IAM Architect
Chaska, MN · On-site
Expertise in IAM platforms (Okta, SailPoint, Ping, ForgeRock), PAM solutions (CyberArk, BeyondTrust ... Architect IAM for engineering design workflows, integrating with EDA tools (Cadence, Synopsys ...
Quick apply
Chaska, MN · On-site
Expertise in IAM platforms (Okta, SailPoint, Ping, ForgeRock), PAM solutions (CyberArk, BeyondTrust ... Architect IAM for engineering design workflows, integrating with EDA tools (Cadence, Synopsys ...
Quick apply
Chaska, MN · On-site
Expertise in IAM platforms (Okta, SailPoint, Ping, ForgeRock), PAM solutions (CyberArk, BeyondTrust ... Architect IAM for engineering design workflows, integrating with EDA tools (Cadence, Synopsys ...
Plano, TX · On-site
$53 - $72.50/hr
Lead the design and architecture of IAM systems including SSO, MFA, provisioning, directory ... Experience in Amazon Web Services ,ForgeRock and OKTA implementation on SAAS * Experience with ...
Quick apply
Plano, TX · On-site
$53 - $72.50/hr
Lead the design and architecture of IAM systems including SSO, MFA, provisioning, directory ... Experience in Amazon Web Services ,ForgeRock and OKTA implementation on SAAS * Experience with ...
IDM (Identity Management) architect with SiteMinder /ForgeRock experience Location: Atlanta, GA Duration: 6 Months Manage IDM web services implementation Meet the evolving and diverse needs of a ...
IDM (Identity Management) architect with SiteMinder /ForgeRock experience Location: Atlanta, GA Duration: 6 Months Manage IDM web services implementation Meet the evolving and diverse needs of a ...
Plano, TX · On-site
$53 - $72.50/hr
IAM Architect/Lead Location: Plano, TX - Onsite Duration: 12+ Months Consultant needs to be local ... Experience in Amazon Web Services ,ForgeRock and OKTA implementation on SAAS * Experience with ...
Quick apply
Plano, TX · On-site
$53 - $72.50/hr
IAM Architect/Lead Location: Plano, TX - Onsite Duration: 12+ Months Consultant needs to be local ... Experience in Amazon Web Services ,ForgeRock and OKTA implementation on SAAS * Experience with ...
Chicago, IL · On-site
$73 - $94/hr
CIAM Architect Location:- Chicago,IL Duration:- Full Time Must Have Technical/Functional Skills ... Good to have working experience on other CIAM products like PingFederate, PingAccess, ForgeRock
Quick apply
Chicago, IL · On-site
$73 - $94/hr
CIAM Architect Location:- Chicago,IL Duration:- Full Time Must Have Technical/Functional Skills ... Good to have working experience on other CIAM products like PingFederate, PingAccess, ForgeRock
Job responsibilities * Architect and oversee identity provisioning, role management, and ... Deploy and manage IAM solutions such as EntraID, Ping, ForgeRock, CyberArk, Hashicorp Vault, and ...
Job responsibilities * Architect and oversee identity provisioning, role management, and ... Deploy and manage IAM solutions such as EntraID, Ping, ForgeRock, CyberArk, Hashicorp Vault, and ...
Job responsibilities * Architect and oversee identity provisioning, role management, and ... Deploy and manage IAM solutions such as EntraID, Ping, ForgeRock, CyberArk, Hashicorp Vault, and ...
Job responsibilities * Architect and oversee identity provisioning, role management, and ... Deploy and manage IAM solutions such as EntraID, Ping, ForgeRock, CyberArk, Hashicorp Vault, and ...
Westbrook, ME · On-site +1
$66 - $85.50/hr
Architect and govern secure authentication and authorization patterns across diverse customer use ... ForgeRock, Microsoft Entra ID) * Expertise in OIDC, OAuth 2.0, SAML, FIDO2/WebAuthn, and SCIM
Westbrook, ME · On-site +1
$66 - $85.50/hr
Architect and govern secure authentication and authorization patterns across diverse customer use ... ForgeRock, Microsoft Entra ID) * Expertise in OIDC, OAuth 2.0, SAML, FIDO2/WebAuthn, and SCIM
Seattle, WA · On-site
$171K - $260K/yr
Job responsibilities * Architect and oversee identity provisioning, role management, and ... Deploy and manage IAM solutions such as EntraID, Ping, ForgeRock, CyberArk, Hashicorp Vault, and ...
Seattle, WA · On-site
$171K - $260K/yr
Job responsibilities * Architect and oversee identity provisioning, role management, and ... Deploy and manage IAM solutions such as EntraID, Ping, ForgeRock, CyberArk, Hashicorp Vault, and ...
Active Directory Architect/Network Engineer Selected candidate will manage and maintain current IDM, Linux and AD infrastructure, assist the server team with day to day operations (ForgeRock, AD ...
Active Directory Architect/Network Engineer Selected candidate will manage and maintain current IDM, Linux and AD infrastructure, assist the server team with day to day operations (ForgeRock, AD ...
