Job#: 3021408 Job Description: Job Description: IAM ArchitectLocation: Remote (Preference for candidates based in or near
Coral Gables, FL or
Juno Beach, FL)
Position Type: Full-Time
Department: Identity & Access Management
Reports To: IAM Program Leadership (Cameron Buck)
SummaryWe are seeking a highly experienced
Identity & Access Management (IAM) Architect to serve as the senior technical lead for the enterprise IAM program. This role will shape and guide the overall IAM architecture across corporate and SIP environments, define both current and future-state strategies, and provide technical oversight for critical implementation initiatives. The ideal candidate brings deep IAM expertise, strong architectural vision, and the ability to influence and lead across a fragmented and evolving identity landscape.
This is a high-visibility role supporting mission-critical programs, requiring the ability to rapidly onboard, partner across diverse teams, and act as the key strategic advisor for IAM within the organization.
Key ResponsibilitiesIAM Strategy & Architecture- Serve as the enterprise IAM Architect, responsible for the holistic IAM strategy and roadmap (not a solution architect role).
- Evaluate current IAM platforms (SailPoint, ISOM, Azure Entra, CyberArk, etc.) and define a scalable, future-state architecture.
- Lead architectural reviews, solutioning discussions, and long-term identity modernization efforts.
Solution Design & Governance- Design solutions for ABAC, passwordless authentication, RBAC, role engineering, just-in-time (JIT) access, and identity lifecycle automation.
- Define governance models, access control frameworks, and product ownership responsibilities.
- Develop and maintain architectural standards, documentation, and role matrices.
Implementation Leadership- Partner with internal teams and external vendors to drive implementation across:
- Access Governance
- Identity Lifecycle & Provisioning
- Authentication & Federation
- Privileged Access Management (PAM)
- Provide oversight, guidance, and technical leadership for high-impact programs such as Optimus (power generation access control) and passwordless initiatives.
Collaboration & Mentorship- Influence and guide teams across corporate IT, SIP, OT, directory services, and authentication domains.
- Mentor engineers, solution architects, and technical resources assigned to IAM platforms or projects.
- Act as a bridge between leadership, engineering, and vendor partners to ensure alignment and execution success.
Skills & ExperienceRequired- Significant senior-level experience in IAM architecture, identity governance, and enterprise access strategies.
- Deep understanding of IAM platforms (SailPoint preferred) - hands-on experience valued, but architectural expertise is prioritized.
- Strong ability to design solutions for complex, multi-environment ecosystems (corporate + OT/SIP).
- Demonstrated success influencing technical direction without direct authority.
- Experience working with and guiding vendors, implementation partners, and cross-functional teams.
Preferred- Experience with passwordless technologies, ABAC, RBAC modernization, or JIT access.
- Background supporting OT security or mixed IT/OT identity environments.
- Familiarity with NERC CIP or similar regulatory frameworks (depending on environment).
Environment & Context- Operates within a federated identity landscape where ownership spans multiple teams.
- Partners closely with senior IAM leadership and works across high-stakes strategic initiatives.
- Remote role with preference for candidates in the Eastern time zone.
- Occasional on-site presence in Coral Gables or Juno Beach as needed for workshops or project milestones.
Key Focus Areas- Enterprise IAM architecture & strategic planning
- Identity modernization and future-state solutioning
- Governance model design and long-term framework creation
- Implementation oversight and vendor coordination
Ideal Candidate ProfileA senior IAM leader who thrives in complex environments, brings clarity to fragmented identity ecosystems, and can serve as the "right-hand" technical authority to IAM leadership. Someone who balances strategic thinking with pragmatic execution guidance, and who is comfortable driving transformation across both corporate and operational technology environments.
Apex Systems is a world-class IT services company that serves thousands of clients across the globe. When you join Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Apex uses a virtual recruiter as part of the application process. Click for more details.
Apex Benefits Overview: Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Apex team member can provide.