Identity Architect 100% Remote
POSITION SUMMARY
The Senior Identity Architect is a senior-level, hybrid leadership role operating as a high-influence individual contributor. This position is responsible for defining the long-term vision, strategy, and target architecture for the enterprise IAM program.
The successful candidate will serve as a hands-on technical authority, translating enterprise-level strategy into actionable engineering blueprints. This role will lead the unification of a diverse identity landscape developed across multiple business cycles and establish an executable 5-year modernization roadmap.
The position requires immediate impact by identifying and mitigating the highest-risk areas while simultaneously developing the long-term IAM strategy. The Senior Identity Architect will serve as the authoritative voice on how identities are governed, authenticated, and authorized while ensuring compliance with stringent federal and state utility regulations.
KEY RESPONSIBILITIES
Tactical Execution & Architecture Unification
- Conduct an immediate, visually driven inventory of the distributed identity landscape across corporate IT, cloud, and operational technology (OT) environments.
- Develop technical diagrams, end-to-end process workflows, and architectural visualizations that clearly communicate current and future-state identity architectures to executive and technical audiences.
- Identify the highest-risk areas and greatest opportunities for short-term improvement within the first 90 days and implement practical tactical remediations.
- Establish authoritative enterprise identity standards and technical baselines across the organization.
- Define transformation milestones, operational metrics, and measurable objectives to track migration from legacy infrastructure to modern, consolidated identity ecosystems.
Regulatory Compliance & Governance Engineering
- Architect identity solutions that address regulatory requirements applicable to publicly traded utilities, including:
- Public Service Commission (PSC)
- Sarbanes-Oxley (SOX)
- Payment Card Industry Data Security Standard (PCI-DSS)
- North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP)
- Transportation Security Administration (TSA) security directives
- Partner with Compliance, Control Owners, and technical teams to design access controls and automated evidence-generation workflows that support repeatable audit outcomes.
- Develop unified identity architectures and operational patterns that satisfy overlapping regulatory requirements while eliminating redundant compliance-specific silos.
- Implement Identity Governance and Administration (IGA) frameworks focused on:
- Role-Based Access Control (RBAC)
- Automated Joiner-Mover-Leaver (JML) processes
- Separation of Duties (SoD)
- Identity lifecycle governance
- General IT controls
SECURITY FRAMEWORK & CLOUD INTEGRATION
- Align enterprise identity architecture with industry-standard security frameworks, including NIST Cybersecurity Framework (NIST CSF) and CIS Critical Security Controls.
- Drive adoption of Zero Trust principles, positioning identity as a practical security perimeter across cloud and on-premises environments.
- Architect secure identity lifecycles for AI agents, large language models (LLMs), and automated programmatic workloads.
- Establish least-privilege authentication and authorization models for AI and automated workloads.
- Develop adaptive governance models addressing data access, API authentication, and runtime security challenges associated with enterprise AI technologies.
CROSS-FUNCTIONAL PARTNERSHIP & LEADERSHIP
- Partner with business leaders, Enterprise Architecture, Infrastructure, and Operational Technology teams to align localized technical decisions with enterprise identity strategy.
- Collaborate with Human Resources to establish the HR Information System (HRIS) as the authoritative source for identity lifecycle events.
- Enable real-time, automated downstream access changes based on employee onboarding, transfers, and terminations.
- Serve as a consultative advisor to cross-functional teams, identifying deviations from enterprise identity standards and recommending appropriate strategic adjustments.
BEHAVIORAL COMPETENCIES
- Organizational Humility – Prioritize enterprise transformation and collaboration while actively listening to and validating challenges across business units.
- Execution Drive – Take ownership of complex technical environments, proactively resolve challenges, and consistently drive modernization initiatives forward.
- Interpersonal Agility – Clearly communicate complex identity and security concepts to technical and non-technical stakeholders while building strong cross-functional relationships.
QUALIFICATIONS & EXPERIENCE
Required Experience
- 10+ years of experience in Cybersecurity, Information Security, or Enterprise Architecture.
- At least 5 years of dedicated experience in enterprise-scale IAM architecture and design.
- Proven experience leading identity transformation programs within highly regulated industries such as utilities, financial services, aerospace, or critical infrastructure.
- Extensive experience designing, visualizing, and implementing IAM solutions across hybrid environments, including multi-tier infrastructure and major public cloud platforms.
PREFERRED TECHNICAL EXPERIENCE
Identity Governance & Administration (IGA)
- SailPoint
- Saviynt
- Equivalent IGA platforms
- Access Management & Federation
- Microsoft Entra ID
- Okta
- Ping Identity
- SAML 2.0
- OIDC
- OAuth 2.0
- SCIM
Privileged Access Management (PAM)
- CyberArk
- BeyondTrust
- Delinea
CERTIFICATIONS & TRAINING
Candidates should possess advanced, industry-recognized certifications demonstrating cybersecurity and architectural expertise, such as:
- CISSP – Certified Information Systems Security Professional
- CISSP-ISSAP – Information Systems Security Architecture Professional
- TOGAF – The Open Group Architecture Framework
- SABSA – Sherwood Applied Business Security Architecture
- Advanced SANS/GIAC certifications, such as GDSA, Google Cloud PlatformM, or GSEC
- Identity Management Institute credentials, including CIAM or CIMP, are a plus.