Identity Management Engineer
The Identity Management Engineer is responsible for designing, developing, and operating the B. Braun Customer Identity and Access Management (CIAM) platform. The role focuses on building secure backend services and authorization models using One Identity Manager. This includes implementing identity lifecycle processes, integration with custom APIs, and ensuring compliance with security, governance, and regulatory requirements.
Duties and responsibilities:
Develop and maintain the Identity Management Platform based on One Identity Manager
-
Design and implement scalable backend services for:
Customer administration
Identity lifecycle processes (Joiner, Mover, Leaver)
Build secure, high-performance service layers and processes
Ensure modular, maintainable, and extensible application design
-
Contribute to:
CIAM strategy and roadmap
Architecture design and evolution
-
Collaborate in defining:
Authorization and identity standards
Secure and scalable system design
Implement and extend One Identity Manager capabilities
Develop custom synchronization solutions (REST APIs)
Implement data mapping, transformation, and consistency checks
Ensure reliable data exchange and synchronization across systems
Implement logic for license assignment and tracking
Implement and support threat modeling and risk assessments
Ensure compliance with: DPIA (Data Protection Impact Assessment), Data retention policies, DSR (Data Subject Rights)
Enforce secure coding and identity security best practices
Provide 2nd/3rd level support for CIAM services and applications
Monitor system performance and troubleshoot issues
Ensure high availability and reliability of identity services
Required Qualifications
Must-have
Hands-on experience with One Identity Manager or similar
Strong understanding of Identity & Access Management (IAM / CIAM) concepts, access governance, and identity lifecycle management processes.
-
Familiarity with:
Programming language: ()
Scripting languages (PowerShell)
Frontend development (Angular)
-
Solid understanding of:
Authorization models, especially ReBAC
OpenFGA or similar fine-grained authorization systems
-
Experience with:
Integration and synchronization between systems
Database design and handling identity data
Designing and building processes
Nice-to-have
-
Experience with:
Azure cloud services
Event-driven architecture
-
Understanding of:
GDPR and data privacy regulations
CI/CD pipelines and DevOps practices
Familiarity with EMS systems or contract management platforms
Backend development skills (e.g., C#, .NET, Java)
-
Experience with:
API development (REST)
Authentication protocols (OAuth2, OpenID Connect)
Personal Skills
Strong analytical and conceptual thinking
High security and quality awareness
Ability to work in complex, regulated environments
Strong ownership and proactive mindset
Good communication skills with technical and business stakeholders
Benefits:
Additional social funds for summer holidays and Christmas
Co-funding of a Multisport card and private medical care
Opportunity to join group life insurance
Fundings for trainings and conferences
Co-funding of professional development
Free language lessons and access to an e-learning platform
Team-building and sports events