--- title: 'Federated Authentication Engineer - OESIS Framework at OPSWAT' canonical: 'https://feeny.ai/job/federated-authentication-engineer-oesis-framework-opswat-ho-chi-minh-city-zpte5m56pbm6' type: 'job' last_seen: '2026-09-13' --- # Federated Authentication Engineer - OESIS Framework at OPSWAT - **Company:** OPSWAT - **Location:** Ho Chi Minh City, Vietnam - **Posted:** 2026-09-12 - **Last confirmed live:** 2026-09-13 - **Apply:** https://www.opswat.com/jobs/4725660005?gh_jid=4725660005 ## Job description OPSWAT, a global leader in IT, OT, and ICS critical infrastructure cybersecurity, delivers an end-to-end platform that gives public and private sector organizations and enterprises the critical advantage needed to protect their complex networks, secure their devices, and ensure compliance. Over the last 20 years our commitment to innovative technology has earned the trust of more than 1,700 organizations, governments, and institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life. The Position At OPSWAT, we’re building cutting-edge solutions that protect the world’s critical infrastructure. You will play a pivotal role in shaping the future of our OESIS Framework platform with cloud solution integrations. This role owns how the SDK authenticates into each customer's own tenant across Endpoint Device Management platforms — without OPSWAT ever holding the customer's raw credentials. That "passthrough" model, plus secure multi-tenant token/credential storage, is the core of the job. ## What you will be doing - Design and implement OAuth2/OIDC flows per platform: (For example: CrowdStrike API client-credentials flow, Microsoft Entra ID (Azure AD) app-registration and Graph API auth flows, JAMF Pro OAuth2/bearer or client-credentials flows) - Implement SAML 2.0-based federation for enterprise SSO passthrough scenarios where a customer's identity provider is the source of truth - Build secure, multi-tenant credential and token storage with rotation, integrating with secrets managers (HashiCorp Vault, Azure Key Vault, AWS Secrets Manager, or equivalent) - Design the "passthrough" auth architecture so the embedded SDK authenticates to the customer's own device management tenant directly, without OPSWAT storing or proxying raw customer credentials - Implement token refresh, expiry handling, and re-authentication logic that integrates cleanly with the Data Engineer's long-running query pipelines - Define least-privilege scoping per platform and support certificate-based auth / mutual TLS where the vendor API supports it - Support customer onboarding: app-registration/consent flows for remote enrollment (such as Entra ID, API client setup for CrowdStrike, and API role/privilege configuration for JAMF Pro) ## What we need from You - 3+ years in identity/access engineering with hands-on OAuth2, OIDC, SAML 2.0, and ideally SCIM - Direct experience with Microsoft Entra ID (Azure AD) app registrations and Graph API authentication flows - Experience implementing OAuth2 client-credentials flows against third-party enterprise APIs (for example: CrowdStrike Falcon, JAMF Pro, or comparable) - Strong grasp of token lifecycle management: refresh tokens, expiry, revocation, scope/claim design - Experience with secrets management and secure credential storage in multi-tenant SaaS environments - Familiarity with certificate-based authentication (mTLS, client certificates) - Security-first mindset: working knowledge of common auth vulnerabilities (token leakage, replay attacks, scope creep) It would be nice if you have - Prior experience building "passthrough" or delegated auth architectures specifically for OEM/SDK products embedded in third-party platforms - Background in enterprise IAM tooling (Okta, Ping Identity, Entra ID) or CIAM - Familiarity with Zero Trust Network Access (ZTNA) and device posture or compliance - Security certifications (CISSP, OSCP, or similar) - Cybersecurity domain knowledge and software development experience - Familiarity with Regulatory