1

Forgerock Engineer Jobs in Texas (NOW HIRING)

Architect-Java

Houston, TX · On-site

$60.25 - $81.25/hr

Proven experience as a Full Stack Java Developer, with a focus on IAM, cloud technologies, project ... Experience with IAM tools and platforms (e.g., Okta, ForgeRock, Microsoft Azure AD). Understanding ...

... ForgeRock \ PingAM \ PingOne Advanced Identity Cloud. • Experience with REST APIs, JSON, and scripting languages (Python, JavaScript, NodeJS). • Experience with programming languages (Java), SIEM ...

... ForgeRock \ PingAM \ PingOne Advanced Identity Cloud. Experience with REST APIs, JSON, and scripting languages (Python, JavaScript, NodeJS). Experience with programming languages (Java), SIEM ...

Working knowledge of OAuth 2.0, OpenID Connect, IAM, Ping Identity, and ForgeRock. * Proven ability to lead teams, mentor engineers, and deliver in Agile environments. * Strong analytical, problem ...

Working knowledge of OAuth 2.0, OpenID Connect, IAM, Ping Identity, and ForgeRock. * Proven ability to lead teams, mentor engineers, and deliver in Agile environments. * Strong analytical, problem ...

Working knowledge of OAuth 2.0, OpenID Connect, IAM, Ping Identity, and ForgeRock. * Proven ability to lead teams, mentor engineers, and deliver in Agile environments. * Strong analytical, problem ...

Showing results 21-40

Forgerock Engineer information

What is a ForgeRock engineer?

ForgeRock Engineers are IT professionals who specialize in implementing, configuring, and maintaining ForgeRock's identity and access management (IAM) solutions. Their work involves integrating ForgeRock products such as Identity Gateway, Access Management, Directory Services, and Identity Management into an organization's infrastructure. They ensure secure authentication, authorization, and user management, often working closely with security teams to meet compliance and security requirements. ForgeRock Engineers also troubleshoot issues, perform upgrades, and help customize solutions to fit business needs.

What are the key skills and qualifications needed to thrive as a ForgeRock engineer?

To thrive as a ForgeRock Engineer, you need expertise in identity and access management (IAM), knowledge of ForgeRock’s Identity Platform (including Access Management, Directory Services, and Identity Gateway), and often a degree in computer science or a related field. Familiarity with tools such as ForgeRock OpenAM, OpenIDM, LDAP, SAML, OAuth, and certifications like ForgeRock Certified Identity Management Specialist are highly valuable. Problem-solving abilities, strong communication, and a proactive approach to security issues are crucial soft skills in this role. These skills ensure the effective deployment, management, and troubleshooting of secure IAM solutions that protect organizational data and enable seamless user access.

What are some common challenges ForgeRock engineers face when integrating identity solutions with existing enterprise systems?

Forgerock Engineers often encounter challenges when integrating identity and access management platforms with legacy or heterogeneous enterprise systems. These challenges can include addressing compatibility issues, ensuring seamless user migration, and maintaining security compliance throughout the integration process. Close collaboration with infrastructure, security, and application teams is usually required to align technical requirements and minimize disruptions. Staying up to date with Forgerock's evolving tools and best practices also helps in overcoming integration hurdles efficiently.

What is the difference between Forgerock Engineer vs Forgerock Developer?

AspectForgerock EngineerForgerock Developer
Primary FocusImplementing and maintaining Forgerock identity solutions, system integration, and infrastructure setup.Developing, customizing, and scripting within Forgerock platforms to meet specific client needs.
Required SkillsKnowledge of Forgerock products, system administration, security protocols, and integration techniques.Proficiency in coding, scripting, and API development within Forgerock environments.
CertificationsForgerock certifications, security certifications, and related credentials.Forgerock certifications, programming certifications, and API development credentials.

While both roles work within the Forgerock ecosystem, Forgerock Engineers focus on deployment, configuration, and system integration, whereas Forgerock Developers concentrate on customizing and coding solutions within the platform. Both roles often collaborate but serve different technical needs in identity management projects.

What are popular job titles related to Forgerock Engineer jobs in Texas?

For Forgerock Engineer jobs in Texas, the most frequently searched job titles are:

What job categories do people searching Forgerock Engineer jobs in Texas look for?

