ForgeRock Access Management (Workforce IAM)
Job Description
The role involves delivering enterprise-scale identity and access transformation programs focused on employee, contractor, and privileged user access across hybrid and cloud environments. The selected candidate will be responsible for hands-on configuration of ForgeRock Access Management capabilities, enabling secure SSO, conditional/adaptive access, and MFA with emphasis on phishing-resistant authentication (e.g., FIDO2/WebAuthn/passkeys) and security hardening. You will collaborate with client stakeholders to build Zero Trust-aligned workforce identity architectures and ensure audit-ready controls.\n\nRequired Skills & Qualifications\n3-7 years of experience in Identity & Access Management (IAM).\nMinimum 2 years of hands-on experience with ForgeRock Access Management (AM) implementing workforce authentication and SSO.\nStrong understanding of authentication and federation standards: SAML 2.0, OAuth 2.0, OpenID Connect, JWT/JWS/JWE.\nHands-on experience implementing conditional/adaptive access and step-up authentication using ForgeRock Authentication Trees/Policies.\nHands-on experience implementing MFA, including phishing-resistant MFA (FIDO2/WebAuthn/passkeys/security keys) and secure enrollment/recovery flows.\nExperience integrating with Active Directory / LDAP and troubleshooting directory/authentication issues.\nExperience with REST APIs and basic scripting (JavaScript/Groovy; familiarity with PowerShell or Python is a plus).\nStrong troubleshooting skills across auth flows, sessions, cookies, redirects, and protocol-level issues.\n\nPreferred Qualifications\nExperience with ForgeRock Identity Management (IDM) and/or ForgeRock Identity Gateway (IG).\nExperience with containerized deployments (Docker/Kubernetes/OpenShift) and HA/DR architectures for IAM.\nExposure to SIEM/log analytics (Splunk/ELK) and building audit-ready authentication logging and reporting.\nKnowledge of Zero Trust architecture patterns, device trust concepts, and modern authentication hardening practices.\nExperience with cloud platforms (Azure/AWS/GCP) and hybrid identity integrations.\nRelevant certifications (nice to have): ForgeRock certifications, Security+, or equivalent IAM/security certifications.\n\nPlease let me know if you are interested in this position and send me your resume to