Project details
Recommended projects
Vibe Coding Web Scraping Expert (m/f/d)
Infor AS Consultant (m/f/d)
Senior Cloud Developer TypeScript (m/f/d)
Management Consultant (Senior Level) (m/w/d)
Control Systems Technician / Control Systems Specialist (m/f/d)
IT Project Manager ISO 27.001 - Gap Closure (m/f/d)
Expert in process automation for law firm environments (m/f/d)
Cyber Security Consultant – Product Security & Regulatory Compliance (f/m/d)
Data Engineer (m/f/d)
Java IT Architect (m/f/d)
Adobe Experience Cloud Consultant (m/f/d)
Commissioning & Qualification (C&Q) Engineer (m/f/d)
Safety and Health Protection Coordinator (SiGeKo) and Safety Specialist (SiFa) (m/f/d)
Project Manager (Project Control Focus) (m/f/d)
Area Product Manager (m/f/d)
Financial Accountant (m/f/d)
Interim Accounting Lead / Head Of (m/f/d)
Construction Manager according to LBO - Civil and MEP (m/f/d)
Auditor – FSC® and PEFC Chain of Custody (m/f/d)
Social Compliance Auditor (m/f/d)
ISO 20121 Auditor (w/m/d)
Interim Staff Product Manager (m/w/d)
Development of TM1 Planning Analytics and Interfaces (m/f/d)
Tax Strategy Consulting
Freelance Product Owner for Point Of Sale App
Evaluation Scenario Writer (m/w/d)
Quality Compliance Auditor (GCP/GCLP/GVP) (M/W/D)
Senior Regulatory Compliance Expert (FDA Inspection Preparation) (m/f/d)
Construction & Contractor Safety Specialist (SiGeKo) (M/F/D)
HSE Specialist – Cell Manufacturing
Frontend developer to HR platform with Angular experience
Time's up! We are no longer accepting applications.
Keycloak / IAM Specialist (m/f/d)
Project info
- Period01.03.2026 - 31.12.2026
- Daily rate900 - 1100€
- Languages Essential:
- German(Advanced)
Desirable:- English(Advanced)
- German
- Remote100%
Description
- Design, implementation, and operation of Identity & Access Management solutions with LDAP, Kerberos, OIDC, OAuth2, SAML, and SCIM.
- Implementation of RBAC/ABAC models as well as multi-realm and multi-tenant architectures.
- Configuration of SSO flows, MFA, and identity federation.
- Deployment and operation of Keycloak on VMs, Docker, and Kubernetes (on-prem & GCP/GKE).
- Integration of Keycloak with LDAP, IPA, Active Directory, ADFS, and Entra ID for identity sync and federation.
- Securing Keycloak with TLS and handling ingress, SSL termination, and high availability.
- Integration of Keycloak with Google Identity as an identity provider or broker.
- Mapping Keycloak roles to GCP IAM roles for workload access control.
- Integration of HashiCorp Vault for securing secrets, certificates, and service credentials.
- Using Vault PKI to issue and rotate TLS certificates.
- Implementing dynamic database secrets via Vault.
- Automated secret injection into Kubernetes using Vault Agent, ESO, or sidecar.
- Introducing secret and certificate rotation policies to minimize security risks.
- Automating Keycloak and Vault with Terraform, Helm, ArgoCD, and Ansible.
- Automated configuration of realms, clients, and policies via APIs or the Terraform provider.
- Integration of IAM and Vault workflows into CI/CD pipelines for standardized application onboarding.
- Analysis and resolution of token, federation, and certificate errors.
- Monitoring IAM and Vault platforms with Prometheus and Grafana.
- Incident handling for certificate expirations, Vault unseal errors, and migration issues
Requirements
- Solid knowledge of authentication protocols (OIDC, OAuth2, SAML, Kerberos, LDAP).
- Extensive experience deploying Keycloak (VMs, Kubernetes, optional GCP).
- Experience integrating HashiCorp Vault for secret management.
- Experience with automation using Terraform, Helm, and ArgoCD.
- Strong troubleshooting skills for hybrid IAM workflows.