Loading jobs…
Loading jobs…
TripleLift — New York New York
About TripleLift We're TripleLift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting. Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses. Our technology is where the world's leading brands find audiences across online video, connected television, display and native ads.
Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance. As part of the Vista Equity Partners portfolio, we are NMSDC certified, qualify for diverse spending goals and are committed to economic inclusion. com .
Overview The Senior/Principal Identity and API Architect plays a critical role in driving TripleLift’s identity infrastructure and API security strategy within the Exchange team, directly influencing how we authenticate and authorize publishers, buyers, and platform partners across our programmatic marketplace. In this position, you will partner closely with Engineering, Product, and Services teams to design and own the end-to-end identity architecture that underpins our Exchange’s security, scalability, and interoperability. This is an exciting opportunity for someone who wants to build a best-in-class identity platform from the ground up, shaping how TripleLift authenticates billions of programmatic transactions while serving as a strategic thought partner to Exchange leadership on API governance and access control.
Responsibilities
Architect and own TripleLift’s end-to-end identity platform, including tenant models, SSO integrations, machine-to-machine authentication, and delegated administration for publishers and demand partners. Design and implement Auth0 tenant architecture, including custom domains, enterprise connections, Actions/Rules, and token lifecycle management (refresh rotation, session policies, JWKS). 0 and OIDC flows across the Exchange — including PKCE, M2M client credentials, and device authorization — ensuring secure and consistent authentication for all platform participants.
, SpiceDB, Ory Keto), enabling fine-grained access control across publisher hierarchies (networks, properties, seats, users). Own the API gateway layer, designing rate limiting, scoped token validation, mTLS enforcement, and consistent error semantics across Traefik, Kong, AWS API Gateway, or equivalent infrastructure. 0, OIDC) for enterprise onboarding, delegated self-service administration, and integration of first-party data and authenticated traffic signals into programmatic decisioning.
0 M2M, API key management), partner onboarding flows, and identity traceability across bid request/response flows for audit, fraud detection, and deal enforcement. Manage AWS identity and API infrastructure, including IAM roles and cross-account trust, Cognito integration patterns, Secrets Manager and KMS for credential lifecycle, and STS-based service-to-service auth in multi-account environments. Establish and maintain identity and API security standards, conducting threat modeling, reviewing integrations for compliance with RBAC/ABAC/ReBAC policies, and responding to security incidents.
, GDPR, CCPA as they relate to identity signals).