Strong experience implementing and supporting IBM Security Access Manager (ISAM), including WebSEAL configuration, junctions, ACLs, protected object space (POS)
Solid Java development experience, preferably with Authentication and authorization patterns in distributed systems
Strong understanding of IAM fundamentals: SSO, MFA concepts, token-based auth, identity lifecycle basics
Strong communication skills and ability to work across security, infrastructure, and application teams.
Must-Have
Strong experience implementing and supporting IBM Security Access Manager (ISAM), including WebSEAL configuration, junctions, ACLs, protected object space (POS)
Authentication/authorization policies, session and cookie management
Federation using SAML, OIDC, OAuth2
Mapping rules / policy scripting (often JavaScript-based in federation flows)
Solid Java development experience, preferably with Spring / Spring Boot, REST APIs, microservices concepts
Authentication and authorization patterns in distributed systems
Strong understanding of IAM fundamentals: SSO, MFA concepts, token-based auth, identity lifecycle basics
Experience with Linux/Unix, troubleshooting, logs, and network fundamentals (HTTP/S, TLS, headers, cookies)
Strong communication skills and ability to work across security, infrastructure, and application teams.
Nice-to-Have
Experience with IBM Security Verify Access (ISVA) (newer branding/evolution of ISAM)
Experience with IBM Security Directory Server / LDAP tuning and troubleshooting
Exposure to API gateways, WAF, reverse proxy patterns, and mTLS