other
Posted May 6Customer Identity & Access Management (CIAM) Security Architecture Lead
at ezyVet
Virtual United States, United StatesRemote
Requirements
- experience in CIAM/IAM with at least 3 years in a lead or security architecture capacity Demonstrated
- experience with Auth0 and at least one additional Tier-1 CIAM platform (e.g., Okta CIAM, Ping Identity, ForgeRock, Microsoft Entra ID) Expertise in OIDC, OAuth 2.0, SAML, FIDO2/ WebAuthn , and SCIM Location: 100% remote/virtual is fine for this role.
- Strong understanding of modern application architectures (SPAs, microservices, mobile APIs) and cloud platforms (AWS preferred) Proven ability to translate identity risk and architectural gaps into actionable remediation and roadmap decisions Strong understanding of Zero Trust principles, identity threat models, logging, monitoring, and auditability Ability to communicate complex security concepts to technical and non-technical stakeholders Proven ability to navigate a matrixed organization to accomplish
- Qualifications Security certifications such as CISSP-ISSAP, CISM, or senior vendor certifications (e.g., Okta or Auth0 Certified Architect)
- Experience with Identity-as-Code, CI/CD pipelines, and Terraform
- Experience integrating CIAM with fraud detection, bot mitigation, or risk-based authentication engines
- Experience supporting CIAM in regulated or high-trust environments such as healthcare or life sciences Programming or scripting
- experience (Python, Java, Go, etc.)
- Experience applying analytics or AI/ML to identity security or anomaly detection What Success Looks Like A hardened, well-architected Auth0 environment aligned with enterprise security standards and long-term CIAM vision Clear remediation of current-state CIAM security and configuration gaps A scalable, secure CIAM foundation supporting consistent customer experiences across products A platform-agnostic CIAM architecture that can evolve or migrate without increasing risk Product teams enabled with secure,
Experience
- What You Will Need To Succeed... 8+ years of
Benefits
- requirements and long-term CIAM vision.
- Base annual salary target: $160000 - $180000 (yes, we do have flexibility if needed)
- Opportunity for annual cash bonus and yearly equity award
- Health / Dental / Vision Benefits Day-One 5% matching 401k Additional
- benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more! Why IDEXX? We’re proud of the work we do, because our work matters.
- At IDEXX, you will be supported by competitive compensation, incentives, and
Additional details
- IDEXX’s Cyber Security and Information Security teams enable a resilient, adaptable, and security-aware enterprise—supporting the technology that delivers trusted products and solutions to customers worldwide.
- The Customer Identity & Access Management (CIAM) Security Architecture Lead is a senior, high-impact role within the Information Security organization , serving as the primary architectural authority and technical visionary for customer identity across IDEXX’s customer-facing ecosystem.
- This role is responsible for assessing, strengthening, and evolving a secure, scalable, and unified CIAM architecture that supports multiple products, customer types, and integration models—while delivering a consistent, friction-aware customer experience.
- IDEXX has an existing Auth0 implementation in place; however, this role will lead a comprehensive review and re-architecture of the current environment to ensure it is securely implemented, properly configured, and aligned to enterprise-scale
- While Auth0 is the current CIAM platform, this role maintains a platform-agnostic security architecture perspective, ensuring IDEXX can evolve, extend, or transition CIAM platforms as business, risk, or regulatory needs change .
- You will bridge executive strategy and hands-on engineering execution—defining not only what is built, but how customer identity integrates into IDEXX’s broader cyber security architecture, ensuring identity is a business enabler, not a constraint.
- Location : We are seeking someone driving distance to our Westbrook, Maine HQ where you will be able to work hybrid, with a minimum of 8 days on-site per month.
- In this role, your key responsibilities will include...
- CIAM Security Architecture & Platform Leadership: Serve as the security architecture authority for customer identity and access management across all customer-facing products Assess the existing Auth0 deployment and lead remediation, reconfiguration, and architectural improvements to meet enterprise security and scale
- requirements for CIAM implementations Ensure CIAM solutions integrate with the broader security ecosystem including SIEM/SOAR, IAM/IGA, monitoring, and fraud detection platforms Partner with GRC, Security Operations, and Product Security teams to perform threat modeling, support audits, and reduce identity-related risk Cross-Functional Leadership & Communication Act as the primary CIAM security advisor to Product, Marketing, IT, Engineering, and Platform teams Translate complex identity and security