IBM IAM Architect
Location: Remote (U.S. Based)
Type: Contract
About the Role:
We’re looking for a seasoned IBM IAM Architect who knows how to design and deploy enterprise-scale access and identity systems using IBM’s suite — specifically WebSEAL (ISAM) and Tivoli/ISIM — and who has navigated the complexities of transitioning from CA (SiteMinder/Identity Manager) to modern IAM stacks.
Key Responsibilities:
- Architect and deploy secure access solutions using IBM WebSEAL / ISAM
- Manage and enhance identity lifecycle workflows in IBM Tivoli Identity Manager (ITIM/ISIM)
- Lead or support migration projects from CA SiteMinder / CA Identity Manager to IBM or modern IGA stacks
- Configure and manage authentication/authorization policies, federation (SAML/OIDC), and access controls
- Develop custom adapters and scripts (Java/JavaScript) for provisioning, password sync, and access workflows
- Integrate with directories (Tivoli/ITDS, SDS, AD), HR systems, ticketing platforms (ServiceNow), and cloud apps
- Support coexistence strategies and hybrid architectures during tool transitions
- Create architecture documentation, deployment runbooks, and knowledge transfers for operational teams
What We're Looking For:
- 8+ years in Identity & Access Management, with strong IBM stack experience
- Deep hands-on experience with WebSEAL (reverse proxy config, ACLs, junctions)
- Proven track record implementing or supporting Tivoli/ISIM for identity governance
- Experience migrating from CA SiteMinder / CA Identity Manager — especially enterprise deployments
- Strong working knowledge of LDAP, SAML, OAuth 2.0, OIDC, and REST APIs
- Ability to write and debug custom scripts/adapters in Java and JavaScript
- Comfortable collaborating with infrastructure, security, and application teams in enterprise environments
- Strong documentation and communication skills — can explain the “why,” not just the “how”
Bonus Points:
- Experience with SailPoint, Saviynt, or other IGA modernization efforts
- Familiarity with containerized deployments (Docker, OpenShift) or CI/CD pipelines
- Exposure to Zero Trust or PAM strategies in enterprise architectures
- IBM or CA certifications