The top searched job categories for Forgerock Engineer jobs in Texas are:

What cities in Texas are hiring for Forgerock Engineer jobs?

Cities in Texas with the most Forgerock Engineer job openings:

Infographic showing various Forgerock Engineer job openings in Texas as of August 2026, with employment types broken down into 92% Full Time, 3% Part Time, and 5% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution.

Senior Identity & Access Management (CIAM) Engineer

PepsiCo

Plano, TX • On-site

$80K - $134K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 18 days ago


PepsiCo rating

7.5

Company rating: 7.5 out of 10

Based on 903 frontline employees who took The Breakroom Quiz

153rd of 443 rated food and drinks producers


Job description

Overview

The Identity Access Management (IAM) Engineer will serve as a hands-on technical resource with strong Customer Identity and Access Management (CIAM) expertise, responsible for implementing, supporting, and improving secure identity solutions for B2B, B2C, and external user populations.

This role requires solid technical experience in CIAM platforms such as Okta Customer Identity Cloud/Auth0, Okta, Ping, or ForgeRock, with strong hands-on knowledge of OAuth 2.0, OpenID Connect, SAML, JWT, SCIM, API integrations, MFA, passwordless, adaptive authentication, and customer identity lifecycle flows.

The engineer will work on CIAM implementation activities from requirements through production support, including platform configuration, application integration, testing, troubleshooting, documentation, and operational handoff.

The successful candidate should be able to operate independently on technical tasks, support CIAM design discussions, strengthen security controls, and help onboard digital applications while maintaining good user experience and compliance alignment.

Must have strong hands-on configuration, scripting, API integration, troubleshooting, and support experience in CIAM or access management environments.

This role is based out of Plano, Texas and requires coming into the office.


Responsibilities
  • Serve as a hands-on CIAM technical resource for implementation, configuration, integration, and production support.
  • Configure and support CIAM solutions using Okta Customer Identity Cloud/Auth0, Okta, Ping, ForgeRock, or comparable platforms.
  • Build and support customer identity flows including registration, login, MFA, passwordless authentication, social login, consent, profile management, account recovery, and progressive profiling.
  • Support secure application integrations using OAuth 2.0, OpenID Connect, SAML, JWT, SCIM, REST APIs, SDKs, webhooks, and token-based authorization patterns.
  • Implement B2B and B2C identity patterns for web, mobile, portal, API, eCommerce, and partner-facing applications.
  • Configure platform capabilities such as Auth0 Actions, Rules, Hooks, Organizations, Management APIs, Okta Workflows, Identity Engine, Universal Directory, and Lifecycle Management.
  • Develop scripts, workflows, and automation to support identity lifecycle, application onboarding, monitoring, reporting, and operational efficiency.
  • Work with Cybersecurity, API, architecture, digital product, and application teams to support secure authentication and authorization patterns.
  • Participate in CIAM roadmap delivery, platform modernization, migrations, and capability enhancements.
  • Troubleshoot authentication, federation, token, consent, profile, directory, API, latency, and production availability issues.
  • Support monitoring, alerting, logging, audit, and reporting using tools such as Splunk, ELK, Prometheus, or native platform logs.
  • Implement security controls such as adaptive authentication, attack protection, bot protection, risk-based access, identity proofing integrations, and zero trust-aligned policies.
  • Support privacy, regulatory, audit, and compliance requirements related to customer identity, consent, data protection, and access governance.
  • Use DevSecOps practices, CI/CD pipelines, Git-based configuration management, Terraform, Ansible, or similar tools to improve repeatability and reduce manual changes.
  • Create and maintain integration patterns, technical design documents, runbooks, standards, and operational handoff materials.
  • Provide Level 2/Level 3 support, incident support, root cause analysis, and improvement recommendations for CIAM services.
  • Share technical knowledge with team members and contribute to Agile DevOps delivery practices.

Compensation and Benefits:

  • The expected compensation range for this position is between $80,200 - $134,250.
  • Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
  • Bonus based on performance and eligibility target payout is 8% of annual salary paid out annually.
  • Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
  • In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.

