Project details
Recommended projects
Fullstack Engineer (m/f/d)
Infor AS Consultant (m/f/d)
Senior Cloud Developer TypeScript (m/f/d)
Control systems engineer / Control systems specialist (m/f/d)
IT Project Manager ISO 27.001 - Gap Closure (m/f/d)
Cyber Security Consultant – Product Security & Regulatory Compliance (m/f/d)
Data Engineer (m/f/d)
Java IT Architect (m/f/d)
Adobe Experience Cloud Consultant (m/f/d)
Commissioning & Qualification (C&Q) Engineer (m/f/d)
Safety and Health Protection Coordinator (SiGeKo) and Safety Specialist (SiFa) (m/f/d)
Freelance Cybersecurity Consultant for AI Red Teaming
Freelance Post-Merger Integration Consultant with a Strong Tech and Commercial Focus (m/f/d)
Freelance Java Developer (m/f/d)
FSC CoC Auditor (m/f/d)
Freelance Product Owner Android Development (m/f/d)
Development of TM1 Planning Analytics and Interfaces (m/f/d)
Consulting in Tax Strategy
Freelance Product Owner for Point Of Sale App
Evaluation Scenario Writer (m/w/d)
Quality Compliance Auditor (GCP/GCLP/GVP) (M/F/D)
Senior Regulatory Compliance Expert (FDA Inspection Preparation) (m/f/d)
Senior Faktor 10 Developer (IPS / IPM) (m/f/d)
Construction & Contractor Safety Specialist (SiGeKo) (M/w/d)
EHS Specialist – Cell Manufacturing
EHS Specialist – Body in White (M/W/D)
EHS Specialist – Facilities (M/W/D)
Senior Project Manager Customer Interaction
AI Consultant - Machine Learning (m/w/d)
AI Consultant for Vibe Coding (m/w/d)
Frontend developer to HR platform with Angular experience
Time's up! We are no longer accepting applications.
Keycloak / IAM Specialist (m/f/d)
Project info
- Period01.03.2026 - 31.12.2026
- Daily rate900 - 1100€
- Languages Essential:
- German(Advanced)
Desirable:- English(Advanced)
- German
- Remote100%
Description
- Design, implementation, and operation of Identity & Access Management solutions with LDAP, Kerberos, OIDC, OAuth2, SAML, and SCIM.
- Implementation of RBAC/ABAC models as well as multi-realm and multi-tenant architectures.
- Configuration of SSO flows, MFA, and identity federation.
- Deployment and operation of Keycloak on VMs, Docker, and Kubernetes (on-prem & GCP/GKE).
- Integration of Keycloak with LDAP, IPA, Active Directory, ADFS, and Entra ID for identity sync and federation.
- Securing Keycloak with TLS and handling ingress, SSL termination, and high availability.
- Integration of Keycloak with Google Identity as an identity provider or broker.
- Mapping Keycloak roles to GCP IAM roles for workload access control.
- Integration of HashiCorp Vault for securing secrets, certificates, and service credentials.
- Using Vault PKI to issue and rotate TLS certificates.
- Implementing dynamic database secrets via Vault.
- Automated secret injection into Kubernetes using Vault Agent, ESO, or sidecar.
- Introducing secret and certificate rotation policies to minimize security risks.
- Automating Keycloak and Vault with Terraform, Helm, ArgoCD, and Ansible.
- Automated configuration of realms, clients, and policies via APIs or the Terraform provider.
- Integration of IAM and Vault workflows into CI/CD pipelines for standardized application onboarding.
- Analysis and resolution of token, federation, and certificate errors.
- Monitoring IAM and Vault platforms with Prometheus and Grafana.
- Incident handling for certificate expirations, Vault unseal errors, and migration issues
Requirements
- Solid knowledge of authentication protocols (OIDC, OAuth2, SAML, Kerberos, LDAP).
- Extensive experience deploying Keycloak (VMs, Kubernetes, optional GCP).
- Experience integrating HashiCorp Vault for secret management.
- Experience with automation using Terraform, Helm, and ArgoCD.
- Strong troubleshooting skills for hybrid IAM workflows.