Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Customer Identity & Access Management (CIAM) Security Architecture Lead

$160k - $180k

IDEXX LABORATORIES

IDEXX's Cyber Security and Information Security teams enable a resilient, adaptable, and security-aware enterprise-supporting the technology that delivers trusted products and solutions to customers worldwide.


The Customer Identity & Access Management (CIAM) Security Architecture Lead is a senior, high-impact role within the Information Security organization , serving as the primary architectural authority and technical visionary for customer identity across IDEXX's customer-facing ecosystem.


This role is responsible for assessing, strengthening, and evolving a secure, scalable, and unified CIAM architecture that supports multiple products, customer types, and integration models-while delivering a consistent, friction-aware customer experience. IDEXX has an existing Auth0 implementation in place; however, this role will lead a comprehensive review and re-architecture of the current environment to ensure it is securely implemented, properly configured, and aligned to enterprise-scale requirements and long-term CIAM vision.


While Auth0 is the current CIAM platform, this role maintains a platform-agnostic security architecture perspective, ensuring IDEXX can evolve, extend, or transition CIAM platforms as business, risk, or regulatory needs change. You will bridge executive strategy and hands-on engineering execution-defining not only what is built, but how customer identity integrates into IDEXX's broader cyber security architecture, ensuring identity is a business enabler, not a constraint.


In this role, your key responsibilities will include...


CIAM Security Architecture & Platform Leadership:

  • Serve as the security architecture authority for customer identity and access management across all customer-facing products
  • Assess the existing Auth0 deployment and lead remediation, reconfiguration, and architectural improvements to meet enterprise security and scale requirements
  • Design and evolve an enterprise CIAM architecture that remains portable across other CIAM platforms (e.g., Okta CIAM, Ping Identity, ForgeRock, Microsoft Entra ID)
  • Establish CIAM security standards, reference architectures, control requirements, and guardrails aligned with Zero Trust principles and enterprise security strategy

Strategic Roadmap & Vision
  • Develop and maintain a multi-year CIAM roadmap aligned with enterprise goals and digital transformation initiatives
  • Define future-state capabilities including SSO, MFA, passwordless authentication, adaptive authentication, modern RBAC/ABAC models, and expansion across B2B and B2C use cases
  • Ensure the roadmap addresses remediation of current-state gaps while enabling long-term scalability and consistency
Authentication, Authorization & Federation
  • Architect and govern secure authentication and authorization patterns across diverse customer use cases
  • Design and implement federated identity integrations using OIDC, OAuth 2.0, and SAML
  • Support customer-managed and federated identity scenarios, including trust boundary definition, assurance levels, and delegated administration models
Multi-Tenant, Admin & Delegated Access Models
  • Architect secure multi-tenant CIAM models supporting multiple products, customers, and environments
  • Design layered administrative and delegated access controls for internal operations and customer administrators
  • Ensure administrative access adheres to least privilege, separation of duties, and strong auditability
Integrations, System Accounts & Non-Human Identity
  • Architect CIAM solutions supporting both human customer identities and system, service, and integration accounts
  • Define secure API authentication, token lifecycle management, system to system (internal and external) authentication patterns and non-interactive access patterns

Security Controls, Risk & Governance
  • Define and validate security controls, configurations, and assurance requirements for CIAM implementations
  • Ensure CIAM solutions integrate with the broader security ecosystem including SIEM/SOAR, IAM/IGA, monitoring, and fraud detection platforms
  • Partner with GRC, Security Operations, and Product Security teams to perform threat modeling, support audits, and reduce identity-related risk
Cross-Functional Leadership & Communication
  • Act as the primary CIAM security advisor to Product, Marketing, IT, Engineering, and Platform teams
  • Translate complex identity and security requirements into clear, consumable architectural guidance
  • Communicate CIAM strategy, risk posture, and progress to VP-level and executive leadership
What You Will Need To Succeed...
  • 8+ years of experience in CIAM/IAM with at least 3 years in a lead or security architecture capacity
  • Demonstrated experience assessing, remediating, and scaling existing CIAM implementations in complex environments
  • Deep hands-on experience with Auth0 and at least one additional Tier-1 CIAM platform (e.g., Okta CIAM, Ping Identity, ForgeRock, Microsoft Entra ID)
  • Expertise in OIDC, OAuth 2.0, SAML, FIDO2/WebAuthn, and SCIM
  • Location: 100% remote/virtual is fine for this role. Preferred is being local/driving distance or willing to relocate to the Westbrook, Maine area, but that is not required.
  • Strong understanding of modern application architectures (SPAs, microservices, mobile APIs) and cloud platforms (AWS preferred)
  • Proven ability to translate identity risk and architectural gaps into actionable remediation and roadmap decisions
  • Strong understanding of Zero Trust principles, identity threat models, logging, monitoring, and auditability
  • Ability to communicate complex security concepts to technical and non-technical stakeholders
  • Proven ability to navigate a matrixed organization to accomplish goals
Preferred Qualifications
  • Security certifications such as CISSP-ISSAP, CISM, or senior vendor certifications (e.g., Okta or Auth0 Certified Architect)
  • Experience with Identity-as-Code, CI/CD pipelines, and Terraform
  • Experience integrating CIAM with fraud detection, bot mitigation, or risk-based authentication engines
  • Experience supporting CIAM in regulated or high-trust environments such as healthcare or life sciences
  • Programming or scripting experience (Python, Java, Go, etc.)
  • Experience applying analytics or AI/ML to identity security or anomaly detection