Qualifications

Minimum Qualifications:

  • 8+ years of overall IT experience with hands-on engineering or support background.
  • 6+ years of IAM, access management, authentication, federation, or identity engineering experience.
  • 4+ years of hands-on CIAM implementation or support experience for B2B, B2C, external customer, partner, or digital identity use cases.
  • Hands-on experience with Okta Customer Identity Cloud/Auth0, Okta, Ping, ForgeRock, or comparable CIAM platform.
  • Strong working knowledge of OAuth 2.0, OpenID Connect, SAML 2.0, JWT, SCIM, LDAP, REST APIs, SDKs, webhooks, and API security.
  • Hands-on experience configuring CIAM applications, connections, identity providers, login/sign-up flows, redirect URIs, callback URLs, logout URLs, custom domains, and branding.
  • Good understanding of OAuth/OIDC flows including Authorization Code with PKCE, Client Credentials, refresh tokens, scopes, claims, audiences, issuers, token validation, and token lifetime management.
  • Experience integrating CIAM with single-page applications, mobile apps, backend APIs, portals, and partner-facing applications using vendor SDKs, REST APIs, and modern web frameworks.
  • Experience configuring or supporting MFA, passwordless authentication, social login, enterprise federation, user registration, account recovery, profile management, and consent capture.
  • Hands-on experience with custom claims, rules/actions/hooks, API permissions, RBAC, groups/roles, attribute mapping, and user metadata/profile attribute management.
  • Experience troubleshooting CIAM issues related to redirects, SSO sessions, token errors, certificate/metadata mismatches, CORS, API authorization failures, login failures, and user provisioning issues.
  • Understanding of CIAM security controls such as adaptive MFA, bot/credential attack protection, breached password detection, rate limits, tenant logs, suspicious activity monitoring, and audit logging.
  • Hands-on scripting or development experience using Java, JavaScript, Node.js, React, Spring Boot, Python, PowerShell, or similar technologies.
  • Experience with CI/CD, DevSecOps, Git, Terraform, Ansible, Jenkins, GitHub Actions, Azure DevOps, or comparable automation tools.
  • Experience supporting production IAM or CIAM platforms, including monitoring, logging, incident support, root cause analysis, and performance troubleshooting.
  • BS/BA degree in Computer Science, Information Security, Engineering, or equivalent work experience.
  • Okta Certified Administrator preferred; Okta Certified Consultant, Okta Certified Developer, Auth0/Okta Customer Identity Cloud certification, or Ping/ForgeRock certification is a plus.
  • CISSP, CIAM, CISM, or comparable security certification is a plus.

Preferred Qualifications:

  • Experience implementing enterprise CIAM solutions at scale.
  • Hands-on experience with Okta Customer Identity Cloud/Auth0 capabilities such as Actions, Rules, Hooks, Organizations, Management API, attack protection, log streaming, and custom domains.
  • Experience with Okta Identity Engine, Universal Directory, Lifecycle Management, Workflows, Administrative APIs, and application integration patterns.
  • Exposure to Ping, ForgeRock, SiteMinder, Azure AD/Entra ID, AWS Cognito, or other identity platforms is preferred.
  • Ability to support secure B2B and B2C identity models for large-volume customer environments, including retail, eCommerce, mobile, portal, or partner ecosystems.
  • Good understanding of authentication and authorization patterns including SSO, federation, token exchange, refresh tokens, session management, scopes, claims, consent, and delegated authorization.
  • Understanding of API gateways, microservices, REST integration, reverse proxies, load balancers, headers-based authentication, and secure API access patterns.
  • Experience integrating CIAM with web applications, mobile applications, CRM, Salesforce, SAP, eCommerce platforms, directories, data platforms, or downstream business systems.
  • Awareness of privacy and security requirements such as GDPR, CCPA, consent capture, data minimization, audit logging, and customer data protection.
  • Experience with security controls such as risk-based authentication, adaptive MFA, bot mitigation, credential attack protection, suspicious activity detection, and passwordless authentication.
  • Hands-on experience with Java, Node.js, JavaScript, React, Spring Boot, Python, PowerShell, SQL, and REST API development.
  • Experience deploying or supporting identity solutions in AWS, Azure, or hybrid environments.
  • Exposure to Docker, Kubernetes, Linux, Windows, middleware, Apache, and enterprise infrastructure components.
  • Experience with Splunk, ELK, Prometheus, native CIAM logs, SIEM integrations, or operational dashboards.
  • Experience creating reusable integration patterns, runbooks, standards, and technical documentation.
  • Experience supporting application migrations from legacy IAM platforms to modern CIAM capabilities.
  • Ability to troubleshoot complex issues while continuing to build deeper SME-level expertise.

