Location: Remote, US-based (must be authorized to work in the United States)Engagement Type: Independent Contractor 1099Duration: 6 months, with potential to extendIndustry: Financial ServicesAbout the RoleWe are looking for an experienced IAM Ping Identity Engineer to join a large financial services organization on a contract basis. You will work within a mature, compliance-driven environment to support the design, implementation, and ongoing operations of the organization's identity and access management infrastructure. This role is well-suited for someone who has hands-on Ping product experience and is comfortable operating under the governance and change management standards typical of regulated industries.Key ResponsibilitiesDesign, configure, and maintain Ping Identity solutions including PingFederate, PingAccess, and PingDirectoryAdminister and troubleshoot SSO, federation, and authentication integrations across enterprise applicationsSupport OAuth 2.0, OIDC, and SAML-based integrations with internal and external service providersParticipate in the full IAM lifecycle including onboarding, access provisioning, and deprovisioning workflowsCollaborate with application teams, security architects, and infrastructure teams to integrate applications with the Ping ecosystemMaintain documentation for configurations, runbooks, and change requests in alignment with change management policiesAssist with audits, compliance reviews, and evidence gathering for regulatory requirements (SOX, PCI-DSS, or similar)Identify and remediate security vulnerabilities or misconfigurations within the IAM environmentSupport incident triage and resolution for authentication and access-related issuesRequired Qualifications4-7 years of experience in Identity and Access Management3+ years of hands-on experience with Ping Identity products (PingFederate required; PingAccess and PingDirectory a strong plus)Solid understanding of federation protocols: SAML 2.0, OAuth 2.0, and OIDCExperience working in regulated environments such as financial services, healthcare, or governmentFamiliarity with LDAP/Active Directory and directory services integrationWorking knowledge of MFA solutions and adaptive authentication policiesExperience with change management processes and operating within ITSM frameworks (ServiceNow or equivalent)Ability to work independently and manage deliverables with limited day-to-day supervisionPreferred QualificationsPing Identity certifications (PingFederate Engineer, etc.)Experience with CyberArk, SailPoint, or other PAM/IGA platformsExposure to cloud IAM patterns (AWS IAM, Azure AD/Entra ID)Scripting or automation experience (Python, PowerShell, or Bash) for IAM workflowsFamiliarity with SOX, PCI-DSS, or FFIEC compliance frameworksContractor RequirementsMust be based in the United States and authorized to work without sponsorshipMust be able to pass a background check, including financial background screeningCorp-to-Corp (C2C) considered; no third-party C2C without prior approval