Role Summary The ForgeRock Engineer will design, configure, and support ForgeRock within a complex workforce IAM environment. The role is critical for enabling federation with Microsoft Entra ID , supporting legacy and contemporary application authentication , and enabling a phased migration toward Entra ID as the single workforce entry point .
Key Responsibilities
- Engineer and support ForgeRock Access Management (AM) for workforce authentication.
- Configure and manage authentication flows, federation, and application integrations .
- Implement and support ForgeRock ↔ Microsoft Entra ID federation (POC and production).
- Support integrations with RSA, ADFS , and legacy identity systems.
- Assess applications tightly integrated with ForgeRock and define migration or coexistence strategies.
- Troubleshoot complex SSO, federation,
and authentication issues.
- Support remediation of legacy or non‑standard authentication patterns.
Mandatory Skills & Experience
- Strong hands‑on experience with ForgeRock AM (authentication trees, federation, access policies).
- Deep understanding of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC) .
- Experience integrating ForgeRock with Microsoft Entra ID / Azure AD .
- Experience in multi ‑ IDP enterprise environments .
- Strong troubleshooting skills across authentication, claims, certificates, and federation flows.
Preferred Experience
- Experience supporting Identity Provider consolidation programs.
- Familiarity with MFA integration and authentication hardening.
- Experience working with applications that do not support SAML/OIDC .