> Markdown version of [/jobs/ext/1183528-identity-and-access-management-architect](https://www.wearedevelopers.com/jobs/ext/1183528-identity-and-access-management-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management Architect - **Company:** Deloitte T.T.L. - **Location:** Chicago, IL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Biometrics, Continuous Integration, DevOps, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Azure Active Directory, Cloud Services, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Cyberark, Togaf, SailPoint - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=42e410ca8f1f2f6e ## About the Role Do you possess the following?: 10+ years of IAM experience with progressive technical leadership, experience in a consulting or large enterprise environment preferred. Proven track record designing, delivering, and operating enterprise-scale IAM solutions across cloud and on-prem environments. Deep technical knowledge of authentication/authorization protocols and standards (OAuth2/OIDC, SAML, SCIM, LDAP) and modern IAM architectures. Hands-on experience with at least two major IAM technologies (e.g., Entra ID/Azure AD, Microsoft AD, CyberArk, SailPoint, Ping Identity). Strong stakeholder management and communication skills, able to present technical concepts to executive audiences and translate business needs into technical requirements. Experience leading vendors, technical teams, and cross-functional workstreams to successful outcomes. Advanced degree (MS) or certifications (e.g., CISSP, CISM, SABSA, TOGAF, vendor-specific IAM certs). Experience with zero-trust identity models, identity governance, privileged access management, and modern authentication modalities (passwordless, biometrics, adaptive MFA). Prior experience building IAM programs or working in high-regulation industries (finance, healthcare, government). Balance strategic thinking with the ability to roll up sleeves and deliver technically where needed. Identity Providers / Directories: Entra ID/Azure AD, Microsoft AD Identity Governance and PAM: SailPoint, CyberArk Authentication & Federation: Ping Identity, OAuth2/OIDC, SAML, SCIM Cloud & DevOps integration: AWS/Azure/GCP identity services, CI/CD tooling ## Description We are seeking a Senior Manager-level IAM Architect to partner with Senior IAM leadership team to define and drive the technical strategy and architecture for Identity and Access Management (IAM) across the organization. This role combines strategic leadership, hands-on solution design with product owners, and senior level stakeholder engagement, to secure identities, enable business objectives, and improve user experience across digital channels. This individual must have a pulse on the emerging identity technology trends and best practices to coordinate with Product Owners for integrated IAM architectures and roadmaps. Core Responsibilities Partner with Senior IAM leadership team to define and own the enterprise IAM architecture, strategy, reference patterns, and roadmaps across authentication, authorization, identity lifecycle, privileged access, and account protection. Engage in executive level leadership conversations, translate business goals into IAM requirements, coordinate with IAM product owners on technical feasibility to ensure solutions scale and interoperate across on-premises, cloud, and hybrid environments. Partner with IAM product technical leads to assist with technical design and implementation for authentication (e.g. MFA, SSO, etc), authorization models (e.g. RBAC, ABAC, etc), identity provisioning, lifecycle management, and privileged access controls. Champion innovation with Identity and Access Management tools, evaluate and provide recommendations to product owners for consideration and integration with the existing platform, while balancing security, privacy, and usability. Architect secure integrations between IAM platforms and applications, directories, cloud services, and CI/CD pipelines, set standards and reusable patterns for developers. Partner with IAM Sr. Leadership team and IAM product technical leads to address IAM risk assessments, threat modeling, and remediation strategies, partner with security, risk, and compliance teams to implement controls and measure risk reduction. Partner with IAM product technical leads to oversee incident response activities as they relate to identity compromise, and lead post-incident root-cause analysis and remediation. Drive adoption: create technical guidance, architecture diagrams, and executive-level briefings, mentor architects and senior engineers on IAM best practices. Collaborate with product, engineering, and business leaders to prioritize roadmap items, measure outcomes (security posture, access-related incidents, time-to-provision), and demonstrate business value. Ensure compliance with relevant regulations and internal policies, support audits and attestations related to identity and access controls. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)