HimalayasHimalayas logo
IDEXXID

Customer Identity & Access Management (CIAM) Security Architecture Lead

IDEXX Laboratories, Inc. is a leading provider of veterinary diagnostics and information technology, enhancing the health of animals and ensuring the safety of water and milk globally.

IDEXX

Employee count: 1001-5000

Salary: 160k-180k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

IDEXX’s Cyber Security and Information Security teams enable a resilient, adaptable, and security-aware enterprise—supporting the technology that delivers trusted products and solutions to customers worldwide.

The Customer Identity & Access Management (CIAM) Security Architecture Lead is a senior, high-impact role within the Information Security organization, serving as the primary architectural authority and technical visionary for customer identity across IDEXX’s customer-facing ecosystem.

This roleis responsible forassessing, strengthening, and evolving a secure, scalable, and unified CIAM architecture that supports multiple products, customer types, and integration models—while delivering a consistent, friction-aware customer experience. IDEXX has an existing Auth0 implementation in place; however, this role will lead a comprehensive review and re-architecture of the current environment to ensure it is securely implemented, properly configured, and aligned to enterprise-scale requirements and long-term CIAM vision.

While Auth0 is the current CIAM platform, this rolemaintainsa platform-agnostic security architecture perspective, ensuring IDEXX can evolve, extend, or transition CIAM platforms as business, risk, or regulatory needschange. You will bridge executive strategy and hands-on engineering execution—defining not only what is built, but how customer identity integrates into IDEXX’s broader cyber security architecture, ensuring identity is a business enabler, not a constraint.

In this role, your key responsibilities will include...

CIAM Security Architecture & Platform Leadership:

  • Serve as the security architecture authority for customer identity and access management across all customer-facing products

  • Assess the existing Auth0 deployment and lead remediation, reconfiguration, and architectural improvements to meet enterprise security and scale requirements

  • Design and evolve an enterprise CIAM architecture thatremainsportable across other CIAM platforms (e.g., Okta CIAM, Ping Identity, ForgeRock, Microsoft Entra ID)

  • Establish CIAM security standards, reference architectures, control requirements, and guardrails aligned with Zero Trust principles and enterprise security strategy

Strategic Roadmap & Vision

  • Develop andmaintaina multi-year CIAM roadmap aligned with enterprise goals and digital transformation initiatives

  • Define future-state capabilities including SSO, MFA,passwordlessauthentication, adaptive authentication, modern RBAC/ABAC models, and expansion across B2B and B2C use cases

  • Ensure the roadmap addresses remediation of current-state gaps while enabling long-term scalability and consistency

Authentication, Authorization & Federation

  • Architect and govern secure authentication and authorization patterns across diverse customer use cases

  • Design and implement federated identity integrations using OIDC, OAuth 2.0, and SAML

  • Support customer-managed and federated identity scenarios, including trust boundary definition, assurance levels, and delegated administration models

Multi-Tenant, Admin & Delegated Access Models

  • Architect secure multi-tenant CIAM models supporting multiple products, customers, and environments

  • Design layered administrative and delegated access controls for internal operations and customer administrators

  • Ensure administrative access adheres to least privilege, separation of duties, and strong auditability

Integrations, System Accounts & Non-Human Identity

  • Architect CIAM solutions supporting both human customer identities and system, service, and integration accounts

  • Define secure API authentication, token lifecycle management,system to system (internal and external) authentication patternsand non-interactive access patterns

Security Controls, Risk & Governance

  • Define andvalidatesecurity controls, configurations, and assurance requirements for CIAM implementations

  • Ensure CIAM solutions integrate with the broader security ecosystem including SIEM/SOAR, IAM/IGA, monitoring, and fraud detection platforms

  • Partner with GRC, Security Operations, and Product Security teams to perform threat modeling, support audits, and reduce identity-related risk

Cross-Functional Leadership & Communication

  • Act as the primary CIAM security advisor to Product, Marketing, IT, Engineering, and Platform teams

  • Translate complex identity and security requirements into clear, consumable architectural guidance

  • Communicate CIAM strategy, risk posture, and progress to VP-level and executive leadership

What You Will NeedToSucceed...

