securing a new UK-hosted identity platform to support a major identity separation and security modernisation programme. You will design and implement a new internet-facing PingFederate environment, integrate multi-factor authentication across critical services, and support Active Directory domain separation from a global shared environment to a locally managed UK platform. You will ensure identity services are resilient, compliant and aligned with UK-hosted infrastructure requirements, while improving user experience and supporting robust governance and documentation.
Responsibilities
- Design, build and configure a new UK-hosted PingFederate environment to support secure authentication services.
- Deploy internet-facing PingFederate services within a DMZ, ensuring robust security and resilience.
- Design secure trust relationships between the UK PingFederate platform and existing corporate Ping environments.
- Configure SAML and OpenID Connect integrations to support application migrations onto the new identity platform.
- Support the implementation and optimisation of PingFederate, PingID and PingDirectory across the environment.
- Implement Ping-based multi-factor authentication across business-critical applications to strengthen access security.
- Integrate multi-factor authentication capabilities with CyberArk privileged access workflows.
- Enable MFA-protected break-glass access to critical servers to support secure emergency access scenarios.
- Support MFA integration for Cisco network device administration to secure network management access.
- Migrate existing MFA solutions and proof-of-concept implementations into the strategic Ping platform.
- Support identity consolidation and migration activities as part of the transition to UK-hosted services.
- Assist with Active Directory migration from .COM to .NET domains, ensuring secure and seamless transitions.
- Enable secure authentication for migrated users, applications and servers across the new platform.
- Align identity services and configurations with UK-hosted infrastructure requirements and standards.
- Implement self-service MFA credential management capabilities to improve user autonomy and reduce support overhead.
- Develop and enhance user onboarding and identity lifecycle processes to improve consistency and control.
- Support identity tagging and provisioning workflows to ensure accurate and efficient access management.
- Produce clear and comprehensive Standard Operating Procedures to support ongoing operations.
- Create Standard Work documentation to enable effective operational handover and support.
- Review and improve existing runbooks and operational processes to align with the new identity platform.
- Align global identity configurations and standards to ensure consistency and compliance across environments.
Essential Skills
- Strong, hands-on experience with Ping Identity technologies, including PingFederate, PingID, PingDirectory and PingDataSync.
- In-depth knowledge of SAML 2.0, OAuth 2.0 and OpenID Connect protocols.
- Proven experience designing and deploying multi-factor authentication architectures.
- experience with Active Directory integration and migration, including domain separation activities.
- Practical experience with RADIUS authentication services.
- experience integrating identity platforms with CyberArk for privileged access management.
- Strong understanding of DMZ and internet-facing authentication architectures.
- Solid background in Identity and Access Management (IAM) principles and practices.
- Ability to produce high-quality technical documentation, including SOPs, runbooks and standard work.
- experience working with Windows Server and enterprise authentication technologies.
- experience working with Cisco network environments in the context of secure access and MFA.
Additional Skills & Qualifications
- experience in large-scale identity consolidation and migration programmes.
- Exposure to identity lifecycle management, including user onboarding, provisioning and deprovisioning.
- Familiarity with designing and implementing self-service credential management capabilities.
- experience aligning identity services with regional or local infrastructure and regulatory requirements.
- Strong analytical and problem-solving skills, with the ability to troubleshoot complex authentication issues.
- Clear communication skills, with the ability to collaborate effectively with security, infrastructure and application teams.
Why Work Here?
You will join a world-leading engineering and technology organisation that invests heavily in modern, secure digital platforms. The environment encourages innovation, continuous improvement and the adoption of best-in-class security practices. You will have the opportunity to work on a high-profile transformation programme, collaborate with skilled professionals and develop your expertise in cutting-edge identity and access management technologies.
Work Environment
You will work within a modern enterprise environment focused on secure, UK-hosted infrastructure and advanced identity services. The role involves working with technologies such as PingFederate, PingID, PingDirectory, PingDataSync, CyberArk, Active Directory, RADIUS, Windows Server and Cisco network devices. You will operate in a security-conscious setting with internet-facing services deployed in a DMZ, following structured operational processes supported by SOPs and runbooks. The work pattern and specific hours may vary according to project needs, with a strong emphasis on reliability, documentation and collaboration across security, infrastructure and application teams.
Location
Bristol, UK
Rate/Salary
550.00 - 650.00 GBP Hourly
#J-18808-Ljbffr

