Corporate Vice President - Head of Authentication Engineering, Identity & Access Management

Posted 2 Days Ago
Be an Early Applicant
New York, NY, USA
Hybrid
148K-211K Annually
Expert/Leader
Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Powered by purpose. Driven by people. Built to evolve.
The Role
Leads enterprise authentication engineering strategy, architecture, delivery, reliability, and user experience across workforce, applications, APIs, cloud, hybrid environments, non-human identities, and AI agents. Oversees federation, SSO, MFA, passkeys, authorization, PKI, workload identity, and continuous authentication. Directly manages authentication engineers, including hiring, staffing, performance management, technical guidance, and career development. Represents Cybersecurity in governance forums and drives secure, scalable authentication modernization.
Summary Generated by Built In
Location Designation: Hybrid - 3 days per quarter
Technology, Data, AI and Ventures:
Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes.
Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era - all backed by the stability and purpose of a mutual company built to last.
The Head of Authentication Engineering, Identity & Access Management is the senior, hands-on technical leader accountable for the strategy, architecture, engineering, and reliability of New York Life's enterprise authentication capabilities across workforce, application, API, cloud (AWS, Azure, and GCP), and emerging AI agent-based access patterns. This is a builder and technical authority role, not a purely advisory or governance position - you will define the target state, make difficult design decisions, and personally engage in the most complex authentication challenges. This is also a people leadership role: you will directly manage a team of authentication engineers, and are accountable for providing them with day to day guidance, technical oversight, and career development.
This leader owns authentication as an end to end capability, including federation, SSO, MFA, passwordless and phishing-resistant authentication, adaptive and continuous authentication, session management, token services, API authorization, and authentication patterns for non human identities and AI enabled systems. User experience is treated as a core engineering outcome, not an afterthought, alongside strong identity assurance. You will need the technical depth to be credible with engineers and architects, and the executive presence to represent Cybersecurity in enterprise governance forums. As the direct manager of the authentication engineering team, you are responsible for staffing, workload allocation, performance management, and ensuring every team member receives the guidance and oversight needed to do their job well.
What You'll Do:
• Own the enterprise authentication strategy, target architecture, roadmap, and standards across workforce, application, API, cloud (AWS, Azure, GCP), and hybrid environments.
• Serve as the authoritative design leader for authentication, federation, authorization, session security, and identity assurance, and position the enterprise for passkeys, workload identity, agent identity, and continuous verification.
• Lead the design and enterprise-scale delivery of phishing-resistant, passwordless authentication (FIDO2, passkeys) and adaptive, risk-based, and continuous authentication models.
• Architect enterprise federation and SSO using SAML 2.0, OAuth 2.0, and OpenID Connect, and design secure API authorization patterns including token exchange, delegation, and fine grained authorization.
• Help set NYL's direction on leading edge authentication and authorization protocols, including Identity Assertion Authorization Grant (ID-JAG), Shared Signals Framework/CAEP, and Transaction Tokens, and evaluate where they fit the enterprise roadmap.
• Treat authentication user experience as a core engineering outcome own end to end journey mapping across devices, platforms, and recovery paths to reduce friction while maintaining strong identity assurance.
• Apply PKI, mTLS, and certificate based authentication for human and machine access, including workload identity across cloud and hybrid platforms.
• Own authentication patterns for non human identities and AI enabled systems, including AI agents, agent to agent interactions, and MCP enabled workflows.
• Use telemetry and testing to identify friction and failure patterns across the authentication journey, and drive continuous, measurable UX improvement.
• Own the reliability and operational health of authentication services, including availability, scalability, latency, and incident response.
• Represent IAM and Cybersecurity in Security Review Board and Architecture Review Board forums, and lead technical reviews of authentication flows, cloud identity, and vendor solutions.
• Serve as the direct people manager for a team of authentication engineers: own hiring, staffing, and workload distribution, conduct regular one on ones and performance reviews, set individual development plans, and provide the hands on technical guidance and day to day oversight needed to raise the team's technical bar.
