Customer Identity & Access Management; CIAM Security Architecture Lead
Job in
Westbrook, Cumberland County, Maine, 04098, USA
Listed on 2026-02-09
Listing for:
Idexx
Full Time
position Listed on 2026-02-09
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security, Data Security
Job Description & How to Apply Below
** Location**:
We are seeking someone driving distance to our Westbrook, Maine HQ where you will be able to work hybrid, with a minimum of 8 days on-site per month. We are also open to those willing to relocate.
IDEXX’s Cyber Security and Information Security teams enable a resilient, adaptable, and security-aware enterprise—supporting the technology that delivers trusted products and solutions to customers worldwide.
** The Customer Identity & Access Management (CIAM) Security Architecture Lead is a senior, high-impact role within the Information Security organization**, serving as the primary architectural authority and technical visionary for customer identity across IDEXX’s customer-facing ecosystem.
This role is
** responsible for
**** assessing, strengthening, and evolving a secure, scalable, and unified CIAM architecture
** that supports multiple products, customer types, and integration models—while delivering a consistent, friction-aware customer experience. IDEXX has an existing Auth0 implementation in place; however, this role will lead a comprehensive review and re-architecture of the current environment to ensure it is securely implemented, properly configured, and aligned to enterprise-scale requirements and long-term CIAM vision.
While Auth0 is the current CIAM platform, this role maintains a platform-agnostic security architecture perspective, ensuring IDEXX can evolve, extend, or transition CIAM platforms as business, risk, or regulatory needs change. You will bridge executive strategy and hands-on engineering execution—defining not only what is built, but how customer identity integrates into IDEXX’s broader cyber security architecture, ensuring identity is a business enabler, not a constraint.
** In this role, your key responsibilities will include...
** Serve as the security architecture authority for customer identity and access management across all customer-facing products Assess the existing Auth0 deployment and lead remediation, reconfiguration, and architectural improvements to meet enterprise security and scale requirements Establish CIAM security standards, reference architectures, control requirements, and guardrails aligned with Zero Trust principles and enterprise security strategy Ensure administrative access adheres to least privilege, separation of duties, and strong auditability Architect CIAM solutions supporting both human customer identities and system, service, and integration accounts Define and validate security controls, configurations, and assurance requirements for CIAM implementations
Translate complex identity and security requirements into clear, consumable architectural guidance
** 8+ years of experience in CIAM/IAM with at least 3 years in a lead or security architecture capacity
** Demonstrated experience assessing, remediating, and scaling existing
** CIAM
* * implementations in complex environments Deep hands-on experience with Auth0 and at least one additional Tier-1 CIAM platform (e.g., Okta CIAM, Ping Identity, Forge Rock, Microsoft Entra )Proven ability to translate identity risk and architectural gaps into actionable remediation and roadmap decisions Ability to communicate complex security concepts to technical and non-technical stakeholders Proven ability to navigate a matrixed organization to accomplish goals
** Preferred Qualifications
** Experience with Identity-as-Code, CI/CD pipelines, and Terraform Experience integrating CIAM with fraud detection, bot mitigation, or risk-based authentication engines Experience supporting CIAM in regulated or high-trust environments such as healthcare or life sciences Programming or scripting experience (Python, Java, Go, etc.) Experience applying analytics or AI/ML to identity security or anomaly detection
* Product teams enabled with secure, reusable identity patterns that accelerate delivery
** What you can expect from us:*
* • Base annual salary target: $140000 - $160000 (yes, we do have flexibility if needed)
• Opportunity for annual cash bonus and yearly Equity award
• Health / Dental / Vision Benefits Day-One
• 5% matching 401k
• Additional benefits including but not limited to financial support,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×