  • 8+ years of experience in CIAM/IAM with at least 3 years in a lead or security architecture capacity

  • Demonstrated experience assessing, remediating, and scaling existing CIAM implementations in complex environments

  • Deep hands-on experience with Auth0 and at least oneadditionalTier-1 CIAM platform (e.g., Okta CIAM, Ping Identity, ForgeRock, Microsoft Entra ID)

  • Expertisein OIDC, OAuth 2.0, SAML, FIDO2/WebAuthn, and SCIM

  • Location: 100% remote/virtual is fine for this role. Preferred is being local/driving distance or willing to relocate to the Westbrook, Maine area, but that is not required.

  • Strong understanding of modern application architectures (SPAs, microservices, mobile APIs) and cloud platforms (AWS preferred)

  • Proven ability to translate identity risk and architectural gaps into actionable remediation and roadmap decisions

  • Strong understanding of Zero Trust principles, identity threat models, logging, monitoring, and auditability

  • Ability to communicate complex security concepts to technical and non-technical stakeholders

  • Proven ability to navigate a matrixed organization toaccomplishgoals

Preferred Qualifications

  • Security certifications such as CISSP-ISSAP, CISM, or senior vendor certifications (e.g., Okta or Auth0 Certified Architect)

  • Experience with Identity-as-Code, CI/CD pipelines, and Terraform

  • Experience integrating CIAM with fraud detection, bot mitigation, or risk-based authentication engines

  • Experience supporting CIAM in regulated or high-trust environments such as healthcare or life sciences

  • Programming or scripting experience (Python, Java, Go, etc.)

  • Experience applying analytics or AI/ML to identity security or anomaly detection

What Success Looks Like

  • A hardened, well-architected Auth0 environment aligned with enterprise security standards and long-term CIAM vision

  • Clear remediation of current-state CIAM security and configuration gaps

  • A scalable, secure CIAM foundation supporting consistent customer experiences across products

  • A platform-agnostic CIAM architecture that can evolve or migrate without increasing risk

  • Product teams enabled with secure, reusable identity patterns that accelerate delivery

What you can expect from us:
• Base annual salary target: $160000 - $180000 (yes, we do have flexibility if needed)
• Opportunity for annual cash bonus and yearly equity award
• Health / Dental / Vision Benefits Day-One

• 5% matching 401k

• Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!

Why IDEXX?

We’re proud of the work we do, because our work matters. An innovation leader in every industry we serve, we follow our Purpose and Guiding Principles to help pet owners worldwide keep their companion animals healthy and happy, to ensure safe drinking water for billions, and to help farmers protect livestock and poultry from diseases. We have customers in over 175 countries and a global workforce of over 10,000 talented people.

So, what does that mean for you? We enrich the livelihoods of our employees with a positive and respectful work culture that embraces challenges and encourages learning and discovery.   At IDEXX, you will be supported by competitive compensation, incentives, and benefits while enjoying purposeful work that drives improvement.

Let’s pursue what matters together.

IDEXX values a diverse workforce and workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply.

IDEXX is an equal opportunity employer. Applicants will not be discriminated against because of race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition, or any protected category prohibited by local, state, or federal laws.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 160k-180k USD

Education

Bachelor degree

Experience

8 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

United States +/- 0 hours

About IDEXX

Learn more about IDEXX and their company culture.

View company profile

IDEXX Laboratories, Inc. is a global leader in veterinary diagnostics and information technology, enhancing the health and well-being of pets, people, and livestock. Established in 1983 by David Evans Shaw, IDEXX has grown to become a vital partner for veterinarians, farmers, and water quality professionals around the world. Headquartered in Westbrook, Maine, IDEXX operates across more than 175 countries, offering a comprehensive range of innovative diagnostic and information technology-based products and services.

With a dedicated workforce of over 10,000 employees, IDEXX develops and manufactures a variety of diagnostic tools that empower veterinary practices and help practitioners deliver exceptional care to animals. Their offerings include in-clinic diagnostic tests, veterinary software, and water testing solutions that ensure the safety of drinking water for billions. The strength of IDEXX lies in its commitment to innovation, quality, and collaboration within the veterinary and agricultural industries, providing solutions that improve patient outcomes and support animal health.

Claim this profileIDEXX logoID

IDEXX

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

35 remote jobs at IDEXX

Explore the variety of open remote roles at IDEXX, offering flexible work options across multiple disciplines and skill levels.

View all jobs at IDEXX

Remote companies like IDEXX

Find your next opportunity by exploring profiles of companies that are similar to IDEXX. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan