Identity Access Manager (IAM)

Gravity Hair Salon, LLC
Salt Lake City, UT, United States
about 1 month ago
Apply on www.gravityitresources.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$166,400.0 - $176,800.0
Working hours
Regular working hours

Tech stack

Cloud Computing Federated Identity Management Identity and Access Management OAuth OpenID Openid Connect Azure Active Directory Security Assertion Markup Language (SAML) Single Sign-On Software Engineering Software Troubleshooting

Job description

We are seeking an experienced Senior Identity & Access Management (IAM) Consultant to lead the migration of enterprise authentication services from ForgeRock OpenAM to PingOne Advanced Identity Cloud and Microsoft Entra ID. This consultant will be responsible for designing and executing a secure, scalable migration strategy while minimizing business disruption and ensuring a seamless transition for users and applications. The ideal candidate has deep expertise in enterprise identity platforms, single sign-on (SSO), federation protocols, and authentication architecture, along with a proven track record of leading large-scale IAM modernization initiatives. Key Responsibilities

  • Assess the current authentication environment, including ForgeRock OpenAM, application integrations, and identity workflows.
  • Develop a comprehensive migration strategy, roadmap, project timeline, and implementation plan.
  • Design, configure, and implement PingOne Advanced Identity Cloud and Microsoft Entra ID solutions.
  • Migrate applications and authentication services from ForgeRock OpenAM to the target platforms.
  • Configure, implement, and validate Single Sign-On (SSO) using OAuth 2.0, OpenID Connect (OIDC), and SAML 2.0.
  • Ensure authentication, authorization, and identity federation services meet enterprise security and compliance requirements.
  • Perform system integration testing, user acceptance testing (UAT), troubleshooting, and issue resolution throughout the migration.
  • Create comprehensive technical documentation, architecture diagrams, configuration guides, and operational runbooks.
  • Conduct knowledge transfer sessions and provide training to internal IT and security teams.
  • Deliver post-migration support, optimization, and stabilization to ensure a successful production rollout.
  • Collaborate with infrastructure, security, application development, and business stakeholders throughout the project lifecycle.
  • Follow IAM and cybersecurity best practices to maintain a secure, resilient authentication environment.

Requirements

  • 7+ years of experience in Identity and Access Management (IAM) engineering or consulting.
  • Hands-on experience with PingOne Advanced Identity Cloud.
  • Strong experience with Microsoft Entra ID (Azure Active Directory).
  • Experience administering and migrating ForgeRock OpenAM environments.
  • Expertise implementing and supporting Single Sign-On (SSO) and identity federation.
  • Strong knowledge of authentication and authorization protocols, including:
  • OAuth 2.0
  • OpenID Connect (OIDC)
  • SAML 2.0
  • Experience designing enterprise authentication architectures.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Excellent communication skills with the ability to document technical solutions and work with both technical and non-technical stakeholders.

Employment Eligibility: Gravity cannot transfer nor sponsor a work visa for this position. Applicants must be eligible to work in the U.S. for any employer directly (we are not open to contract or “corp to corp” agreements).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.gravityitresources.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all