Compliance Data frameworks (like PCI-DSS, SOX, HIPPA, etc) Why join us? At OPSWAT, we believe in empowering our people to do their best work. We encourage you to watch the [video](https://www.youtube.com/watch?v=et8Rs0hEOLw&t=2929s) of our companies’ more than 20 years’ experience of securing critical infrastructure. You’ll be part of a mission-driven OESIS ([OESIS Framework](https://www.youtube.com/watch?v=2i_aRGaK2Ag&pp=ygUQb3Bzd2F0IE9FU0lTIFNESw%3D%3D)) team that values innovation, collaboration, and continuous development. Together, we’re building [SDK](https://software.opswat.com/OESIS_V4/html/index.html?_gl=1*104kihc*_gcl_au*NTY1MzQyNzQzLjE3NjEwNzEwNDc.*_ga*MTc0MzkxMTc4Mi4xNzYxMDcxMDQ4*_ga_B4377JYKYJ*czE3NjIwMjY4MzUkbzkkZzEkdDE3NjIwMjk4ODUkajUzJGwwJGg4OTQxMDkxNjQ.) technology that makes a difference. OPSWAT is an equal opportunity employer. We celebrate diversity and are committed to providing an environment where equal employment opportunities are extended to all employees and applicants, free of discrimination and harassment of any type. All employment decisions are based on individual qualifications, job requirements, and business needs without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other category protected by federal, state, or local laws. Recruiting Agencies: we do not accept unsolicited resumes from third party agencies for any of our open positions. To submit resumes for our jobs, there must be a recruiting contract approved by our legal team and endorsed by both parties. We are currently not accepting additional 3rd party agencies at this time. ## About OPSWAT ## Company Overview - **One-liner**: OPSWAT protects the world’s critical infrastructure by securing every file, device, and data transfer across IT, OT, and air-gapped networks using its AI-powered MetaDefender Platform. - **Entity Type**: Private (venture-backed; $125M total funding raised; bootstrapped for many years) - **Headquarters**: Tampa, Florida, United States - **Founded**: 2002 - **Founders**: Benny Czarny ## Core Business - **Primary industry**: Cybersecurity (critical infrastructure protection) - **Target customers**: B2B, Enterprise, Government – including nuclear facilities, defense networks, energy grids, financial institutions, and other mission-critical organizations. - **Mission / purpose**: “Trust no file. Trust no device.” – prevent known, unknown, and AI-generated threats from reaching the systems the world depends on. ## Products & Services - **MetaDefender Platform** (SaaS / On-premises / Hybrid): Unified cybersecurity platform providing file security, email security, removable media protection, network security, cross-domain transfer, endpoint compliance, and cloud security. Key technologies: Deep CDR™ (Content Disarm and Reconstruction), Metascan™ Multiscanning (30+ anti-malware engines), AI-driven threat prediction, Adaptive Sandbox, Proactive DLP, and File-Based Vulnerability Assessment. - **Peripheral & Removable Media Protection**: Kiosk-based scanning and compliance enforcement for USB drives and transient assets. - **Managed File Transfer**: Secure cross-boundary file movement with built-in threat prevention, policy enforcement, and audit trails. - **Data Diode & Security Gateway Solutions**: Hardware-enforced unidirectional data transfer for air-gapped and segmented networks. - **Email Security**: Neutralizes weaponized attachments and embedded threats using Deep CDR and Multiscanning. - **Access & Endpoint Security (OESIS Framework)**: Assesses device posture before granting network access, covering managed and unmanaged devices. - **OPSWAT Academy**: Professional certification in Critical Infrastructure Protection (CIP) – 28 courses, 456,000+ registered students, 268,000+ certified. ## Market Standing - **Valuation / Market Cap**: Not publicly disclosed - **Key Metric**: Annual Revenue $110M (LinkedIn, 2025 estimate); Total Funding $125M - **Notable Investors / Partners**: Not explicitly listed in search results, but the company is