Haystack
← Back to Jobs
Other
KJ

IAM ForgeRock Architect

kjohn@samrusystems.comUnited States🇺🇸United StatesPosted 25 Aug 2026

Why This Role Stands Out

This hybrid role offers significant opportunities to shape enterprise IAM strategies and architect cutting-edge solutions using the ForgeRock platform, perfect for experienced architects seeking impactful work. You'll drive innovation in a respected company, developing advanced skills in a collaborative environment. Apply now to leverage your expertise in this dynamic and growing field.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
2 weeks ago
DockerOracleAWSMFAOAuthSAMLSSOSplunkAzureComplianceGoogle CloudGroovyHelmJavaJavaScriptKubernetesLDAPRESTZero Trust

Job Description

Role Overview

We are seeking an experienced IAM Architect with deep specialization in the ForgeRock Identity Platform (including PingOne AIC / Ping Identity stack) to lead the strategy, design, and deployment of enterprise-grade access management, governance, and directory solutions. You will translate business requirements into high-scale, secure authentication and identity architectures across cloud, hybrid, and on-premises environments.


Responsibilities:

·         Solution Architecture & Strategy: Lead the architectural strategy, reference architecture design, and roadmap planning for enterprise IAM using ForgeRock components.

·         ForgeRock Engineering: Design and implement authentication journeys using trees/nodes in ForgeRock AM (Access Management), lifecycle workflows in ForgeRock IDM (Identity Management), dynamic routing in ForgeRock IG (Identity Gateway), and directory schemas in ForgeRock DS (Directory Services / OpenDJ).

·         Protocol & Federation Management: Design secure Single Sign-On (SSO), Multi-Factor Authentication (MFA), and OAuth2/OIDC/SAML 2.0 federation across modern and legacy applications.

·         Integration & Customization: Develop and review custom nodes, scripts, and extensions in Java, JavaScript, or Groovy to extend platform functionality.

·         Cloud & DevOps Alignment: Containerize and deploy ForgeRock solutions using Docker and Kubernetes (K8s) on public cloud infrastructure (AWS, Azure, Google Cloud Platform).

·         Stakeholder Engagement: Collaborate with C-suite, Security, and AppDev teams to enforce Zero Trust principles, RBAC/ABAC models, and compliance policies

 

Required Qualifications & Technical Skills

·         ForgeRock AM, IDM, IG, DS (OpenDJ) and/or PingOne Advanced Identity Cloud (AIC).

·         OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, UMA, SCIM, LDAP.
Core Java, JavaScript, Groovy, REST APIs, JSON.

·         Docker, Kubernetes, Helm charts, CI/CD pipelines, AWS/Azure/Google Cloud Platform deployment.

·         10+ years total in IAM, with 4+ years as a lead architect on large-scale ForgeRock implementations.

 

Preferred Certifications & Nice-to-Haves

·         Certifications: ForgeRock Accredited Access Management / Identity Management Administrator/Architect, CISSP, or CISM.

·         Legacy Migration: Proven experience migrating legacy access management solutions (e.g., Oracle Access Manager, CA SiteMinder) to ForgeRock.

·         Monitoring & Security: Hands-on experience with SIEM integrations (Splunk, AppDynamics) and CIEM/Zero Trust frameworks



Similar jobs