Non-Technical skills:

  • Strong communication skills with the ability to explain CIAM concepts to technical teams, application owners, and security partners.
  • Self-starter who can analyze requirements, identify risks, propose solutions, and complete technical tasks with limited guidance.
  • Strong analytical and problem-solving skills, especially during integration troubleshooting and production support.
  • Ability to balance security, user experience, scalability, performance, compliance, and delivery timelines.
  • Ability to work across global teams, vendors, cybersecurity, architecture, product, and application teams.
  • Good documentation discipline, including integration guides, runbooks, standards, and operational handoff materials.
  • Flexible and able to adapt to changing priorities in a fast-paced enterprise environment.

EEO Statement

Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance.

All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity

If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy.

Please view our Pay Transparency Statement

Qualifications:

Minimum Qualifications:

  • 8+ years of overall IT experience with hands-on engineering or support background.
  • 6+ years of IAM, access management, authentication, federation, or identity engineering experience.
  • 4+ years of hands-on CIAM implementation or support experience for B2B, B2C, external customer, partner, or digital identity use cases.
  • Hands-on experience with Okta Customer Identity Cloud/Auth0, Okta, Ping, ForgeRock, or comparable CIAM platform.
  • Strong working knowledge of OAuth 2.0, OpenID Connect, SAML 2.0, JWT, SCIM, LDAP, REST APIs, SDKs, webhooks, and API security.
  • Hands-on experience configuring CIAM applications, connections, identity providers, login/sign-up flows, redirect URIs, callback URLs, logout URLs, custom domains, and branding.
  • Good understanding of OAuth/OIDC flows including Authorization Code with PKCE, Client Credentials, refresh tokens, scopes, claims, audiences, issuers, token validation, and token lifetime management.
  • Experience integrating CIAM with single-page applications, mobile apps, backend APIs, portals, and partner-facing applications using vendor SDKs, REST APIs, and modern web frameworks.
  • Experience configuring or supporting MFA, passwordless authentication, social login, enterprise federation, user registration, account recovery, profile management, and consent capture.
  • Hands-on experience with custom claims, rules/actions/hooks, API permissions, RBAC, groups/roles, attribute mapping, and user metadata/profile attribute management.
  • Experience troubleshooting CIAM issues related to redirects, SSO sessions, token errors, certificate/metadata mismatches, CORS, API authorization failures, login failures, and user provisioning issues.
  • Understanding of CIAM security controls such as adaptive MFA, bot/credential attack protection, breached password detection, rate limits, tenant logs, suspicious activity monitoring, and audit logging.
  • Hands-on scripting or development experience using Java, JavaScript, Node.js, React, Spring Boot, Python, PowerShell, or similar technologies.
  • Experience with CI/CD, DevSecOps, Git, Terraform, Ansible, Jenkins, GitHub Actions, Azure DevOps, or comparable automation tools.
  • Experience supporting production IAM or CIAM platforms, including monitoring, logging, incident support, root cause analysis, and performance troubleshooting.
  • BS/BA degree in Computer Science, Information Security, Engineering, or equivalent work experience.
  • Okta Certified Administrator preferred; Okta Certified Consulta...

What PepsiCo employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


PepsiCo logo

About PepsiCo

Sourced by ZipRecruiter

PepsiCo products are enjoyed by consumers more than one billion times a day in more than 200 countries and territories around the world. PepsiCo generated $86 billion in net revenue in 2022, driven by a complementary beverage and convenient foods portfolio that includes Lay's, Doritos, Cheetos, Gatorade, Pepsi-Cola, Mountain Dew, Quaker, and SodaStream. PepsiCo's product portfolio includes a wide range of enjoyable foods and beverages, including many iconic brands that generate more than $1 billion each in estimated annual retail sales.

Industry

Food and drink manufacturing

Company size

10,000+ Employees

Headquarters location

Purchase, NY, US

Year founded

1965