Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Communication @ 3
Distributed Systems
GDPR @ 3
Leadership @ 3
Observability
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Our team
We are the CTO Security Service Infrastructure group. We solve complex systems problems, enabling our engineers to quickly ship new products, and prototype the next generation of infrastructure security technologies. Whether we’re designing next-generation security controls or threat modeling distributed systems, our goal is to define the future of how we secure Bloomberg’s infrastructure.
As an architect and product owner in the CTO’s office, you’ll be trusted to understand the intersections between Bloomberg’s global technology footprint, unique software stack, security requirements, and provide guidance for usable infrastructure security. You’ll ensure that logical security controls are manageable at our scale, influence the roadmap for future security technologies, and work alongside engineers across the company.
Responsibilities
In this role, you will help define and drive Bloomberg’s strategy for credential-based authentication experiences.
This includes:
- Login workflows across our properties
- Secure delivery and management of credentials for both clients and internal users
- Policies and controls governing password-based authentication
- Evolution of secure access patterns for engineering and enterprise environments
You will also help shape policies, standards, and safeguards for delegated access and related controlled access workflows. You will work across engineering, security, and business stakeholders to improve authentication experiences that are usable, resilient, and scalable, and to shape the long-term direction of the underlying controls, tools, and workflows.
You’ll evaluate and improve:
- First-time credential delivery
- Login orchestration
- Password setup, reset, recovery, and related authentication journeys
You’ll also:
- Drive the evolution of Bloomberg’s login process, including long-term direction, controls, and implementation priorities
- Define and refine password policy across enterprise and client-facing use cases, balancing security, usability, and supportability
- Partner with adjacent authentication team members to ensure integration with federated access patterns where appropriate
- Work with engineering teams to design and implement authentication-related solutions, controls, and integrations
- Define policies, standards, and control frameworks for delegated access and other sensitive authentication-linked workflows, with appropriate guardrails for approval, accountability, and auditability
- Establish understanding of current authentication workflows, dependencies, pain points, and future-state opportunities
- Produce clear requirements, architecture direction, and implementation guidance for authentication-related initiatives
- Align priorities, tradeoffs, and delivery plans with stakeholders across engineering, product, support, and business teams
- Ensure appropriate auditing, reporting, and observability exist for authentication workflows and related controls
- Assess risks and identify opportunities to strengthen authentication processes and password-related controls across the organization
- Collaborate with vendors, consultants, and industry peers to exchange knowledge and stay informed about the latest advancements in authentication and credential management technologies
Requirements
- 7+ years of experience building, maintaining, and managing security aspects of large-scale, distributed infrastructure and applications
- Strong experience in authentication, credential management, and provision-related technologies, including engineering, integration, and automation with an emphasis on security
- Track record of building collaborative relationships with stakeholders across many functions, with focus on correctness, scalability, and usability of distributed infrastructure
- Ability to build proof-of-concepts solutions, innovate, and partner with Engineering teams to drive adoption
- Ability to collect and document detailed product requirements including RFCs, design rationale, and decision making
- Experience of knowing when to build, buy, or reuse
- Deep knowledge of authentication protocols and standards and how they are adopted in large enterprises
- Demonstrated polished written and oral communication skills, from hands-on deep technical experts to senior leadership
We'd love to see
- Experience managing large scale infrastructure
- Experience handling regulatory requirements such as GDPR, DORA, and HIPAA
- Experience integrating with and securing a combination of in-house developed, open-source, and third-party solutions
- Hands-on experience with authentication and credential management products
- Hands-on experience with enterprise identity management technologies and the challenges of aligning business requirements and organizational behaviors with technology