IAM Architect

Dallas, TX, US • Posted 3 hours ago • Updated 3 hours ago
Contract W2
6 Months
No Travel Required
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Active Directory
  • Cloud Computing
  • CyberArk
  • Cyber Security
  • CISM
  • Enterprise Architecture
  • ISACA
  • Identity Management
  • Incident Management
  • Information Systems
  • Information Security
  • Sarbanes-Oxley
  • OAuth

Summary

Position Overview: The Identity Architect will define and guide an enterprise identity architecture that connects authentication, identity governance, privileged access, secrets management, identity security, and multi-cloud identity into a cohesive operating model. This role will help evolve identity and access management (IAM) from platform-specific activities into an identity-as-a-service capability that enables the business while improving security, auditability, and user experience. The architect will combine technical depth, practical judgment, and strong communication to guide technical and business stakeholders through architecture decisions and implementation paths.

Onsite - Dallas 5x a week

Responsibilities:

· Own and maintain the target-state IAM architecture, reference patterns, principles, standards, and technology roadmap.

· Assess current identity capabilities and recommend improvements across Microsoft Active Directory, Microsoft Entra ID, hybrid identity, cloud identity, authentication, authorization, identity governance, privileged access management (PAM), secrets management, and identity security.

· Design how identity governance, PAM, multifactor authentication (MFA), secrets management, directories, applications, and security tooling should work together.

· Establish architecture patterns for human identities, service accounts, application identities, workload identities, privileged identities, and other non-human identities.

· Define identity lifecycle, joiner/mover/leaver, access request, access review, role, entitlement, privileged access, and exception management patterns.

· Guide single sign-on (SSO), MFA, Conditional Access, federation, identity proofing, adaptive access, and application integration decisions.

· Evaluate integration approaches using application programming interfaces (APIs), connectors, System for Cross-domain Identity Management (SCIM), Security Assertion Markup Language (SAML), OAuth 2.0, OpenID Connect, and related protocols.

· Provide architecture guidance for identity across Microsoft Azure and Amazon Web Services (AWS), including cloud identity models, account structures, roles, permissions, and governance.

· Translate business, security, regulatory, and operational requirements into architecture decisions, detailed requirements, implementation sequencing, and transition plans.

· Review proposed designs and implementations for least privilege, resiliency, supportability, auditability, and alignment with approved standards.

· Partner with IAM leadership, identity engineers, analysts, application teams, cloud teams, security operations, audit, compliance, and organizational change management.

· Use PowerShell, Python, APIs, data exports, or other practical techniques when a platform limitation requires an alternate solution or automation path.

· Maintain architecture documentation, decision records, data flows, integration diagrams, control mappings, and operational standards.

· Support remediation planning for identity data quality, orphaned accounts, stale identities, over-provisioned access, service-account ownership, and privileged-access risk.

· Advise on identity monitoring, detection, incident response, and integration with existing security tooling.

Qualifications:

· 10 or more years of progressive experience in identity, access management, cybersecurity, infrastructure, enterprise architecture, or a closely related discipline.

· 7 or more years of hands-on IAM architecture or senior IAM engineering experience in a large enterprise environment.

· Strong experience with Microsoft Active Directory and Microsoft Entra ID, including hybrid identity, directory synchronization, authentication, authorization, Conditional Access, MFA, and privileged access.

· Demonstrated experience designing or integrating at least two enterprise IAM platforms, with Saviynt preferred and SailPoint accepted.

· Experience with CyberArk or a comparable PAM platform, secrets management, and privileged identity controls.

· Strong understanding of IAM governance, lifecycle management, access reviews, role-based access control, segregation of duties, least privilege, and audit evidence.

· Practical knowledge of AWS and Azure identity and security models.

· Experience with APIs, application integration patterns, federation, SAML, OAuth 2.0, OpenID Connect, SCIM, and automation.

· Ability to analyze complex environments, make architecture decisions, document them clearly, and influence stakeholders without direct authority.

· Ability to work onsite in the Dallas-Fort Worth area approximately 2 to 3 days per week.

· Preferred qualifications:

· Experience in electric utilities, critical infrastructure, North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP), Sarbanes-Oxley Act (SOX), IT general controls, or similarly regulated environments.

· Microsoft identity or security certification, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Saviynt, SailPoint, CyberArk, AWS, or Azure certification.

· Experience with identity threat detection and response, identity security posture management, service-account governance, or non-human identity programs.

· Experience building identity standards, operating models, roadmaps, and governance forums.

Tools and Technologies:

  • Microsoft Active Directory
  • Microsoft Entra ID
  • Azure
  • AWS
  • Saviynt or SailPoint
  • CyberArk or comparable PAM platforms
  • MFA solutions
  • Secrets-management technologies
  • PowerShell
  • Python
  • APIs
  • SCIM
  • SAML
  • OAuth 2.0
  • OpenID Connect
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91097117
  • Position Id: 9099456
  • Posted 3 hours ago

Company Info

About Cloud Destinations LLC

One of the leading US-based staffing and IT consulting partner. Experience exceptional service and top-tier talent across industries. Count on us for staffing solutions that cater to the unique demands of the American market.

Our experienced recruiters ensure a seamless fit within your team, accelerating success. But we go beyond staffing and empower employees with fully sponsored certification programs, keeping them ahead. Experience comprehensive benefits including health, wellness coverage, dental insurance, vision insurance, as well as flexible hours, remote work options, and a robust 401K plan to ensure a secure future at the companies we represent.

At Cloud Destinations, we bring industry expertise and a passion for excellence. From Enterprise Cloud Strategy to Managed Infrastructure Services, Digital Transformation, BI & Data Analytics, Security, Data Engineering, and more, we navigate the IT landscape with finesse. Choose us as your trusted partner, witness transformative talent and exceptional service. Let's unlock new possibilities and drive your success in the dynamic world of IT together.

About_Company_One
Contact the job poster
GM

Govindaraj Muthusamy

Recruiter @ Cloud Destinations LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in Dallas, Texas

•

Today

Easy Apply

Contract

$70 - $80

Remote

•

Today

Easy Apply

Contract

Depends on Experience

Remote

•

Today

Easy Apply

Contract

Depends on Experience

Remote

•

Today

Easy Apply

Contract

Up to $65

Search all similar jobs