ForgeRock Identity Architect

Qode View all jobs
Atlanta, CO, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) Amazon Web Services Microsoft Azure Cloud Computing Continuous Integration Software Debugging Groovy Key Management Lightweight Directory Access Protocols (LDAP) Automation of Marketing OAuth OpenID
+11 more
Ping (Networking Utility) X.509 Azure Active Directory Security Assertion Markup Language (SAML) Session Management Systems Integration Okta System Availability Api Design Restful APIs Api Management

Job description

Join a high-impact POD building a self-service federated SSO platform. You’ll be the hands-on ForgeRock expert designing and engineering a scalable identity broker integrating with Okta, Microsoft Entra ID, PingIdentity, and more. This is a build-from-scratch, code-heavy role-not admin/config. Key Responsibilities

  • Design multi-tenant ForgeRock AM federation architecture
  • Build REST APIs for programmatic SAML SP connection lifecycle (create/validate/activate)
  • Implement SAML/OIDC flows, assertion validation, and secure session management across apps
  • Develop scripted authentication (Groovy/JS) and automate certificate lifecycle (monitoring & rotation)
  • Enable break-glass fallback, ensure high availability, and prepare SCIM-ready architecture
  • Migrate existing manual SP connections to automated framework

Requirements

  • 4+ years hands-on ForgeRock Access Manager (AM)
  • Strong SAML 2.0 (debugging raw assertions), OIDC/OAuth 2.0
  • Experience with ForgeRock REST APIs, scripted nodes, and keystore/X.509 management
  • API design & integrations, LDAP, secrets management (AWS/Vault)
  • Coding: Java/Groovy + CI/CD, API testing, SAML debugging tools

Nice to Have

  • ForgeRock IDM, SCIM 2.0, cloud (AWS/Azure/GCP)
  • Experience with Okta / Entra / Ping as IDP
  • Migration of manual SP setups to programmatic model

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

4:27 min

Centralizing access with open source identity management providers

Den Prysukhin · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all