Job Title: Cybersecurity Specialist (IAM)
Location: Irving, TX
Employment Type: Full-time
Job Description:
Cybersecurity Specialist Principal Identity Security Architect & Product Engineering Lead
Overview
We are seeking a highly experienced Principal Identity Security Architect & Product Engineering Lead to drive the design, engineering, and deployment of next-generation identity security capabilities across the enterprise. This role leads initiatives focused on attack path analysis, identity threat detection and response (ITDR), behavioral analytics, authentication modernization, policy-based access control (PBAC), and identity-driven attack containment. The position collaborates across cybersecurity, infrastructure, architecture, and product engineering teams to advance strategic Zero Trust transformations and strengthen overall cyber defense.
Required Experience & Qualifications
10+ years of experience in Cybersecurity, IAM Architecture, Identity Governance, or Security Engineering.
Proven track record leading enterprise-scale identity transformation programs in large, complex, highly regulated environments.
Deep knowledge of NIST frameworks, Zero Trust Architecture (ZTA), and modern identity threat models.
Relevant industry certifications preferred: CISSP, CCSP, Microsoft Certified: Azure Security Engineer, CIAM, or equivalent.
Must Have Technical/Functional Skills
IAM & Security Architecture:
Deep expertise in enterprise IAM architecture, Zero Trust security models, and identity governance frameworks.
Solid grasp of Identity Threat Detection and Response (ITDR), attack path analysis, privilege escalation defense, and risk-based authentication.
Comprehensive knowledge of SSO, MFA, Federation protocols (SAML, OIDC, OAuth 2.0), Privileged Access Management (PAM), and machine/workload identity lifecycle.
Product Expertise:
Strong hands-on engineering and integration experience with PlainID and Sgnl.ai.
Advanced deployment and operational knowledge of CrowdStrike Identity Protection and Microsoft Entra ID (Azure AD).
Engineering & Integration:
Proven capability in security product engineering, API integrations, identity orchestration, and cloud-native architectures.
Expertise in implementing Policy-Based Access Control (PBAC), dynamic authorization models, and fine-grained entitlement governance.
Strong ability to translate complex business and regulatory compliance requirements into secure, resilient, and scalable technical patterns.
Roles & Responsibilities
Identity Security Strategy & Architecture:
Define, maintain, and execute enterprise identity security roadmaps aligned with Zero Trust principles.
Architect scalable IAM solutions supporting workforce, customer, privileged, and machine identities across hybrid and multi-cloud environments.
Establish security baselines, architectural standards, and governance policies for authentication, dynamic authorization, and access management.
Product Engineering & Platform Delivery:
Lead end-to-end product engineering, configuration, and integration for Sgnl.ai, PlainID, CrowdStrike Identity Protection, and Entra ID.
Partner with security product vendors and internal engineering teams to operationalize tools and eliminate identity security blind spots.
Integrate identity platforms seamlessly into enterprise applications, APIs, and hybrid cloud infrastructure.
Threat Protection, ITDR & Attack Path Analysis:
Expand attack path mapping and graph-based analysis to proactively identify and remediate lateral movement risks and privilege escalation vectors.
Implement identity threat detection mechanisms, risk scoring, behavioral analytics, and automated attack containment workflows.
Enhance visibility into complex identity relationships, cross-system entitlements, and toxic access combinations.
Authentication & Access Modernization:
Advance Policy-Based Access Control (PBAC) adoption using PlainID to deliver context-aware, fine-grained access decisions.
Accelerate the rollout of passwordless/strong authentication, adaptive MFA, and modern authenticator capabilities while optimizing user experience.
Design and implement continuous verification models, combining behavioral telemetry with contextual signals to inform real-time access decisions.