Jobs and Careers
ID

Customer Identity & Access Management (CIAM) Security Architecture Lead

IDEXX
United Statesfull_timeVerifiedPosted 6 Feb 2026
💰 $160,000/yr($140,000/yr$160,000/yr)

About the role

IDEXX’s Cyber Security and Information Security teams enable a resilient, adaptable, and security-aware enterprise—supporting the technology that delivers trusted products and solutions to customers worldwide. 
 
The Customer Identity & Access Management (CIAM) Security Architecture Lead is a senior, high-impact role within the Information Security organization, serving as the primary architectural authority and technical visionary for customer identity across IDEXX’s customer-facing ecosystem. 
 
This role is responsible for assessing, strengthening, and evolving a secure, scalable, and unified CIAM architecture that supports multiple products, customer types, and integration models—while delivering a consistent, friction-aware customer experience. IDEXX has an existing Auth0 implementation in place; however, this role will lead a comprehensive review and re-architecture of the current environment to ensure it is securely implemented, properly configured, and aligned to enterprise-scale requirements and long-term CIAM vision. 
 
While Auth0 is the current CIAM platform, this role maintains a platform-agnostic security architecture perspective, ensuring IDEXX can evolve, extend, or transition CIAM platforms as business, risk, or regulatory needs change. You will bridge executive strategy and hands-on engineering execution—defining not only what is built, but how customer identity integrates into IDEXX’s broader cyber security architecture, ensuring identity is a business enabler, not a constraint. 

Location: We are seeking someone driving distance to our Westbrook, Maine HQ where you will be able to work hybrid, with a minimum of 8 days on-site per month. We are also open to those willing to relocate.

In this role, your key responsibilities will include... 

CIAM Security Architecture & Platform Leadership:

  • Serve as the security architecture authority for customer identity and access management across all customer-facing products 

  • Assess the existing Auth0 deployment and lead remediation, reconfiguration, and architectural improvements to meet enterprise security and scale requirements 

  • Design and evolve an enterprise CIAM architecture that remains portable across other CIAM platforms (e.g., Okta CIAM, Ping Identity, ForgeRock, Microsoft Entra ID) 

  • Establish CIAM security standards, reference architectures, control requirements, and guardrails aligned with Zero Trust principles and enterprise security strategy 

Strategic Roadmap & Vision 

  • Develop and maintain a multi-year CIAM roadmap aligned with enterprise goals and digital transformation initiatives 

  • Define future-state capabilities including SSO, MFA, passwordless authentication, adaptive authentication, modern RBAC/ABAC models, and expansion across B2B and B2C use cases 

  • Ensure the roadmap addresses remediation of current-state gaps while enabling long-term scalability and consistency 

Authentication, Authorization & Federation 

  • Architect and govern secure authentication and authorization patterns across diverse customer use cases 

  • Design and implement federated identity integrations using OIDC, OAuth 2.0, and SAML 

  • Support customer-managed and federated identity scenarios, including trust boundary definition, assurance levels, and delegated administration models 

Multi-Tenant, Admin & Delegated Access Models 

  • Architect secure multi-tenant CIAM models supporting multiple products, customers, and

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

IDEXX

View company profile →