We’re seeking a strategic and hands-on IAM Architect to design and lead enterprise-scale identity, access, and governance solutions across hybrid cloud environments. This role is ideal for someone who combines deep technical knowledge of modern identity protocols with the ability to translate business risk and compliance requirements into robust, scalable IAM designs.
Key Responsibilities
- Define and evolve the enterprise Identity & Access Management architecture, aligning with Zero Trust and cloud-first strategies.
- Design and implement authentication, authorization, and federation services using protocols such as OAuth2, OIDC, SAML, and SCIM.
- Lead design reviews for IGA, PAM, and CIAM implementations (e.g., SailPoint, Saviynt, CyberArk, Okta, Ping, Entra ID).
- Architect joiner–mover–leaver (JML) processes, RBAC / ABAC models, and access certification workflows.
- Integrate IAM with cloud (AWS, Azure, GCP) and on-premise applications using SCIM, APIs, or automation pipelines.
- Define and implement conditional access, MFA, and risk-based authentication policies.
- Collaborate with Cybersecurity, Infrastructure, and DevOps teams to embed IAM controls into DevSecOps pipelines and IaC frameworks (Terraform, PowerShell, Python).
- Develop IAM roadmaps, reference architectures, and governance frameworks in alignment with standards (ISO 27001, NIST).
- Partner with compliance and audit teams to ensure identity assurance, SoD enforcement, and access governance reporting.
- Mentor engineering teams and support vendor evaluations and proof-of-concepts for IAM technologies.
Required Skills & Experience
Proven experience designing or implementing at least two of the following :Workforce / CIAM solutions : Okta, Ping, Entra ID (Azure AD), ForgeRockIGA platforms : SailPoint, SaviyntPAM tools : CyberArk, Delinea, BeyondTrustDeep knowledge of SAML, OAuth2, OIDC, SCIM, LDAP, and PKI.Strong understanding of Zero Trust, risk-based access, and conditional policies.Experience integrating IAM with SIEM and SOAR platforms for monitoring and incident response.Familiarity with cloud IAM (AWS IAM, Azure PIM, GCP IAM) and automation using APIs or IaC.Excellent communication and documentation skills — able to present architecture and risk trade-offs to both technical and executive audiences.Preferred Certifications (one required, one preferred)
Required (one of) :Microsoft SC-300 : Identity and Access AdministratorOkta Certified ProfessionalPreferred (nice-to-have) :CISSP or CCSP (for architectural breadth)SailPoint IdentityIQ / IdentityNow ArchitectNice-to-Have
Exposure to Zero Trust architecture, Adaptive MFA, or policy-as-code frameworks.Familiarity with ISO 27001 or SOC 2 audit cycles.Experience building IAM reference architectures and reusable automation templates.