• Provide adequate guidance and oversight of the team's work at every stage - from design through delivery - including reviewing designs and code, unblocking engineers on complex problems, and ensuring work meets NYL's security, quality, and delivery standards before it ships.
What You'll Bring:
• Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or equivalent practical experience.
• 12+ years of progressive experience in identity and access management, security engineering, or platform engineering, including significant leadership of enterprise authentication engineering.
• 5+ years of experience as a direct people manager of engineers, with a demonstrated track record of hiring, coaching, performance management, and career development, and the ability to provide the guidance and oversight a technical team needs day to day.
• Expert level knowledge of SAML 2.0, OAuth 2.0, OpenID Connect, federation, SSO, MFA, session security, and token lifecycle management.
• Deep hands on experience with enterprise federation and access management platforms such as PingFederate, PingAccess, PingOne, or comparable technologies.
• Demonstrated ability to design authentication journeys that are secure, low friction, and measurable, with a track record of using UX and telemetry data to drive improvement.
• Proven experience delivering passwordless and phishing resistant authentication at enterprise scale (FIDO2, passkeys, Windows Hello for Business, HYPR, or equivalent).
• Strong experience with API security and authorization, including gateways, token exchange, delegation, and fine grained authorization.
• Practical experience with PKI, mTLS, certificate based authentication, and machine or workload authentication across cloud platforms (AWS, Azure, or GCP).
• Ability to lead technical reviews, make high consequence design decisions, and communicate clearly with engineers, executives, governance bodies, and risk partners.
Preferred Qualifications:
• Experience modernizing authentication in a regulated financial services or similarly complex enterprise environment.
• Experience integrating authentication with zero trust network access, cloud platforms (AWS, Azure, GCP), and enterprise device management.
• Experience securing non human identities, AI agents, agent to agent interactions, delegated access, or MCP enabled systems.
• Experience with workload identity standards such as SPIFFE/SPIRE and cloud native service identity.
• Experience with policy as code and fine grained authorization approaches such as OPA, Cedar, ABAC, or relationship based access control.
• Familiarity with leading edge and emerging web access management (WAM) protocols such as ID-JAG, Shared Signals Framework/CAEP, and Transaction Tokens, and the judgment to help set enterprise direction on their adoption.
• Relevant certifications such as CISSP, CISM, CCSP, or a cloud security credential (AWS, Azure, or GCP).
Job Level: LEVELPF5
Pay Transparency
Salary Range: $147,500-$211,000
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Company Overview
At New York Life, our 180-year legacy of purpose and integrity fuels our future. As we evolve into a more technology-, data-, and AI-enabled organization, we remain grounded in the values that drive lasting impact.
Our diverse business portfolio creates opportunities to make a difference across industries and communities-inviting bold thinking, collaborative problem-solving, and purpose-driven innovation. Here, you'll find the rare balance of long-standing stability and forward momentum, supported by an inclusive team that honors tradition while embracing progress.
As a Fortune 100 mutual company, we offer a place to grow your skills, contribute to meaningful work, and deliver solutions that matter. Your ideas drive what's next, and your growth powers it.
Our Benefits
We provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Our Commitment to Inclusion
At New York Life, fostering an inclusive workplace is fundamental to who we are and how we serve our communities. We have a longstanding commitment to creating an environment where individuals can contribute their best and succeed together. This foundation is rooted in our core values of humanity and integrity, ensuring that every employee feels valued and supported. By embracing a broad range of perspectives and experiences, we achieve greater success and fulfill our promise of providing financial security and peace of mind to families across all communities. Click here to learn more about New York Life's leadership in this space.
Recognized as one of Fortune's World's Most Admired Companies, New York Life is committed to improving local communities through a culture of employee giving and volunteerism, supported by the Foundation. We're proud that due to our mutuality, we operate in the best interests of our policy owners. To learn more about career opportunities at New York Life, please visit the Careers page of www.NewYorkLife.com.
Job Requisition ID: 94834
#BI-Hybrid

