Identity Access Manager (IAM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking an experienced Senior Identity & Access Management (IAM) Consultant to lead the migration of enterprise authentication services from ForgeRock OpenAM to PingOne Advanced Identity Cloud and Microsoft Entra ID. This consultant will be responsible for designing and executing a secure, scalable migration strategy while minimizing business disruption and ensuring a seamless transition for users and applications. The ideal candidate has deep expertise in enterprise identity platforms, single sign-on (SSO), federation protocols, and authentication architecture, along with a proven track record of leading large-scale IAM modernization initiatives. Key Responsibilities
- Assess the current authentication environment, including ForgeRock OpenAM, application integrations, and identity workflows.
- Develop a comprehensive migration strategy, roadmap, project timeline, and implementation plan.
- Design, configure, and implement PingOne Advanced Identity Cloud and Microsoft Entra ID solutions.
- Migrate applications and authentication services from ForgeRock OpenAM to the target platforms.
- Configure, implement, and validate Single Sign-On (SSO) using OAuth 2.0, OpenID Connect (OIDC), and SAML 2.0.
- Ensure authentication, authorization, and identity federation services meet enterprise security and compliance requirements.
- Perform system integration testing, user acceptance testing (UAT), troubleshooting, and issue resolution throughout the migration.
- Create comprehensive technical documentation, architecture diagrams, configuration guides, and operational runbooks.
- Conduct knowledge transfer sessions and provide training to internal IT and security teams.
- Deliver post-migration support, optimization, and stabilization to ensure a successful production rollout.
- Collaborate with infrastructure, security, application development, and business stakeholders throughout the project lifecycle.
- Follow IAM and cybersecurity best practices to maintain a secure, resilient authentication environment.
Requirements
- 7+ years of experience in Identity and Access Management (IAM) engineering or consulting.
- Hands-on experience with PingOne Advanced Identity Cloud.
- Strong experience with Microsoft Entra ID (Azure Active Directory).
- Experience administering and migrating ForgeRock OpenAM environments.
- Expertise implementing and supporting Single Sign-On (SSO) and identity federation.
- Strong knowledge of authentication and authorization protocols, including:
- OAuth 2.0
- OpenID Connect (OIDC)
- SAML 2.0
- Experience designing enterprise authentication architectures.
- Strong troubleshooting, analytical, and problem-solving skills.
- Excellent communication skills with the ability to document technical solutions and work with both technical and non-technical stakeholders.
Employment Eligibility: Gravity cannot transfer nor sponsor a work visa for this position. Applicants must be eligible to work in the U.S. for any employer directly (we are not open to contract or “corp to corp” agreements).
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The Best X (Twitter) Accounts for Developers
Dev Digest 121 - AI goes offline
Highest Paying Tech Companies for Developers
Why Attend a Developer Event in 2026?