Companies Qode ForgeRock Identity Engineer / Architect

About the role

Qode · Onsite

Role: ForgeRock Identity Engineer / Architect

Location: VA, NJ, TX, Atlanta, Colorado, Tampa


About the Role

Join a high-impact POD building a self-service federated SSO platform. You’ll be the hands-on ForgeRock expert designing and engineering a scalable identity broker integrating with Okta, Microsoft Entra ID, PingIdentity, and more. This is a build-from-scratch, code-heavy role—not admin/config.


Key Responsibilities

  • Design multi-tenant ForgeRock AM federation architecture
  • Build REST APIs for programmatic SAML SP connection lifecycle (create/validate/activate)
  • Implement SAML/OIDC flows, assertion validation, and secure session management across apps
  • Develop scripted authentication (Groovy/JS) and automate certificate lifecycle (monitoring & rotation)
  • Enable break-glass fallback, ensure high availability, and prepare SCIM-ready architecture
  • Migrate existing manual SP connections to automated framework


Must Have

  • 4+ years hands-on ForgeRock Access Manager (AM)
  • Strong SAML 2.0 (debugging raw assertions), OIDC/OAuth 2.0
  • Experience with ForgeRock REST APIs, scripted nodes, and keystore/X.509 management
  • API design & integrations, LDAP, secrets management (AWS/Vault)
  • Coding: Java/Groovy + CI/CD, API testing, SAML debugging tools


Nice to Have

  • ForgeRock IDM, SCIM 2.0, cloud (AWS/Azure/GCP)
  • Experience with Okta / Entra / Ping as IDP
  • Migration of manual SP setups to programmatic model


Why This Role?

You’ll define the identity architecture powering hundreds of future customers—owning critical decisions, building automation, and solving complex, real-world federation challenges.


Ready to apply to Qode?
Apply to Qode

Similar jobs

Sign up for suggestions tailored to the jobs you open and the searches you save.

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get the worldwide-remote edge.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free