Skills Required

  • Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or equivalent practical experience
  • 12+ years of progressive experience in identity and access management, security engineering, or platform engineering
  • Significant leadership experience in enterprise authentication engineering
  • 5+ years of direct people management experience leading engineers
  • Expert knowledge of SAML 2.0, OAuth 2.0, OpenID Connect, federation, SSO, MFA, session security, and token lifecycle management
  • Hands-on experience with enterprise federation and access management platforms such as PingFederate, PingAccess, PingOne, or comparable technologies
  • Experience designing secure, low-friction, measurable authentication journeys using UX and telemetry data
  • Experience delivering passwordless and phishing-resistant authentication at enterprise scale, including FIDO2 or passkeys
  • Strong experience with API security and authorization, including gateways, token exchange, delegation, and fine-grained authorization
  • Practical experience with PKI, mTLS, certificate-based authentication, and machine or workload authentication across cloud platforms
  • Ability to lead technical reviews, make high-consequence design decisions, and communicate with engineers, executives, governance bodies, and risk partners
  • Experience modernizing authentication in regulated financial services or a similarly complex enterprise environment
  • Experience integrating authentication with zero trust network access, cloud platforms, and enterprise device management
  • Experience securing non-human identities, AI agents, agent-to-agent interactions, delegated access, or MCP-enabled systems
  • Experience with workload identity standards such as SPIFFE/SPIRE and cloud-native service identity
  • Experience with policy as code and fine-grained authorization approaches such as OPA, Cedar, ABAC, or relationship-based access control
  • Familiarity with ID-JAG, Shared Signals Framework/CAEP, and Transaction Tokens
  • CISSP, CISM, CCSP, or cloud security credential

What the Team is Saying

Tyrone
Emma
Deepa
Patricia
Joel
Nishit

New York Life Insurance Company Compensation & Benefits Highlights

  • Retirement Support Corporate employees are offered a 401(k) with company match and, for many roles, a defined‑benefit pension, with both the employee contributions and company match vesting 100% from day one. Qualified financial professionals may also have access to a defined‑benefit plan, per plan documents.
  • Parental & Family Support Paid New Parent leave doubled to 8 weeks for all parents as of January 1, 2024, and birthing parents typically receive an additional 6 weeks of paid short‑term disability. The company also highlights fertility and adoption support, backup childcare, tutoring, and elder‑care resources.
  • Healthcare Strength Medical, dental, and vision coverage are paired with HRAs/FSAs, an Employee Assistance Program, wellness programs, and telemedicine. Work/life perks such as gym discounts or on‑site gyms further reinforce the health and wellbeing offering.

New York Life Insurance Company Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
12,000 Employees
Year Founded: 1845

What We Do

At New York Life, our 180-year legacy of integrity, mutuality, and financial strength fuels a future defined by bold transformation. As the largest mutual life insurance company in the U.S., we operate on behalf of our policy owners—not shareholders. That structure allows us to take a long-term view, investing in people, purpose, and innovation that endures. Guided by a clear enterprise vision to become a technology-, data-, and AI-powered company, we’re modernizing our platforms, rearchitecting experiences, and embedding intelligence across our products and services. Our mission has always been about helping people through life’s most meaningful moments. Today, technology is amplifying that mission—enabling us to serve clients, advisors, and communities in more personalized, proactive ways. With a diversified business portfolio spanning insurance, investments, retirement, group benefits, and direct-to-consumer offerings, New York Life delivers the stability of a Fortune 100 company with the agility of one that’s continuously evolving. We’re powered by a values-led culture, inclusive teams, and a shared belief that when our people thrive, so does our company. Here, tradition fuels momentum—and your ideas, energy, and growth power what’s next.

Why Work With Us

New York Life is transforming from the inside out—blending 180 years of trust with the velocity of innovation. What makes us different is our culture: grounded in integrity, humanity, and shared success—values that show up in how we work, lead, and grow. If you want a place where innovation has purpose—build what's next with us.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

New York Life Insurance Company Teams

Team
Internships and Early Career Programs
About our Teams

New York Life Insurance Company Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Not Specified
Company Office Image
HQNew York, NY
Company Office Image
Jersey City, NJ
Philadelphia, PA
Company Office Image
Tampa, FL
Company Office Image
White Plains, NY
Learn more

Similar Jobs

New York Life Insurance Company Logo New York Life Insurance Company

Project Manager

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
12000 Employees
100K-143K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Operations Manager

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
3 Locations
12000 Employees
90K-130K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Senior Associate - Business/Technology Analyst

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
12000 Employees
115K-130K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Service Client Specialist to the Managing Partner 94730

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
In-Office
Melville, NY, USA
12000 Employees
65K-80K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account