1

Forgerock Architect Jobs in Oregon (NOW HIRING)

Forgerock Architect information

How does a ForgeRock Architect typically collaborate with cross-functional teams during identity and access management (IAM) projects?

A ForgeRock Architect works closely with security, development, operations, and business teams to design and implement IAM solutions tailored to organizational needs. They often facilitate workshops to gather requirements, create technical blueprints, and ensure seamless integration with existing IT systems. Collaboration includes mentoring developers on ForgeRock best practices, coordinating with project managers to meet deadlines, and communicating with stakeholders to align technical solutions with business objectives. This role requires strong interpersonal skills to navigate the complexities of cross-departmental projects and ensure successful outcomes.

What is the difference between Forgerock Architect vs Forgerock Developer?

AspectForgerock ArchitectForgerock Developer
Primary RoleDesigns and oversees the implementation of ForgeRock identity solutionsDevelops and codes ForgeRock modules and integrations
Required SkillsArchitecture, system design, project managementProgramming, scripting, technical troubleshooting
CertificationsForgeRock certifications, architecture credentialsForgeRock developer certifications
Work EnvironmentProject planning, client interaction, high-level designCode development, testing, debugging

The Forgerock Architect focuses on designing and planning ForgeRock solutions, ensuring they meet client needs, while the Forgerock Developer implements these designs through coding and technical development. Both roles require ForgeRock certifications but differ in scope and responsibilities.

What is a ForgeRock Architect?

A ForgeRock Architect is an IT professional who specializes in designing and implementing identity and access management (IAM) solutions using ForgeRock products. They are responsible for planning system architecture, integrating ForgeRock Identity Platform components, and ensuring security and scalability. Their expertise includes understanding authentication, authorization, user provisioning, and directory services. ForgeRock Architects often collaborate with stakeholders to tailor solutions that meet business and regulatory requirements.

What are the key skills and qualifications needed to thrive as a ForgeRock Architect?

To thrive as a ForgeRock Architect, you need deep expertise in identity and access management (IAM), strong knowledge of ForgeRock suite (such as Identity Management and Access Management), and relevant experience in solution architecture. Familiarity with tools like ForgeRock Directory Services, scripting languages, and cloud platforms, along with certifications like ForgeRock Certified Access Management Specialist, is highly valuable. Excellent problem-solving, stakeholder communication, and project leadership skills help you design and implement secure, scalable IAM solutions. These competencies ensure robust security, seamless user experiences, and the successful delivery of complex identity projects.
What are popular job titles related to Forgerock Architect jobs in Oregon? For Forgerock Architect jobs in Oregon, the most frequently searched job titles are:
What job categories do people searching Forgerock Architect jobs in Oregon look for? The top searched job categories for Forgerock Architect jobs in Oregon are:
What cities in Oregon are hiring for Forgerock Architect jobs? Cities in Oregon with the most Forgerock Architect job openings:

Cyber Identity - PlainID/PBAC Engineering Manager II

Deloitte

Portland, OR • On-site

Full-time

Posted 5 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

45th of 150 rated financial services


Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Position Summary
As an experienced PlainID professional at Deloitte Consulting, you will be responsible for delivering high-quality work products within defined timelines while providing delivery and technical leadership to the PBAC engagement team who delivers the PBAC/ABAC authorization tools including PlainID. This role combines deep technical ownership with engineering expertise, governance, and stakeholder management.

Work you'll do

As a PlainID professional, you will:

  • Configure and implement the PlainID Authorization Platform within client environments, including policy modelling and decision-point/information-point setup.
  • Lead technical discussions with Enterprise architects and IAM stake holders.
  • Lead a PBAC team for successful and seamless delivery.
  • Design fine-grained, attribute-based access policies (PBAC/ABAC) that translate business rules into technical controls, including row- and column-level data access restrictions where needed.
  • Integrate PlainID with client identity providers (Okta, Microsoft Entra ID, Ping Identity, ForgeRock), API gateways, microservices, and data platforms such as Snowflake or Big Query.
  • Support the full policy lifecycle - authoring, testing, versioning, and deployment - using PlainID's visual policy modeling and policy-as-code capabilities.
  • Run requirements sessions with client stakeholders to document current-state access patterns and design the target-state authorization model.
  • Troubleshoot policy conflicts, integration issues, and authorization-decision errors across the client's technology stack.
  • Lead the testing, validation, and go-live activities, including access-decision auditing and performance checks.
  • Lead the team to produce clear technical documentation - policy catalogs, integration diagrams, runbooks - for both the client and the internal delivery team.
  • Partner with engagement leads and architects to keep delivery on track and surface risks early.
  • Stay current on PlainID's platform roadmap, including emerging capabilities for AI agent and machine-identity authorization.
  • Lead the team to establish and maintain runbooks, SOPs, knowledge articles, and documentation standards for repeatable and governed support operations.
  • Lead the conversation with client stakeholders, internal teams, and third-party vendors to resolve defects, manage dependencies, and improve service outcomes.