What Success Looks Like
  • A hardened, well-architected Auth0 environment aligned with enterprise security standards and long-term CIAM vision
  • Clear remediation of current-state CIAM security and configuration gaps
  • A scalable, secure CIAM foundation supporting consistent customer experiences across products
  • A platform-agnostic CIAM architecture that can evolve or migrate without increasing risk
  • Product teams enabled with secure, reusable identity patterns that accelerate delivery

What you can expect from us:
• Base annual salary target: $160000 - $180000 (yes, we do have flexibility if needed)
• Opportunity for annual cash bonus and yearly equity award
• Health / Dental / Vision Benefits Day-One
• 5% matching 401k
• Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!

Why IDEXX?

We're proud of the work we do, because our work matters. An innovation leader in every industry we serve, we follow our Purpose and Guiding Principles to help pet owners worldwide keep their companion animals healthy and happy, to ensure safe drinking water for billions, and to help farmers protect livestock and poultry from diseases. We have customers in over 175 countries and a global workforce of over 10,000 talented people.

So, what does that mean for you? We enrich the livelihoods of our employees with a positive and respectful work culture that embraces challenges and encourages learning and discovery. At IDEXX, you will be supported by competitive compensation, incentives, and benefits while enjoying purposeful work that drives improvement.


Let's pursue what matters together.


IDEXX values a diverse workforce and workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply.

IDEXX is an equal opportunity employer. Applicants will not be discriminated against because of race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition, or any protected category prohibited by local, state, or federal laws.

#LI-REMOTE
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Customer Identity & Access Management (CIAM) Security Architecture Lead in United States vacancy
  • $160k - $180k

     ...Customer Identity & Access Management (CIAM) Security Architecture Lead IDEXX's Cyber Security and Information Security teams enable a resilient, adaptable, and security-aware enterprise—supporting the technology that delivers trusted products and solutions to customers... 
    Customer
    Local area
    Remote work
    Worldwide
    Relocation

    IDEXX Laboratories

    United States
    1 day ago
  •  ...Identity & Access Management (IAM) System Engineer We are seeking...  ...passionate about security, cloud integrations...  ...hear from you! As Customer Identity and Access Management (CIAM) Architect Lead is responsible for...  ...actions Technology Architecture (SSO, MFA, Identity... 
    Customer
    Work at office
    Local area
    Remote work
    Flexible hours
    3 days per week
    1 day per week

    Mercer France

    Charlotte, NC
    2 days ago
  •  ...Senior Lead Architect Shape secure digital experiences and drive Customer Identity and Access Management strategy and customer security. If you...  ...to develop high-quality architecture solutions for various software...  ...and optimizing CIAM platforms, collaborating... 
    Customer

    Chase

    Jersey City, NJ
    5 days ago
  • A global technology firm is seeking a Customer Identity & Access Management (CIAM) Security Architecture Lead in Westbrook, Maine. This senior role involves assessing and evolving CIAM architecture across various products while ensuring security and scalability. Candidates... 
    Customer

    IDEXX GmbH

    Westbrook, ME
    5 days ago
  •  ...Security & Identity Lead - Agentic ERP Platform The Security & Identity...  ...Lead owns the security architecture, identity management, and compliance posture...  ...agent interactions, data access, and system integrations...  ...frameworks that protect customer environments — and for producing... 
    Customer
    Remote work

    Rimini Street

    United States
    3 days ago
  • $160k - $180k

    IDEXX is seeking a CIAM Security Architecture Lead to oversee customer identity management across its products. This role requires 8+ years of CIAM/IAM experience and at least 3 years in a lead capacity. Strong hands-on knowledge of Auth0 and additional platforms like Okta... 
    Customer
    Remote job

    IDEXX

    Worcester, MA
    2 days ago
  • $125k - $170k

     ...Lead Identity and Access Management Architect – National Security Remote - US Overview Hybrid remote opportunity -...  ...to develop strategies and meet customers' business objectives. Candidate...  .... Facilitate design architecture and conduct peer reviews with... 
    Customer
    Contract work
    Local area
    Remote work

    ePlus

    United States
    3 days ago
  • $115k - $135k

     ...Certifications: GICSP, CIAM, Tenable, and...  ...note: Active security clearances are...  ...like cameras, access controls and...  ...- Identity & Access Administrator...  ...(Zentry token management) and the IT layer...  ...partnerships with leading technology providers...  ...helps customers simplify complex... 
    Customer
    Full time
    Contract work
    For contractors
    Remote work

    Telispree Communications

    Temecula, CA
    25 days ago
  •  ...Hobbsnews is seeking a Principal Technical Analyst – Customer Identity and Access Management to design and implement scalable CIAM solutions in Georgia, USA. This role is vital for ensuring secure digital customer experiences by controlling authentication and authorization... 
    Customer

    Hobbsnews

    New York, NY
    1 day ago
  •  ...Role: IAM / CIAM Lead - PAM (Infrastructure Security) Location: Irvine...  ...strong Privileged Access Management (PAM) expertise to...  ...implement secure identity frameworks across...  ...Management (IAM) Customer Identity & Access...  ...Security Zero Trust Architecture API Security... 
    Customer

    Purple Drive

    Irvine, CA
    2 days ago
  • Quest Software Canada Inc is seeking a senior Identity Security leader to operate at the intersection of architecture, strategy, and customer engagement. This role involves designing and securing modern identity ecosystems and engaging with CIOs, CISOs, and enterprise architects... 
    Customer

    Quest Software Canada Inc

    Washington DC
    2 days ago
  • Stellantis is seeking a Customer Identity and Access Management leader based in Auburn Hills, MI. This role requires overseeing the strategy, implementation, and governance of CIAM solutions while ensuring secure customer authentication and identity management. Candidates... 
    Customer

    Stellanti

    Auburn Hills, MI
    2 days ago
  • $80k - $90k

     ...Bluestaq, we build secure data platforms...  ...secure data management by staying...  ...counts: modern architecture, operational excellence...  ...Events Lead to own the...  ...level is felt by customers, partners,...  ...Must be able to access and navigate all...  ..., gender identity, genetic information... 
    Customer
    Live in
    Local area
    Immediate start
    Relocation
    Flexible hours
    Day shift
    Afternoon shift

    Bluestaq US External

    Colorado Springs, CO
    1 day ago
  • $97k - $207.5k

     ...Associate Manager, Security Research Engineer L3...  ...dedication to our customers' mission and quest...  ...Functions: Lead, mentor and...  ...review high-level architecture, internal project...  ...conditions), gender identity, gender expression...  ...requirements for access to classified information... 
    Customer
    Work at office
    Local area
    Remote work
    Flexible hours
    Weekend work
    Afternoon shift

    L3Harris Technologies

    United States
    4 days ago
  • $58 - $63 per hour

     ...ICAM Operations - Lead (IGA) to oversee and guide the Identity Governance & Administration...  ...(IGA) program, manage a team of...  ...governance and user access management. In the...  ...Monitor & Improve IAM Security & Compliance: Implement...  ...transformation for our customers. Our expertise in... 
    Customer
    Contract work
    Temporary work
    Interim role

    TEKsystems

    Washington DC
    4 days ago
  • $190k - $270k

     ...worldwide. Business customers have contracts...  ...and Data Link Security team at Logos...  ...driver of the architecture, overseeing development...  ...Chain Security Lead will own the...  ...organization Manage the chain of...  ...status, gender identity or expression,...  ...candidate’s ability to access export‑... 
    Customer
    Local area
    Worldwide

    Logos Space

    San Diego, CA
    4 days ago
  •  ...to drive holistic architectural design *...  ...Evaluates performance, security, reliability, operations...  ...stakeholders and customers to align the...  ...compliant. Manage andmaintainAWS...  ...role may require access to export-controlled...  ..., gender identity, genetic information... 
    Customer
    Flexible hours

    Unisys

    Houston, TX
    1 day ago
  • $154.56k - $171.74k

     ...functions for credit cards, secured cards, and installment loans....  ...live agent, and external agency management.Position Summary:The Identity and Access Management (IAM) Lead Engineer will work in the...  ...protect the companies’ data, customers, and computer systems from business... 
    Customer
    Remote work

    CardWorks Servicing

    Syosset, NY
    5 days ago
  •  ...Sr. Solution Architect (Identity & Access Management and AI/ML)...  ...API Gateway, Application Security, Public Cloud Architecture and end to end solutions...  ...Solutions Architect will lead High Level Design, Reference...  ...that promote flexible customer experience and workflow... 
    Customer
    Flexible hours

    3B Staffing LLC

    Irving, TX
    5 days ago
  •  ...Senior Architect, Identity Access Management At F5, our mission is to power...  ...Within the Infrastructure & Security organization, we deliver...  ...continue to grow, strong architectural leadership and disciplined...  ...policies across workforce and customer identities. Recommend... 
    Customer
    Local area
    Remote work

    F5

    United States
    5 days ago
  • $30k

     ...shared dedication to our customers’ mission and quest...  ...of national security. Job Title: Lead, CAD Designer (Space...  ...and must be able to manage large, complex project...  ...conditions), gender identity, gender expression,...  ...eligibility requirements for access to classified... 
    Customer
    Local area
    Immediate start
    Relocation
    Relocation package
    Flexible hours

    L3Harris

    Wilmington, MA
    4 days ago
  • $35 - $42 per hour

     ...Lead Access Control Technician/Security Technician We are seeking a skilled Lead Access...  ...meet industry standards and customer expectations....  ...status effectively with management and other stakeholders....  ...conditions and lactation), gender identity or gender expression (including... 
    Customer
    Temporary work
    Local area
    Flexible hours
    Weekend work

    Control Systems Inc

    Cedar Park, TX
    4 days ago
  • $52 - $74 per hour

     ...client is seeking a Lead Security Architect to join their...  ...heavily on Security Architecture reviews for SaaS...  ...cloud environments, identity management, and enterprise cybersecurity...  ...identity and access management...  ...solutions and unsurpassed customer service. We're passionate... 
    Customer
    Work at office
    Local area
    3 days per week

    KellyMitchell Group

    Chicago, IL
    4 days ago
  •  ...dedication to our customers' mission and quest...  ...interest of national security. Job Title: Lead, IT Architecture (SAP Solution...  ...objectives. Project Management: Skills in...  ...conditions), gender identity, gender expression...  ...requirements for access to classified information... 
    Customer
    Local area

    L3Harris Technologies

    Melbourne, FL
    3 days ago
  • Lead Consultant - Identity & Access Management Career Guidant, an internationally acclaimed, trusted...  ...Information Technology Custom Learning Services for...  ..., problem definition, Architecture/Design /Detailing of Processes...  ...Management, Information Security, Systems Analysis,... 
    Customer
    Permanent employment
    Full time
    H1b

    Career Guidant Inc.

    Cranston, RI
    2 days ago
  •  ...Toyota is growing and leading the future of...  ...create best-in-class customer experience in an innovative...  ...seeking a skilled Identity and Access Management Engineer, Lead to join our Information Security Department. This...  ...understanding of their architecture and role-based access... 
    Customer

    Toyota Deutschland GmbH

    Plano, TX
    2 days ago
  • The Chronicle Of Higher Education, Inc. is seeking an Identity and Access Manager to lead the development of an Identity and Access Management framework. You'll collaborate with the Information Security team to improve security and compliance for the College’s systems.... 
    Full time

    The Chronicle Of Higher Education, Inc.

    Fort Worth, TX
    1 day ago
  •  ...this role is to lead the design and delivery...  ...of complex identity security solutions, ensuring...  ...outcomes for customers within Saviynt’s...  ...will own end-to-end architecture and technical delivery...  ...and deployment. Manage both technical...  ...Policy Access Control Policy Personnel... 
    Customer

    Medium

    Amsterdam, MO
    4 days ago
  •  ...seeking a Principal Technical Analyst – Customer Identity and Access Management to lead the design, implementation, and optimization of CIAM solutions for seamless digital experiences...  ...platforms and a strong understanding of security principles. This role emphasizes... 
    Customer

    Cummins

    New York, NY
    1 day ago
  •  ...Solutions, the nation's leading provider of architectural doors, frames,...  ..., and complete security integration...  ...professionally. You'll have access to:...  ...by the Project Managers and Field Supervisors...  ...with customer IT and Facilities...  ...orientation, gender identity, national origin... 
    Customer
    For contractors

    Cook & Boardman

    Charleston, SC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Customer Identity & Access Management (CIAM) Security Architecture Lead. Be the first to apply!