Lead Information Security Engineer, Authentication

USAA

Confirmed live today High trust
Closes in 2 days Remote

Quick summary

Work type
Remote
Location
Plano Legacy, TX
Salary
$142,320–$273,930 / yr
Employment
Full-time
Posted
2 days ago
Freshness
Confirmed live today
Closes
Oct 13, 2026 (soon)

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $182k
This role $208k
$117k $291k
below market most similar roles pay here above market

This role pays more than 74% of similar roles. Most pay $154,450–$208,800 — the blue band above. At the midpoint, this role pays about $208k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About USAA

USAA (United Services Automobile Association) is a San Antonio-based Fortune 500 financial services company founded in 1922, dedicated to providing insurance, banking, and investment solutions exclusively to U.S. military members, veterans, and their families.

USAA currently has 51 open roles on FindRole.

Listed pay typically runs $127,310–$243,340 across 35 roles with salary data.

Most-posted roles

View all roles at USAA

At a glance

TL;DR · Lead Information Security Engineer, Authentication

The Lead Information Security Engineer - Authentication serves as a senior technical leader responsible for the architecture, engineering, and strategic direction of enterprise authentication and privileged access management capabilities. This role involves leading the design and modernization of workforce identity services, ensuring secure and scalable access solutions across the enterprise. Key responsibilities include designing, developing, coding, and testing complex cross-functional technical solutions, performing code reviews, and resolving production issues. The position requires hands-on expertise with Okta Workforce Identity Engine, Microsoft Entra ID, Active Directory, ADFS, SAML, OIDC, OAuth, MFA, and passwordless authentication. The engineer will establish authentication standards and engineering patterns within a Zero Trust environment, addressing complex identity provider implementations and federation architectures to solve critical security and compliance challenges across large application environments.

What you'll do

  • Lead the architecture, engineering, and strategic direction of enterprise authentication and privileged access management.
  • Design and modernize workforce identity services using platforms like Okta, Microsoft Entra ID, and Active Directory.
  • Implement authentication integrations using SAML, OIDC, OAuth, MFA, and passwordless authentication protocols.
  • Establish authentication standards, reference architectures, and technical roadmaps within a Zero Trust environment.
  • Design, develop, code, integrate, and test complex cross-functional technical solutions with a focus on security.
  • Resolve complex production issues and lead troubleshooting for end-to-end solutions spanning multiple systems.
  • Monitor and troubleshoot highly complex systems, tools, and vendor integrations.
  • Provide mentorship and guidance to junior engineers to foster a culture of continuous learning.

What we're looking for

  • Bachelor's degree or 4 years of relevant education and/or experience.
  • 8 years of related experience in Security Engineering and/or Information Technology with a security focus.
  • Experience leading company-wide technology projects or initiatives.
  • Experience architecting and supporting enterprise authentication solutions using Okta Workforce Identity Engine, Microsoft Entra ID, Active Directory, and ADFS.
  • Experience designing and implementing authentication integrations using SAML, OIDC, OAuth, and other federation protocols.
  • Experience implementing MFA, adaptive authentication, risk-based access controls, passwordless authentication, and Zero Trust security principles.
  • Experience defining authentication standards, reference architectures, engineering patterns, and technical roadmaps.
  • Ability to work on-site four days per week if residing within a 60-mile radius of a USAA office.

More like this

Similar roles

ICAM Identity Provider (IdP) Engineer, Enterprise Authentication Services

General Dynamics

Remote (Falls Church, VA) 64 days ago $170,000–$230,000
Active Directory Domain Services (AD DS) SAML 2.0 OAuth 2.0 OpenID Connect (OIDC) Microsoft Entra ID Identity and Access Management (IAM) Multi-Factor Authentication (MFA) Single Sign-On (SSO) PKI Certificate-based Authentication LDAP PowerShell Docker Kubernetes Zero Trust Architecture WS-Federation JWT PingFederate Okta
8+ yrs exp Remote

ICAM Identity Provider (IdP) Engineer, Enterprise Authentication Services

General Dynamics

Fort Meade, MD 56 days ago $140,250–$189,750
SAML OAuth 2.0 OpenID Connect (OIDC) WS-Federation Identity and Access Management (IAM) Single Sign-On (SSO) Multi-Factor Authentication (MFA) PKI LDAP Active Directory Microsoft Entra ID PingFederate PingAccess Okta Keycloak PowerShell Docker Kubernetes Zero Trust Architecture
3+ yrs exp

ICAM Identity Provider (IdP) Engineer, Enterprise Authentication Services

General Dynamics

Fort Meade, MD 24 days ago $140,250–$189,750
SAML OAuth 2.0 OpenID Connect (OIDC) WS-Federation Identity and Access Management (IAM) Single Sign-On (SSO) Multi-Factor Authentication (MFA) Active Directory LDAP PKI Certificate-based Authentication Microsoft Entra ID PingFederate PingAccess Okta Keycloak PowerShell Docker Kubernetes Zero Trust Architecture Agile
5+ yrs exp

ICAM Identity Provider (IdP) Engineer, Enterprise Authentication Services

General Dynamics

Remote (Falls Church, VA) 64 days ago $170,000–$230,000
Active Directory Domain Services (AD DS) SAML 2.0 OAuth 2.0 OpenID Connect (OIDC) Microsoft Azure Microsoft Entra ID Identity and Access Management (IAM) Multi-Factor Authentication (MFA) Single Sign-On (SSO) PKI Certificate-based Authentication LDAP PowerShell Docker Kubernetes Zero Trust Architecture Agile JWT WS-Federation
8+ yrs exp Remote

ICAM Engineer

Booz Allen Hamilton

Reston, VA +1 17 days ago $86,800–$198,000
OCI IAM SAML 2.0 OpenID Connect OAuth 2.0 SCIM LDAP Active Directory Zero Trust Terraform Ping Identity Microsoft Entra ID Okta ADFS RBAC ABAC RMF ICD 503 SIEM infrastructure-as-code
8+ yrs exp