Job Title: Information Security Architect IAM / PAM
Work Location: Remote (Anywhere in the Continental US East Coast preferred)
Job Type: Contract (12 Months with potential extension)
Candidate Submission Note:
Crucial Requirement: Candidate resumes must explicitly feature a summary or skills matrix at the top of the resume breaking down total years of experience across the core required areas:
- Privileged Access Management (PAM): 5+ Years
- Active Directory: 8+ Years
- Microsoft Entra ID (Azure AD): 3+ Years
- IAM Controls & Governance: 4+ Years
Position Overview
The Identity and Access Management (IAM) team is seeking an experienced IAM Solution Architect to lead the design, development, and enterprise-wide implementation of robust IAM and PAM solutions. This role is responsible for ensuring secure, scalable, and seamless identity services across enterprise platforms, hybrid multi-cloud environments, and SaaS applications.
You will partner closely with business stakeholders, engineering units, and cybersecurity leadership to establish architectural roadmaps, select best-in-breed vendor tooling, and enforce modern identity controls supporting ongoing digital transformation initiatives.
Key Responsibilities
- Architecture & Solution Design: Lead the end-to-end design, architecture, and governance of enterprise IAM solutions covering authentication, authorization, privileged access management (PAM), and full identity lifecycle management.
- Domain SME: Serve as an enterprise subject matter expert in identity standards, protocols, and control frameworks, including SAML, OIDC, OAuth2, SCIM, PAM, RBAC, and ABAC.
- Hybrid & Cloud Integration: Architect and oversee the integration of IAM platforms with hybrid directory services, on-prem enterprise systems, multi-cloud platforms (AWS, Azure, Google Cloud Platform), and SaaS solutions.
- Roadmaps & Patterns: Establish and maintain reference architectures, target-state identity roadmaps, standard design patterns, and deployment playbooks.
- Vendor & Tooling Evaluation: Drive technical evaluations, proof-of-concept (POC) assessments, and RFP processes for IAM/PAM software and vendor platforms.
- Engineering Mentorship: Provide technical leadership and best-practice guidance to security engineering teams regarding identity integration methods and secure configurations.
- Compliance & Governance: Ensure IAM designs align with enterprise cybersecurity policies and adhere to strict regulatory compliance standards (SOX, PCI-DSS, GDPR).
Required Qualifications & Experience
- Privileged Access Management (PAM): 5+ years of dedicated, hands-on architectural experience designing and deploying PAM platforms (e.g., CyberArk, BeyondTrust, HashiCorp Vault, or Delinea).
- Directory Services: 8+ years of deep architecture and administration experience with on-premises Active Directory (AD forest trusts, Kerberos, LDAP, Group Policies).
- Microsoft Entra ID (Azure AD): 3+ years architecting and managing Microsoft Entra ID deployments, conditional access, hybrid identity sync, and cloud role management.
- IAM Controls & Frameworks: 4+ years evaluating and architecting identity controls, access certifications, segregation of duties (SoD), and lifecycle workflows.
- Strong familiarity with federation and access protocols: SAML, OAuth 2.0, OpenID Connect (OIDC), and SCIM.
- Solid experience integrating enterprise identity solutions into public cloud architectures (AWS, Azure, or Google Cloud Platform).
- Exceptional communication and presentation skills, with proven ability to interface effectively between executive leadership and technical engineering teams.
Thanks
Sri Vardhan Chilakamukku
Infobahn SoftWorld Inc.