IAM Engineer

Posted 3 days ago

ampstekFort Mill (SC)

SENIORITY

Senior

Apply

About the role

Job Title: IAM Engineer with Forge Rock
Location: Fort Mill, SC
Job Description: Experience in Identity and Access Management (IAM) Engineer specializing in designing, implementing, and managing IAM solutions using Forge Rock AIC / Ping Identity AIC.Hands on in configuring access policies, permissions, and identity lifecycle management processes. Hands on in scripting, journey development, and API integrations to enhance IAM functionality. Strong knowledge in performance tuning, troubleshooting, and ensuring high availability and security of IAM infrastructure. Implementation experience in Forge Rock AIC / Ping Identity AIC for a large enterprise, securing 50,000+ identities. SRE / SLM initiatives such as service-level objectives (SLOs), error budgeting, and resilience testing across IAM platforms. Development of API-driven IAM automation workflows, reducing manual effort and improving security posture. Enhanced authentication security by integrating OAuth 2.0 and OpenID Connect (OIDC) into the IAM platform. IAM configuration audit, adherence to NIST and SOC2 standards. Implementation using Forge Rock SDKs. Identity and access assessments and identify vulnerabilities and remediations within Forge Rock CIAM.Managed and configured Forge Rock CIAM components, including Forge Rock Identity Platform, Forge Rock Directory Services, and Forge Rock CIAM Identity Gateway. Solution designing experience on Sailpoint IIQ modules. Security audits and assessments. Good understanding in Okta implementations Develop and enforce IAM policies and procedures to enhance security posture and compliance. Identity Governance and Architect (IGA) and Privileged Access Management (PAM) tools (Okta, Sailpoint, Ping One Advanced Identity Cloud)Led the design and implementation of Cyber Ark's Privileged Access Management (PAM) solutions to safeguard critical assets. Designed and implemented Single Sign-On (SSO) solutions using SAML, enabling seamless access to multiple applications with a single set of credentials. Integrated OAuth 2 for secure API authorization, allowing third-party applications controlled access to internal resources. Expertise in Installation, configuration, deployment, and maintenance of the Ping Federate, Ping One and Ping One Accesss. Experienced in installing, configuring Site Minder policy servers, Web agents, Web Agent Secure Proxy servers, Ping Federate, Ping One Access, ODSEE 11g server (LDAP), Option Packs etc. Thanks & Regards Victorvictor@ampstek.com

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this