The Team

Enables trust and safety of online communications and digital products, protecting users, consumers, and patients from harm. Enables clients to provide consumer confidence in knowing with whom they are dealing and ensuring the integrity of access to data.

Qualifications

Required:

         7+ years of total experience, including strong hands-on experience in PlainID and access management implementation.

         3+ years with access control models - specifically PBAC - and how each maps to real enterprise use cases.

         3+ years of experience integrating and supporting complex integrations and connectors for PIP integration.

         Must have strong knowledge of ensuring compliance with internal and external regulations, including SOX, GDPR, and ISO standards.

         Experience integrating with identity providers and standard protocols: OAuth 2.0, OpenID Connect, SAML, JWT.

         Comfort with policy-as-code concepts and reading/writing structured policy logic (e.g., Rego or similar rules-based languages).

         Working knowledge of APIs and microservices architectures, plus experience with at least one API gateway (Apigee, Kong, Azure API Management, or similar).

         Proven ownership of CAB/change governance, release management, and stakeholder management.

         Advanced troubleshooting capability with strong knowledge of PlainID integration.

  • Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Previous consulting or Big 4 experience preferred.
  • Experience with RBAC, ABAC
  • Strong documentation, reporting, and executive communication skills.
  • Ability to manage vendor coordination

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.


#CyberDTP27


Qualifications:

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Position Summary
As an experienced PlainID professional at Deloitte Consulting, you will be responsible for delivering high-quality work products within defined timelines while providing delivery and technical leadership to the PBAC engagement team who delivers the PBAC/ABAC authorization tools including PlainID. This role combines deep technical ownership with engineering expertise, governance, and stakeholder management.

Work you'll do

As a PlainID professional, you will:

  • Configure and implement the PlainID Authorization Platform within client environments, including policy modelling and decision-point/information-point setup.
  • Lead technical discussions with Enterprise architects and IAM stake holders.
  • Lead a PBAC team for successful and seamless delivery.
  • Design fine-grained, attribute-based access policies (PBAC/ABAC) that translate business rules into technical controls, including row- and column-level data access restrictions where needed.
  • Integrate PlainID with client identity providers (Okta, Microsoft Entra ID, Ping Identity, ForgeRock), API gateways, microservices, and data platforms such as Snowflake or Big Query.
  • Support the full policy lifecycle - authoring, testing, versioning, and deployment - using PlainID's visual policy modeling and policy-as-code capabilities.
  • Run requirements sessions with client stakeholders to document current-state access patterns and design the target-state authorization model.
  • Troubleshoot policy conflicts, integration issues, and authorization-decision errors across the client's technology stack.
  • Lead the testing, validation, and go-live activities, including access-decision auditing and performance checks.
  • Lead the team to produce clear technical documentation - policy catalogs, integration diagrams, runbooks - for both the client and the internal delivery team.
  • Partner with engagement leads and architects to keep delivery on track and surface risks early.
  • Stay current on PlainID's platform roadmap, including emerging capabilities for AI agent and machine-identity authorization.
  • Lead the team to establish and maintain runbooks, SOPs, knowledge articles, and documentation standards for repeatable and governed support operations.
  • Lead the conversation with client stakeholders, internal teams, and third-party vendors to resolve defects, manage dependencies, and improve service outcomes.

The Team

Enables trust and safety of online communications and digital products, protecting users, consumers, and patients from harm. Enables clients to provide consumer confidence in knowing with whom they are dealing and ensuring the integrity of access to data.

Qualifications

Required:

         7+ years of total experience, including strong hands-on experience in PlainID and access management implementation.

         3+ years with access control models - specifically PBAC - and how each maps to real enterprise use cases.

         3+ years of experience integrating and supporting complex integrations and connectors for PIP integration.

         Must have strong knowledge of ensuring compliance with internal and external regulations, including SOX, GDPR, and ISO standards.

         Experience integrating with identity providers and standard protocols: OAuth 2.0, OpenID Connect, SAML, JWT.

         Comfort with policy-as-code concepts and reading/writing structured policy logic (e.g., Rego or similar rules-based languages).

         Working knowledge of APIs and microservices architectures, plus experience with at least one API gateway (Apigee, Kong, Azure API Management, or similar).

         Proven ownership of CAB/change governance, release management, and stakeholder management.

         Advanced troubleshooting capability with strong knowledge of PlainID integration.

  • Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Previous consulting or Big 4 experience preferred.
  • Experience with RBAC, ABAC
  • Strong documentation, reporting, and executive communication skills.
  • Ability to manage vendor coordination

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.


#CyberDTP27


Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom