Customer Identity & Access Management (CIAM) Security Architecture Lead
$160k - $180kIDEXX LABORATORIES
IDEXX's Cyber Security and Information Security teams enable a resilient, adaptable, and security-aware enterprise-supporting the technology that delivers trusted products and solutions to customers worldwide.
The Customer Identity & Access Management (CIAM) Security Architecture Lead is a senior, high-impact role within the Information Security organization , serving as the primary architectural authority and technical visionary for customer identity across IDEXX's customer-facing ecosystem.
This role is responsible for assessing, strengthening, and evolving a secure, scalable, and unified CIAM architecture that supports multiple products, customer types, and integration models-while delivering a consistent, friction-aware customer experience. IDEXX has an existing Auth0 implementation in place; however, this role will lead a comprehensive review and re-architecture of the current environment to ensure it is securely implemented, properly configured, and aligned to enterprise-scale requirements and long-term CIAM vision.
While Auth0 is the current CIAM platform, this role maintains a platform-agnostic security architecture perspective, ensuring IDEXX can evolve, extend, or transition CIAM platforms as business, risk, or regulatory needs change. You will bridge executive strategy and hands-on engineering execution-defining not only what is built, but how customer identity integrates into IDEXX's broader cyber security architecture, ensuring identity is a business enabler, not a constraint.
In this role, your key responsibilities will include...
CIAM Security Architecture & Platform Leadership:
- Serve as the security architecture authority for customer identity and access management across all customer-facing products
- Assess the existing Auth0 deployment and lead remediation, reconfiguration, and architectural improvements to meet enterprise security and scale requirements
- Design and evolve an enterprise CIAM architecture that remains portable across other CIAM platforms (e.g., Okta CIAM, Ping Identity, ForgeRock, Microsoft Entra ID)
- Establish CIAM security standards, reference architectures, control requirements, and guardrails aligned with Zero Trust principles and enterprise security strategy
- Develop and maintain a multi-year CIAM roadmap aligned with enterprise goals and digital transformation initiatives
- Define future-state capabilities including SSO, MFA, passwordless authentication, adaptive authentication, modern RBAC/ABAC models, and expansion across B2B and B2C use cases
- Ensure the roadmap addresses remediation of current-state gaps while enabling long-term scalability and consistency
- Architect and govern secure authentication and authorization patterns across diverse customer use cases
- Design and implement federated identity integrations using OIDC, OAuth 2.0, and SAML
- Support customer-managed and federated identity scenarios, including trust boundary definition, assurance levels, and delegated administration models
- Architect secure multi-tenant CIAM models supporting multiple products, customers, and environments
- Design layered administrative and delegated access controls for internal operations and customer administrators
- Ensure administrative access adheres to least privilege, separation of duties, and strong auditability
- Architect CIAM solutions supporting both human customer identities and system, service, and integration accounts
- Define secure API authentication, token lifecycle management, system to system (internal and external) authentication patterns and non-interactive access patterns
- Define and validate security controls, configurations, and assurance requirements for CIAM implementations
- Ensure CIAM solutions integrate with the broader security ecosystem including SIEM/SOAR, IAM/IGA, monitoring, and fraud detection platforms
- Partner with GRC, Security Operations, and Product Security teams to perform threat modeling, support audits, and reduce identity-related risk
- Act as the primary CIAM security advisor to Product, Marketing, IT, Engineering, and Platform teams
- Translate complex identity and security requirements into clear, consumable architectural guidance
- Communicate CIAM strategy, risk posture, and progress to VP-level and executive leadership
- 8+ years of experience in CIAM/IAM with at least 3 years in a lead or security architecture capacity
- Demonstrated experience assessing, remediating, and scaling existing CIAM implementations in complex environments
- Deep hands-on experience with Auth0 and at least one additional Tier-1 CIAM platform (e.g., Okta CIAM, Ping Identity, ForgeRock, Microsoft Entra ID)
- Expertise in OIDC, OAuth 2.0, SAML, FIDO2/WebAuthn, and SCIM
- Location: 100% remote/virtual is fine for this role. Preferred is being local/driving distance or willing to relocate to the Westbrook, Maine area, but that is not required.
- Strong understanding of modern application architectures (SPAs, microservices, mobile APIs) and cloud platforms (AWS preferred)
- Proven ability to translate identity risk and architectural gaps into actionable remediation and roadmap decisions
- Strong understanding of Zero Trust principles, identity threat models, logging, monitoring, and auditability
- Ability to communicate complex security concepts to technical and non-technical stakeholders
- Proven ability to navigate a matrixed organization to accomplish goals
- Security certifications such as CISSP-ISSAP, CISM, or senior vendor certifications (e.g., Okta or Auth0 Certified Architect)
- Experience with Identity-as-Code, CI/CD pipelines, and Terraform
- Experience integrating CIAM with fraud detection, bot mitigation, or risk-based authentication engines
- Experience supporting CIAM in regulated or high-trust environments such as healthcare or life sciences
- Programming or scripting experience (Python, Java, Go, etc.)
- Experience applying analytics or AI/ML to identity security or anomaly detection
- A hardened, well-architected Auth0 environment aligned with enterprise security standards and long-term CIAM vision
- Clear remediation of current-state CIAM security and configuration gaps
- A scalable, secure CIAM foundation supporting consistent customer experiences across products
- A platform-agnostic CIAM architecture that can evolve or migrate without increasing risk
- Product teams enabled with secure, reusable identity patterns that accelerate delivery
• Base annual salary target: $160000 - $180000 (yes, we do have flexibility if needed)
• Opportunity for annual cash bonus and yearly equity award
• Health / Dental / Vision Benefits Day-One
• 5% matching 401k
• Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more! Why IDEXX? We're proud of the work we do, because our work matters. An innovation leader in every industry we serve, we follow our Purpose and Guiding Principles to help pet owners worldwide keep their companion animals healthy and happy, to ensure safe drinking water for billions, and to help farmers protect livestock and poultry from diseases. We have customers in over 175 countries and a global workforce of over 10,000 talented people. So, what does that mean for you? We enrich the livelihoods of our employees with a positive and respectful work culture that embraces challenges and encourages learning and discovery. At IDEXX, you will be supported by competitive compensation, incentives, and benefits while enjoying purposeful work that drives improvement.
Let's pursue what matters together.
IDEXX values a diverse workforce and workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply. IDEXX is an equal opportunity employer. Applicants will not be discriminated against because of race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition, or any protected category prohibited by local, state, or federal laws. #LI-REMOTE
$160k - $180k
...Customer Identity & Access Management (CIAM) Security Architecture Lead IDEXX's Cyber Security and Information Security teams enable a resilient, adaptable, and security-aware enterprise—supporting the technology that delivers trusted products and solutions to customers...CustomerLocal areaRemote workWorldwideRelocation- ...Identity & Access Management (IAM) System Engineer We are seeking... ...passionate about security, cloud integrations... ...hear from you! As Customer Identity and Access Management (CIAM) Architect Lead is responsible for... ...actions Technology Architecture (SSO, MFA, Identity...CustomerWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week
- ...Senior Lead Architect Shape secure digital experiences and drive Customer Identity and Access Management strategy and customer security. If you... ...to develop high-quality architecture solutions for various software... ...and optimizing CIAM platforms, collaborating...Customer
- A global technology firm is seeking a Customer Identity & Access Management (CIAM) Security Architecture Lead in Westbrook, Maine. This senior role involves assessing and evolving CIAM architecture across various products while ensuring security and scalability. Candidates...Customer
- ...Security & Identity Lead - Agentic ERP Platform The Security & Identity... ...Lead owns the security architecture, identity management, and compliance posture... ...agent interactions, data access, and system integrations... ...frameworks that protect customer environments — and for producing...CustomerRemote work
$160k - $180k
IDEXX is seeking a CIAM Security Architecture Lead to oversee customer identity management across its products. This role requires 8+ years of CIAM/IAM experience and at least 3 years in a lead capacity. Strong hands-on knowledge of Auth0 and additional platforms like Okta...CustomerRemote job$125k - $170k
...Lead Identity and Access Management Architect – National Security Remote - US Overview Hybrid remote opportunity -... ...to develop strategies and meet customers' business objectives. Candidate... .... Facilitate design architecture and conduct peer reviews with...CustomerContract workLocal areaRemote work$115k - $135k
...Certifications: GICSP, CIAM, Tenable, and... ...note: Active security clearances are... ...like cameras, access controls and... ...- Identity & Access Administrator... ...(Zentry token management) and the IT layer... ...partnerships with leading technology providers... ...helps customers simplify complex...CustomerFull timeContract workFor contractorsRemote work- ...Hobbsnews is seeking a Principal Technical Analyst – Customer Identity and Access Management to design and implement scalable CIAM solutions in Georgia, USA. This role is vital for ensuring secure digital customer experiences by controlling authentication and authorization...Customer
- ...Role: IAM / CIAM Lead - PAM (Infrastructure Security) Location: Irvine... ...strong Privileged Access Management (PAM) expertise to... ...implement secure identity frameworks across... ...Management (IAM) Customer Identity & Access... ...Security Zero Trust Architecture API Security...Customer
- Quest Software Canada Inc is seeking a senior Identity Security leader to operate at the intersection of architecture, strategy, and customer engagement. This role involves designing and securing modern identity ecosystems and engaging with CIOs, CISOs, and enterprise architects...Customer
- Stellantis is seeking a Customer Identity and Access Management leader based in Auburn Hills, MI. This role requires overseeing the strategy, implementation, and governance of CIAM solutions while ensuring secure customer authentication and identity management. Candidates...Customer
$80k - $90k
...Bluestaq, we build secure data platforms... ...secure data management by staying... ...counts: modern architecture, operational excellence... ...Events Lead to own the... ...level is felt by customers, partners,... ...Must be able to access and navigate all... ..., gender identity, genetic information...CustomerLive inLocal areaImmediate startRelocationFlexible hoursDay shiftAfternoon shift$97k - $207.5k
...Associate Manager, Security Research Engineer L3... ...dedication to our customers' mission and quest... ...Functions: Lead, mentor and... ...review high-level architecture, internal project... ...conditions), gender identity, gender expression... ...requirements for access to classified information...CustomerWork at officeLocal areaRemote workFlexible hoursWeekend workAfternoon shift$58 - $63 per hour
...ICAM Operations - Lead (IGA) to oversee and guide the Identity Governance & Administration... ...(IGA) program, manage a team of... ...governance and user access management. In the... ...Monitor & Improve IAM Security & Compliance: Implement... ...transformation for our customers. Our expertise in...CustomerContract workTemporary workInterim role$190k - $270k
...worldwide. Business customers have contracts... ...and Data Link Security team at Logos... ...driver of the architecture, overseeing development... ...Chain Security Lead will own the... ...organization Manage the chain of... ...status, gender identity or expression,... ...candidate’s ability to access export‑...CustomerLocal areaWorldwide- ...to drive holistic architectural design *... ...Evaluates performance, security, reliability, operations... ...stakeholders and customers to align the... ...compliant. Manage andmaintainAWS... ...role may require access to export-controlled... ..., gender identity, genetic information...CustomerFlexible hours
$154.56k - $171.74k
...functions for credit cards, secured cards, and installment loans.... ...live agent, and external agency management.Position Summary:The Identity and Access Management (IAM) Lead Engineer will work in the... ...protect the companies’ data, customers, and computer systems from business...CustomerRemote work- ...Sr. Solution Architect (Identity & Access Management and AI/ML)... ...API Gateway, Application Security, Public Cloud Architecture and end to end solutions... ...Solutions Architect will lead High Level Design, Reference... ...that promote flexible customer experience and workflow...CustomerFlexible hours
- ...Senior Architect, Identity Access Management At F5, our mission is to power... ...Within the Infrastructure & Security organization, we deliver... ...continue to grow, strong architectural leadership and disciplined... ...policies across workforce and customer identities. Recommend...CustomerLocal areaRemote work
$30k
...shared dedication to our customers’ mission and quest... ...of national security. Job Title: Lead, CAD Designer (Space... ...and must be able to manage large, complex project... ...conditions), gender identity, gender expression,... ...eligibility requirements for access to classified...CustomerLocal areaImmediate startRelocationRelocation packageFlexible hours$35 - $42 per hour
...Lead Access Control Technician/Security Technician We are seeking a skilled Lead Access... ...meet industry standards and customer expectations.... ...status effectively with management and other stakeholders.... ...conditions and lactation), gender identity or gender expression (including...CustomerTemporary workLocal areaFlexible hoursWeekend work$52 - $74 per hour
...client is seeking a Lead Security Architect to join their... ...heavily on Security Architecture reviews for SaaS... ...cloud environments, identity management, and enterprise cybersecurity... ...identity and access management... ...solutions and unsurpassed customer service. We're passionate...CustomerWork at officeLocal area3 days per week- ...dedication to our customers' mission and quest... ...interest of national security. Job Title: Lead, IT Architecture (SAP Solution... ...objectives. Project Management: Skills in... ...conditions), gender identity, gender expression... ...requirements for access to classified information...CustomerLocal area
- Lead Consultant - Identity & Access Management Career Guidant, an internationally acclaimed, trusted... ...Information Technology Custom Learning Services for... ..., problem definition, Architecture/Design /Detailing of Processes... ...Management, Information Security, Systems Analysis,...CustomerPermanent employmentFull timeH1b
- ...Toyota is growing and leading the future of... ...create best-in-class customer experience in an innovative... ...seeking a skilled Identity and Access Management Engineer, Lead to join our Information Security Department. This... ...understanding of their architecture and role-based access...Customer
- The Chronicle Of Higher Education, Inc. is seeking an Identity and Access Manager to lead the development of an Identity and Access Management framework. You'll collaborate with the Information Security team to improve security and compliance for the College’s systems....Full time
- ...this role is to lead the design and delivery... ...of complex identity security solutions, ensuring... ...outcomes for customers within Saviynt’s... ...will own end-to-end architecture and technical delivery... ...and deployment. Manage both technical... ...Policy Access Control Policy Personnel...Customer
- ...seeking a Principal Technical Analyst – Customer Identity and Access Management to lead the design, implementation, and optimization of CIAM solutions for seamless digital experiences... ...platforms and a strong understanding of security principles. This role emphasizes...Customer
- ...Solutions, the nation's leading provider of architectural doors, frames,... ..., and complete security integration... ...professionally. You'll have access to:... ...by the Project Managers and Field Supervisors... ...with customer IT and Facilities... ...orientation, gender identity, national origin...CustomerFor contractors
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Customer Identity & Access Management (CIAM) Security Architecture Lead. Be the first to apply!
- customer marketing United States
- customer engineer United States
- customer insights analyst United States
- customer retention United States
- work from home customer United States
- customer liaison United States
- customer satisfaction United States
- customer project program manager United States
- director managed services United States
- care management associate United States