trusted by 98% of U.S. nuclear power facilities and 1,500+ organizations in 80+ countries - **Growth Signals**: 854 employees (+16.9% YoY, +167 people); operates in 28 countries (including Vietnam, Romania, Hungary, UK, Israel); pre-validated against NIST 800-53, CMMC 2.0, NERC CIP, Zero Trust, ISO 27001, SOC 2, NEI 08-09 Rev 6 ## Competitive Advantages - **Prevention-first philosophy** – stops threats before execution, unlike detection-based tools. - **Deep CDR™ Technology** – reconstructs files to remove malware while preserving usability. - **Multiscanning with 30+ anti-malware engines** – near 100% detection rate. - **AI embedded natively** – predicts and neutralizes AI-generated threats. - **Air-gap and cross-domain expertise** – data diodes and security gateways for the most sensitive networks. - **Regulatory compliance** – validated for the world’s most rigorous standards in nuclear, defense, and critical infrastructure. ## Strategic Focus - **Deepening AI capabilities** in threat prediction and content verification. - **Expanding the MetaDefender Platform** to cover more attack surfaces (Cloud, OT, IT). - **Growing the OPSWAT Academy** to train a global workforce in CIP. - **Scaling global reach** – already in 28 countries, targeting more government and enterprise segments. ## Why Work Here - **Culture**: Mission-oriented, innovative, transparent, and collaborative. “You are trusted to do your job” – teams have ownership and autonomy. Open communication across all levels. - **Remote / Hybrid / Office**: Flexible-work arrangements; global offices in Tampa, Vietnam, Romania, Hungary, UK, Israel, and others. - **Compensation & Benefits**: Competitive salaries, excellent insurance, stock options, generous PTO, multifaceted reward programs, quarterly/annual reviews. - **Workplace Wellness**: Green office spaces, workout/exercise facilities, friendly environment, work-life balance emphasis. - **Training & Development**: OPSWAT Academy provides privileged CIP certification; mentorship and career growth programs. - **Recognition**: Named one of the best companies to work for in Asia by HR Asia Magazine. ## Sources 1. [OPSWAT Website](https://www.opswat.com/) 2. [OPSWAT Company Page](https://www.opswat.com/company) 3. [OPSWAT About Page](https://www.opswat.com/company/about) 4. [OPSWAT Careers Page](https://www.opswat.com/careers) 5. [OPSWAT LinkedIn](https://www.linkedin.com/company/opswat) ## Other roles at OPSWAT - [Sales Development Representative - Japan](https://feeny.ai/job/sales-development-representative-japan-opswat-tokyo-w7vtd5khn3r0) — Tokyo, Japan - [DevOps Engineer](https://feeny.ai/job/devops-engineer-opswat-veszprem-00kg950y0enm) — Veszprém, Hungary - [SDK Integration Engineer - OESIS Framework](https://feeny.ai/job/sdk-integration-engineer-oesis-framework-opswat-ho-chi-minh-city-j7jm5aq3qa21) — Ho Chi Minh City, Vietnam - [Data Engineer - OESIS Framework](https://feeny.ai/job/data-engineer-oesis-framework-opswat-ho-chi-minh-city-j4874e5nmepj) — Ho Chi Minh City, Vietnam - [Regional Sales Director - West India, Enterprise](https://feeny.ai/job/regional-sales-director-west-india-enterprise-opswat-india-65j66b39mz5t) — India - [Senior Agentic Software Engineer - Marketing](https://feeny.ai/job/senior-agentic-software-engineer-marketing-opswat-ho-chi-minh-city-derr58s1a2dn) — Ho Chi Minh City, Vietnam - [Senior Office Administrator](https://feeny.ai/job/senior-office-administrator-opswat-ho-chi-minh-city-r9n205kt368d) — Ho Chi Minh City, Vietnam - [Technical Support Engineer](https://feeny.ai/job/technical-support-engineer-opswat-london-england-a9tv44kb48h9) — London England, United Kingdom - [Talent Acquisition Business Partner](https://feeny.ai/job/talent-acquisition-business-partner-opswat-tampa-florida-tcj2wpqesdvn) — Tampa Florida, United States - [Joint Professional Services - Technical Support Engineer in Australia](https://feeny.ai/job/joint-professional-services-technical-support-engineer-in-australia-opswat-zfe2tqge17mk) — Australia