Skip to main content

Keycloak / IAM Specialist (m/f/d)

Project specification

Project duration
Period 01.03.2026 - 31.12.2026
Daily rate range
Daily rate 904 - 1104€
Remote work ratio
Remote 100%
Required languages
Languages
German(Advanced)
English(Advanced)

Project expertise

Industries
Information Technology
Business areas
Information Technology Operations

Description

  • Design, implementation, and operation of Identity & Access Management solutions with LDAP, Kerberos, OIDC, OAuth2, SAML, and SCIM.
  • Implementation of RBAC/ABAC models as well as multi-realm and multi-tenant architectures.
  • Configuration of SSO flows, MFA, and identity federation.
  • Deployment and operation of Keycloak on VMs, Docker, and Kubernetes (on-prem & GCP/GKE).
  • Integration of Keycloak with LDAP, IPA, Active Directory, ADFS, and Entra ID for identity sync and federation.
  • Securing Keycloak with TLS and handling ingress, SSL termination, and high availability.
  • Integration of Keycloak with Google Identity as an identity provider or broker.
  • Mapping Keycloak roles to GCP IAM roles for workload access control.
  • Integration of HashiCorp Vault for securing secrets, certificates, and service credentials.
  • Using Vault PKI to issue and rotate TLS certificates.
  • Implementing dynamic database secrets via Vault.
  • Automated secret injection into Kubernetes using Vault Agent, ESO, or sidecar.
  • Introducing secret and certificate rotation policies to minimize security risks.
  • Automating Keycloak and Vault with Terraform, Helm, ArgoCD, and Ansible.
  • Automated configuration of realms, clients, and policies via APIs or the Terraform provider.
  • Integration of IAM and Vault workflows into CI/CD pipelines for standardized application onboarding.
  • Analysis and resolution of token, federation, and certificate errors.
  • Monitoring IAM and Vault platforms with Prometheus and Grafana.
  • Incident handling for certificate expirations, Vault unseal errors, and migration issues

Requirements

  • Solid knowledge of authentication protocols (OIDC, OAuth2, SAML, Kerberos, LDAP).
  • Extensive experience deploying Keycloak (VMs, Kubernetes, optional GCP).
  • Experience integrating HashiCorp Vault for secret management.
  • Experience with automation using Terraform, Helm, and ArgoCD.
  • Strong troubleshooting skills for hybrid IAM workflows.
Project Subscribe Icon

Not applying this time?

Get notified about similar projects matched to your experience.

Frequently asked questions

The project is fully remote, providing complete location flexibility.
The project preferably starts in March 2026 and is planned to end in December 2026 (9 months).
The project is 100% remote. You can work from any location.
The project offers a daily rate of 904 - 1104€ which breaks down to an hourly rate of 113 - 138€/h.
The project requires German (Advanced) as essential language. Additionally, English (Advanced) is desirable.
The project is related to the following industry: Information Technology.
The project covers the following business areas: Information Technology and Operations.
Yes! Recommend a freelancer for the project and earn 30% of FRATCH's profits every time they get placed — for the duration of that project. Simply share your invite link with a colleague to get started.
To apply for the project, click the Apply button on the project page to submit your profile for review. We will forward your resume to the client and get back to you within a few days.
Published:·Updated:

Similar Projects

Senior/Lead Engineer (Freelance/Contract) (m/w/d)

Munich, Germany
from 95%

Infor AS Consultant (m/f/d)

Schweinfurt, Germany
up to 50%

Senior Cloud Developer TypeScript (m/f/d)

100%
904 - 1104€/day

Management Consultant (Senior Level) (m/f/d)

Munich, Germany
up to 100%
904 - 952€/day

Control system technician / Control system specialist (m/f/d)

Hamburg, Germany
up to 20%
960 - 1040€/day

IT Project Manager ISO 27001 - Gap Closure (m/f/d)

Munich, Germany
up to 20%
1000€/day

Cyber Security Consultant – Product Security & Regulatory Compliance (m/f/d)

Germany
up to 100%

Data Engineer (m/f/d)

Munich, Germany
from 95%
800€/day

Java IT Architect (m/f/d)

Germany
up to 100%

Backend Developer

Germany
up to 100%
520 - 560€/day

Senior Data Warehouse Developer / Database Programmer (m/f/d) (Exasol, STACKIT, Cloud DWH, Data Vault)

100%
904 - 1104€/day

Commissioning & Qualification (C&Q) Engineer (m/f/d)

Munich, Germany
up to 100%

Safety and Health Protection Coordinator (SiGeKo) and Safety Specialist (SiFa) (m/f/d)

Hamburg, Germany
0%

Forward Deployed Engineer for AI Implementation (m/f/d)

Munich, Germany
from 90%

Head of Automation and AI Transformation (m/f/d)

Rednitzhembach, Germany
up to 100%

Data Analyst (m/f/d)

100%
904 - 1104€/day

Interim Head of Talent Management (m/f/d)

100%

IT Analyst (m/f/d)

100%
904 - 1104€/day

IT project manager (m/f/d) with Lotus Notes experience

904 - 1104€/day

Project Manager / Program Manager - Agency Setup (m/f/d)

Munich, Germany
848 - 1000€/day

Project Manager with Workday and AI Experience (m/f/d)

Munich, Germany
80 - 90%
752 - 904€/day

E-commerce Listing Designer (m/w/d)

100%
200 - 240€/day

Hardware Product Manager (m/f/d)

Berlin, Germany
60 - 80%
560 - 720€/day

Interim Manager CTO / CIO / Transformation / Technical Leadership (m/f/d)

Munich, Germany
30 - 90%

Financial Accountant (m/f/d)

Hamburg, Germany
up to 80%

Interim Accounting Lead / Head Of (m/f/d)

Germany
up to 100%

Interim Staff Product Manager (m/w/d)

Berlin, Germany
60 - 80%
96 - 104€/day

Development of TM1 Planning Analytics and Interfaces (m/f/d)

Germany
up to 100%

Consulting in Tax Strategy

Karlsruhe, Germany
from 95%
824 - 840€/day

Freelance Product Owner for Point of Sale App

Berlin, Germany
752 - 848€/day