Atlanta, GA · On-site +1
$61 - $79.50/hr
At least 6 years of experience as a Software Architect focusing on building APIs and integration ... major IAM provider such as ForgeRock, Ping Identity or Okta * Understanding of Auth Token ...
Atlanta, GA · On-site +1
$61 - $79.50/hr
At least 6 years of experience as a Software Architect focusing on building APIs and integration ... major IAM provider such as ForgeRock, Ping Identity or Okta * Understanding of Auth Token ...
Boston, MA · On-site
$100K - $130K/yr
Must Have Technical/Functional Skills Hands-on Cloud Architect to lead the Cloud Migration ... ForgeRock, Gateways, WAFs, Load balancers, message, event and other communication components • ...
Boston, MA · On-site
$100K - $130K/yr
Must Have Technical/Functional Skills Hands-on Cloud Architect to lead the Cloud Migration ... ForgeRock, Gateways, WAFs, Load balancers, message, event and other communication components • ...
Plano, TX · On-site
Architect solutions and create detailed Solution Architecture Documents (covering the Experience ... Azure AD, ForgeRock, SailPoint)
Quick apply
Plano, TX · On-site
Architect solutions and create detailed Solution Architecture Documents (covering the Experience ... Azure AD, ForgeRock, SailPoint)
Jersey City, NJ · On-site
$138K - $182K/yr
Collaborate with engineering, architecture, and security teams to define, prioritize, and deliver CIAM features. * Serve as the subject matter expert on ForgeRock, Ping Identity, and Transmit ...
Jersey City, NJ · On-site
$138K - $182K/yr
Collaborate with engineering, architecture, and security teams to define, prioritize, and deliver CIAM features. * Serve as the subject matter expert on ForgeRock, Ping Identity, and Transmit ...
IAM Architect - PingOne Advanced Identity Cloud (AIC) SME Location: Fort Mill, SC 29707 (Onsite ... Experience with ForgeRock/OpenAM migrations to PingOne AIC. Experience with DevOps and CI/CD tools.
IAM Architect - PingOne Advanced Identity Cloud (AIC) SME Location: Fort Mill, SC 29707 (Onsite ... Experience with ForgeRock/OpenAM migrations to PingOne AIC. Experience with DevOps and CI/CD tools.
Open Banking Principal Architect Work location : Memphis (TN), Charlotte (NC), Raleigh (NC) or ... OAuth2.0, OIDC, mTLS with Okta/Ping/Azure AD/ForgeRock; Good to Have: Advanced tokenization and FPE
Open Banking Principal Architect Work location : Memphis (TN), Charlotte (NC), Raleigh (NC) or ... OAuth2.0, OIDC, mTLS with Okta/Ping/Azure AD/ForgeRock; Good to Have: Advanced tokenization and FPE
Dallas, TX · Hybrid
$55 - $60/hr
IAM Architecture & Design (SSO, MFA, Provisioning, Directory Services, PAM), Java, NodeJS, Spring ... ForgeRock, Okta, AWS SaaS IAM Implementation, Monitoring Tools (CloudWatch, RockMon, AppDynamics ...
Quick apply
Dallas, TX · Hybrid
$55 - $60/hr
IAM Architecture & Design (SSO, MFA, Provisioning, Directory Services, PAM), Java, NodeJS, Spring ... ForgeRock, Okta, AWS SaaS IAM Implementation, Monitoring Tools (CloudWatch, RockMon, AppDynamics ...
Memphis, TN · On-site
Maintains First Horizon's Security Architecture Pattern Inventory (across identity, data ... IAM for associates (Entra ID, Active Directory) and clients (Transmit Security, ForgeRock/Ping, or ...
Memphis, TN · On-site
Maintains First Horizon's Security Architecture Pattern Inventory (across identity, data ... IAM for associates (Entra ID, Active Directory) and clients (Transmit Security, ForgeRock/Ping, or ...
Springfield, VA · On-site
... ForgeRock, Okta, Ping Identity, or SailPoint. • Experience establishing ICAM within a Zero Trust Architecture (ZTA) framework. Company : SAIC specializes in IT, enterprise IT, engineering, and ...
Springfield, VA · On-site
... ForgeRock, Okta, Ping Identity, or SailPoint. • Experience establishing ICAM within a Zero Trust Architecture (ZTA) framework. Company : SAIC specializes in IT, enterprise IT, engineering, and ...
$138K - $182K/yr
Collaborate with engineering, architecture, and security teams to define, prioritize, and deliver CIAM features. * Serve as the subject matter expert on ForgeRock, Ping Identity, and Transmit ...
$138K - $182K/yr
Collaborate with engineering, architecture, and security teams to define, prioritize, and deliver CIAM features. * Serve as the subject matter expert on ForgeRock, Ping Identity, and Transmit ...
$10.10 - $18.77
7% of jobs
$18.77 - $27.45
0% of jobs
$27.45 - $36.12
3% of jobs
$42.52 is the 25th percentile. Wages below this are outliers.
