HamburgerMenu
hirist

ForgeRock Lead Engineer - iAM

WSNE Consulting
7 - 11 Years
Multiple Locations

Posted on: 31/08/2026

Job Description

Job Description:

We are looking for an experienced ForgeRock Lead Engineer to serve as a technical SME for enterprise Identity and Access Management (IAM) solutions. The role will be responsible for the design, administration, security, integration, and ongoing optimization of the ForgeRock platform, while providing technical leadership to IAM engineering teams.

The candidate will work closely with business, security, application, infrastructure, and architecture teams to translate requirements into secure and scalable identity solutions. The role will also contribute to platform modernization, automation, governance, and operational excellence across the ForgeRock environment.

Key Responsibilities:

- Provide technical leadership and SME expertise across the ForgeRock Identity Management (IDM), Access Management (AM), Directory Services (DS), and Identity Gateway (IG) components.

- Design, configure, administer, and maintain ForgeRock environments across development, testing, and production.

- Perform platform upgrades, patches, migrations, configuration changes, and environment maintenance.

- Monitor platform health, performance, availability, and logs using tools such as Splunk, ELK, Prometheus, or equivalent monitoring platforms.

- Manage Directory Services, including LDAP schemas, indexes, replication, and directory performance.

- Design and implement identity lifecycle management and provisioning solutions.

- Configure and maintain reconciliation and synchronization processes between ForgeRock IDM and enterprise systems such as HR platforms, Active Directory, and other identity repositories.

- Design and implement application integrations using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), JWT, and REST APIs.

- Configure authentication journeys/trees, authentication nodes, authorization policies, MFA, and adaptive authentication mechanisms.

- Support onboarding of enterprise applications onto the IAM platform and ensure secure integration patterns.

- Implement RBAC, least-privilege access, access policies, and identity governance controls.

- Support audit, compliance, and security requirements related to identity and access management, including applicable SOX, GDPR, and other regulatory controls.

- Troubleshoot complex authentication, authorization, session, provisioning, synchronization, and integration issues.

- Perform root-cause analysis for recurring incidents and implement permanent corrective actions.

- Develop automation and customizations using Java, JavaScript, and Groovy where required.

- Support deployment automation and configuration management through CI/CD and DevSecOps practices.

- Work with cloud platforms such as AWS, Azure, or GCP to deploy and operate IAM solutions.

- Collaborate with security, infrastructure, application, and architecture teams to define secure identity and integration patterns.

- Contribute to CIAM/IAM modernization and migration initiatives, including migrations from legacy or other IAM platforms.

- Establish technical standards, implementation guidelines, operational procedures, and best practices for ForgeRock environments.

- Lead technical discussions, design reviews, code/configuration reviews, and solution walkthroughs.

- Mentor junior and mid-level IAM engineers and provide technical guidance on ForgeRock administration, development, troubleshooting, and best practices.

- Support knowledge transfer, documentation, and operational readiness for IAM-managed services.

Required Skills & Experience:

- 7 - 11 years of overall IT experience, with strong hands-on experience in Identity and Access Management.

- 5+ years of hands-on experience with ForgeRock Identity Management (IDM).

- Strong hands-on expertise with one or more ForgeRock components, with good understanding of the broader ForgeRock platform.

- Strong knowledge of ForgeRock AM, IDM, DS, and IG.

- Strong experience with SAML 2.0, OAuth 2.0, OpenID Connect, JWT, REST APIs, and SSO.

- Strong understanding of LDAP and directory services, including schemas, indexes, replication, and troubleshooting.

- Experience implementing identity lifecycle management, provisioning, reconciliation, and synchronization.

- Experience configuring authentication journeys/trees, authentication nodes, MFA, and authorization policies.

- Hands-on scripting/development experience using Java, JavaScript, or Groovy.

- Good understanding of IAM security, RBAC, access controls, least privilege, and identity governance.

- Experience working with Linux/Unix environments.

- Exposure to CI/CD, DevSecOps, and automated deployment practices.

- Experience with cloud environments such as AWS, Azure, or GCP.

- Strong troubleshooting, analytical, and problem-solving skills.

- Strong communication and stakeholder-management skills.

- Ability to independently lead technical activities and mentor engineering teams.

Good to Have:

- Experience with Docker and Kubernetes.

- Experience with Terraform, Ansible, or other configuration/IaC tools.

- Experience with CIAM implementations and migrations involving Ping, Okta, or custom IAM platforms.

- Experience integrating IAM solutions with enterprise applications and identity sources such as Workday and Active Directory.

- Knowledge of security monitoring and observability platforms such as Splunk, ELK, or Prometheus.

- ForgeRock/Ping Identity certifications.

- Experience working in large-scale global enterprise IAM environments.

Education & Certification:

- Bachelors degree or higher in Computer Science, Information Technology, Engineering, MIS, or a related discipline.

- 15 years of full-time education is required.

- ForgeRock FRX-AM-CSE certification or equivalent certification is preferred.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...