Federated Authentication Engineer - OESIS Framework

OPSWAT
OPSWAT

Full-time

Ho Chi Minh City, Vietnam

Posted on Sep 12, 2026

OPSWAT, a global leader in IT, OT, and ICS critical infrastructure cybersecurity, delivers an end-to-end platform that gives public and private sector organizations and enterprises the critical advantage needed to protect their complex networks, secure their devices, and ensure compliance. Over the last 20 years our commitment to innovative technology has earned the trust of more than 1,700 organizations, governments, and institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life.

The Position

At OPSWAT, we’re building cutting-edge solutions that protect the world’s critical infrastructure. You will play a pivotal role in shaping the future of our OESIS Framework platform with cloud solution integrations. This role owns how the SDK authenticates into each customer's own tenant across Endpoint Device Management platforms — without OPSWAT ever holding the customer's raw credentials. That "passthrough" model, plus secure multi-tenant token/credential storage, is the core of the job.

What you will be doing

  • Design and implement OAuth2/OIDC flows per platform: (For example: CrowdStrike API client-credentials flow, Microsoft Entra ID (Azure AD) app-registration and Graph API auth flows, JAMF Pro OAuth2/bearer or client-credentials flows)
  • Implement SAML 2.0-based federation for enterprise SSO passthrough scenarios where a customer's identity provider is the source of truth
  • Build secure, multi-tenant credential and token storage with rotation, integrating with secrets managers (HashiCorp Vault, Azure Key Vault, AWS Secrets Manager, or equivalent)
  • Design the "passthrough" auth architecture so the embedded SDK authenticates to the customer's own device management tenant directly, without OPSWAT storing or proxying raw customer credentials
  • Implement token refresh, expiry handling, and re-authentication logic that integrates cleanly with the Data Engineer's long-running query pipelines
  • Define least-privilege scoping per platform and support certificate-based auth / mutual TLS where the vendor API supports it
  • Support customer onboarding: app-registration/consent flows for remote enrollment (such as Entra ID, API client setup for CrowdStrike, and API role/privilege configuration for JAMF Pro)

What we need from You

  • 3+ years in identity/access engineering with hands-on OAuth2, OIDC, SAML 2.0, and ideally SCIM
  • Direct experience with Microsoft Entra ID (Azure AD) app registrations and Graph API authentication flows
  • Experience implementing OAuth2 client-credentials flows against third-party enterprise APIs (for example: CrowdStrike Falcon, JAMF Pro, or comparable)
  • Strong grasp of token lifecycle management: refresh tokens, expiry, revocation, scope/claim design
  • Experience with secrets management and secure credential storage in multi-tenant SaaS environments
  • Familiarity with certificate-based authentication (mTLS, client certificates)
  • Security-first mindset: working knowledge of common auth vulnerabilities (token leakage, replay attacks, scope creep)

It would be nice if you have

  • Prior experience building "passthrough" or delegated auth architectures specifically for OEM/SDK products embedded in third-party platforms
  • Background in enterprise IAM tooling (Okta, Ping Identity, Entra ID) or CIAM
  • Familiarity with Zero Trust Network Access (ZTNA) and device posture or compliance
  • Security certifications (CISSP, OSCP, or similar)
  • Cybersecurity domain knowledge and software development experience
  • Familiarity with Regulatory Compliance Data frameworks (like PCI-DSS, SOX, HIPPA, etc)

Why join us?

At OPSWAT, we believe in empowering our people to do their best work. We encourage you to watch the video of our companies’ more than 20 years’ experience of securing critical infrastructure. You’ll be part of a mission-driven OESIS (OESIS Framework) team that values innovation, collaboration, and continuous development. Together, we’re building SDK technology that makes a difference.

OPSWAT is an equal opportunity employer. We celebrate diversity and are committed to providing an environment where equal employment opportunities are extended to all employees and applicants, free of discrimination and harassment of any type. All employment decisions are based on individual qualifications, job requirements, and business needs without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other category protected by federal, state, or local laws.

Recruiting Agencies: we do not accept unsolicited resumes from third party agencies for any of our open positions. To submit resumes for our jobs, there must be a recruiting contract approved by our legal team and endorsed by both parties. We are currently not accepting additional 3rd party agencies at this time.