$36.12 - $44.80
20% of jobs
$44.80 - $53.47
9% of jobs
$53.47 - $62.15
5% of jobs
The median wage is $64.12 / hr.
$62.15 - $70.83
23% of jobs
$74.40 is the 75th percentile. Wages above this are outliers.
$70.83 - $79.50
18% of jobs
$79.50 - $88.18
14% of jobs
$88.18 - $96.85
0% of jobs
$96.85 - $105.53
1% of jobs
$10
$61
$105
| Aspect | Forgerock Architect | Forgerock Developer |
|---|---|---|
| Primary Role | Designs and oversees the implementation of ForgeRock identity solutions | Develops and codes ForgeRock modules and integrations |
| Required Skills | Architecture, system design, project management | Programming, scripting, technical troubleshooting |
| Certifications | ForgeRock certifications, architecture credentials | ForgeRock developer certifications |
| Work Environment | Project planning, client interaction, high-level design | Code development, testing, debugging |
The Forgerock Architect focuses on designing and planning ForgeRock solutions, ensuring they meet client needs, while the Forgerock Developer implements these designs through coding and technical development. Both roles require ForgeRock certifications but differ in scope and responsibilities.

Full-time
Posted 12 days ago
- Experience with supplier/vendor IAM federation in complex semiconductor supply chains.
- Background in IT/OT convergence security for smart factories and Industry 4.0 initiatives.
- Knowledge of chip design workflows, engineering collaboration platforms, and secure IP vaults.
- Relevant certifications: CISSP, CCSP, Microsoft Identity & Access, Okta Certified, ISA/IEC 62443
Cybersecurity Expert.
Required Skills & Experience
8+ years of IAM experience, with at least 3 years in a strategic architecture role for a manufacturing or
semiconductor enterprise.
Proven ability to secure both IT and OT environments in global industrial operations.
Expertise in IAM platforms (Okta, SailPoint, Ping, ForgeRock), PAM solutions (CyberArk, BeyondTrust),
directory services & federation (LDAP, SAML, OAuth2, OpenID Connect, SCIM), Zero Trust IAM architecture
for hybrid cloud & on-premises.
Deep understanding of semiconductor industry workflows, including EDA tools and IP lifecycle
management.
Familiarity with industrial control system (ICS) security, OT protocols, and factory automation networks.
Strong knowledge of export control regulations (ITAR/EAR), IP protection strategies, and global data privacy
compliance.
Key Responsibilities
1. Semiconductor IP Protection
Implement least privilege access to safeguard sensitive chip design files, EDA tools, and proprietary
engineering data.
Architect IAM for engineering design workflows, integrating with EDA tools (Cadence, Synopsys, Mentor
Graphics).
Ensure strict segregation of duties and data residency controls to comply with export controls (ITAR/EAR)
and regional IP protection laws.
Develop federated identity and access models for secure collaboration with external R&D partners,
foundries, and design houses.
2. Factory OT Security & Operational Continuity
Design IAM solutions for Operational Technology (OT) environments, including MES, SCADA/PLC systems,
and factory automation equipment.
Extend Zero Trust principles to the shop floor, securing remote vendor access for equipment maintenance
without compromising uptime.
Integrate IAM with Industrial Control Systems (ICS), considering legacy equipment with limited native
authentication capabilities.
Work with OT security teams to segment access between IT and OT networks, minimizing lateral movement
risks in factories.
3. Global IAM Strategy & Governance
Define the enterprise IAM roadmap for all global sites, aligning with manufacturing, R&D, and supply chain
security requirements.
Standardize access provisioning workflows across factories, design centers, suppliers, and regional offices.
Develop role-based (RBAC) and attribute-based (ABAC) access models that address the needs of factory
operators, R&D engineers, external contractors and vendors, and supply chain partners.
4. Cloud & Hybrid IAM
Architect secure access to cloud-hosted semiconductor design environments and collaboration tools.
Integrate IAM for multi-cloud environments (Azure, AWS, GCP) supporting global engineering teams.
Enable secure identity federation for supply chain and ecosystem partners.
5. Risk Management & Compliance
Ensure IAM policies meet semiconductor industry compliance standards, including NIST 800-53, IEC 62443
(OT security), ISO 27001, and export control regulations (ITAR/EAR).
Lead access certification campaigns and automate identity lifecycle management for employees,
contractors, and vendors worldwide.
Provide IAM audit readiness for IP protection, export compliance, and global data privacy regulations
(GDPR, local DPAs
6. Technology Enablement & Integration - Lead the evaluation, deployment, and integration of enterprise IAM platforms (SailPoint, ForgeRock, Okta
Ping Identity) and Privileged Access Management (PAM) solutions (CyberArk, BeyondTrust).
Automate joiner-mover-leaver (JML) processes across IT, OT, and cloud environments.
Work closely with IT, OT, and cybersecurity teams to ensure high availability and minimal disruption in
production environments
Sourced by ZipRecruiter