Your Job
We are looking for a Lead IAM Engineer to define and evolve Koch’s global identity strategy, architecture, and platforms. This role will serve as a technical leader for authentication, federation, authorization, identity governance, and lifecycle automation across the enterprise, enabling secure access experiences for users, applications, and services worldwide. Working closely with general architects, engineers, security teams, business partners, and customers, this individual will help shape the future of Identity at Koch through modern authentication technologies, Zero Trust principles, and scalable automation.
Our Team
The Koch Technology Identity team provides modern Identity solutions and services for all Koch businesses. We are responsible for the entire enterprise in designing innovative services, creating, and sharing best practices, and providing support for our services.
This role requires an in-office presence in our Zapopan office
What You Will Do
Set IAM architecture & standards: Define reusable patterns for SSO/federation, authorization models,
privileged access, and workload/machine identity.
Lead design governance: Run identity design reviews for new applications and major platform changes; approve patterns, manage exceptions, and drive adoption.
Build authentication & federation: Design and implement SAML2, OAuth2/OIDC, WS-Fed, and FIDO2/passkeys, including adaptive/risk-based auth, conditional access, and MFA.
Engineer IAM platforms: Operate and enhance enterprise identity services (PingOne / PingOne DaVinci or equivalent orchestration platforms).
Lead developer for IAM platforms: Serve as lead developer driving hands-on code development to build, extend, and maintain new and existing identity platforms, including custom connectors, APIs, and orchestration flows.
Design authorization & governance: Build scalable RBAC/ABAC/PBAC models, entitlement catalogs, role engineering, and access request workflows (IGA).
Automate identity lifecy
📌 Lead Identity (Zapopan)
🏢 Koch
📍 Zapopan