Role: Senior Identity & SSO Engineer (Auth0)
Role: Remote (USA)
Duration: 3+ months
Visa: C2H (USC)
Responsibilities:
• Configure Auth0 Applications (SAML, OIDC) for new sponsor onboardings (Next-gen member onboarding platform - OB3 pipeline)
• Execute OB2 $B*(J Auth0 SSO migrations per sponsor, including testing and cutover
• Build and maintain new SSO integrations (e.g., HCSC connections, PingFederate, Lynx SP)
• Manage SSO certificate renewals and rotation schedules
• Troubleshoot and resolve SSO outages (Auth0 logs, SAML trace, connection debugging)
• Maintain Auth0 tenant configuration as code (YAML/JSON exports, GitHub-managed)
• Support Auth0 Post-Login Actions development and maintenance
Required Skills:
• Must have: Auth0 platform (tenant config, Applications, Connections, Actions, Rules)
• Must have: SAML 2.0 protocol (SP-initiated, IdP-initiated, metadata exchange, certificate management)
• Must have: OIDC / OAuth 2.0 (authorization code flow, PKCE, token handling)
• Must have: Node.js or TypeScript (for Auth0 Actions and proxy services)
• Should have: MongoDB (user profile store), Next.js/React (OB3 frontend awareness)
• Nice to have: PingFederate, Azure AD B2C, Okta (for federated IdP integrations)
• Nice to have: Experience with enterprise SSO onboarding at scale (50+ SAML connections)
KPIs:
• New sponsor SSO integrations delivered within agreed timelines
• Certificate renewals completed with zero outage
• Mean time to resolve SSO incidents < 4 hours