Job title: IAM Architect
Work Location: Fort Mill, USA
Onsite
Minimum years of experience: 10 Years
Job Description:
IAM Architecture & Solution Design
Define and implement enterprise IAM architecture aligned with business, security, and regulatory requirements.
Design end-to-end IAM solutions covering:
We are seeking a highly experienced IAM Architect with 10+ years of overall IT experience and strong expertise in designing, implementing, and supporting enterprise-scale Identity and Access Management (IAM) solutions. The ideal candidate should possess deep hands-on and architectural experience across ForgeRock IGA, ForgeRock IDM, PingFederate, SailPoint IIQ, and SailPoint IdentityNow / IDM, with a strong understanding of identity lifecycle management, access governance, authentication, federation, SSO, compliance, and privileged access integration.
Identity lifecycle management (Joiner-Mover-Leaver) Access request and provisioning Certification / access reviews Role-based access control (RBAC) Authentication and Single Sign-On (SSO) Federation and delegated authentication Password management and self-service Develop architecture patterns for cloud, on-prem, and hybrid IAM environments.
Create high-level and low-level design documents, integration architecture, data flows, trust models, and security controls.
Platform Expertise
Lead implementation and governance of IAM platforms including:
ForgeRock IGA
ForgeRock IDM
PingFederate
SailPoint IdentityIQ (IIQ)
SailPoint IdentityNow / SailPoint IDM
Architect solutions for provisioning, reconciliation, account correlation, policy enforcement, and workflow orchestration.
Design and support connector strategy for directories, HR systems, databases, cloud apps, and enterprise applications.
Authentication, Federation & SSO
Design and implement SSO and federation solutions using PingFederate and related standards. Integrate enterprise applications using:
SAML 2.0
OAuth 2.0
OpenID Connect (OIDC)
WS-Federation
LDAP / Active Directory
Architect secure access patterns for internal users, external users, partners, and customer-facing identities where required.
Work closely with application and infrastructure teams to onboard applications into the enterprise IAM ecosystem.