The ForgeRock Engineer will design, configure, and support ForgeRock within a complex workforce IAM environment. The role is critical for enabling
federation with Microsoft Entra ID
, supporting
legacy and modern application authentication
, and enabling a
phased migration toward Entra ID as the single workforce entry point
.
Key Responsibilities
- Engineer and support
ForgeRock Access Management (AM)
for workforce authentication.
- Configure and manage
authentication flows, federation, and application integrations
.
- Implement and support
ForgeRock ↔ Microsoft Entra ID federation
(POC and production).
- Support integrations with
RSA, ADFS
, and legacy identity systems.
- Assess applications tightly integrated with ForgeRock and define migration or coexistence strategies.
- Troubleshoot complex SSO, federation,
and authentication issues.
- Support remediation of legacy or non‑standard authentication patterns.
Mandatory Skills & Experience
- Solid hands‑on experience with
ForgeRock AM
(authentication trees, federation, access policies).
- Deep understanding of
SAML 2.0, OAuth 2.0, OpenID Connect (OIDC)
.
- Experience integrating ForgeRock with
Microsoft Entra ID / Azure AD
.
- Experience in
multi
‑
IDP enterprise environments
.
- Strong troubleshooting skills across authentication, claims, certificates, and federation flows.
Preferred Experience
- Experience supporting
Identity Provider consolidation
programs.
- Familiarity with
MFA integration
and authentication hardening.
- Experience working with applications that
do not support SAML/OIDC
.