IAM - Senior Lead / Architect

Ampcus Inc
Seattle, WA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) Amazon Web Services User Authentication Microsoft Azure Software as a Service Cyber Security Data Governance Software Design Patterns Multi-Factor Authentication Federated Identity Management Identity and Access Management
+26 more
Intrusion Detection and Prevention Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) Microsoft Software OAuth OpenID Role-Based Access Control Openid Connect Azure Active Directory Ansible Phishing Zero Trust Network Access Sherwood Applied Business Security Architecture Security Assertion Markup Language (SAML) Security Information and Event Management Software Deployment Google Cloud Application Enhancement Tool Cloud Platform System Okta Multi-Cloud Togaf Information Technology Deployment Automation SailPoint Terraform

Job description

  • Define and own the target-state architecture and reference designs for the enterprise identity security platform across BeyondTrust (Password Safe, EPM, PRA), Microsoft Entra ID, Active Directory, and SailPoint IdentityNow (IDN).
  • Lead the architecture and deployment strategy for large-scale identity security modernization initiatives, including privileged access transformation, identity governance modernization, cloud identity adoption, Active Directory and hybrid identity modernization, and Zero Trust identity implementations.
  • Establish architecture standards, design patterns, integration blueprints, and governance guardrails for engineering teams, while serving as the design authority through architecture and design reviews.
  • Develop migration and deployment strategies, including sequencing, cutover planning, rollback procedures, and risk mitigation, to transition large user populations and enterprise systems to modern identity platforms with minimal business disruption.
  • Architect integrations across identity platforms, cloud environments (Azure, AWS, GCP), and enterprise/SaaS applications using APIs and identity standards such as SAML, OAuth 2.0/OpenID Connect (OIDC), SCIM, Kerberos, and LDAP.
  • Drive enterprise adoption of phishing-resistant authentication and least-privilege privileged access management (PAM) architecture.
  • Collaborate with engineering, security architecture, cloud/platform teams, product management, and program management to convert architectural vision into executable delivery roadmaps.
  • Provide technical leadership to engineering teams by reviewing solution designs and implementations to ensure compliance with architectural and security standards.
  • Identify, document, and communicate architectural risks, dependencies, and trade-offs to technical teams and executive stakeholders.
  • Ensure identity security solutions align with enterprise security, compliance, and data governance requirements.
  • Utilize AI-powered tools to improve architecture analysis, solution evaluation, and technical documentation.

Requirements

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience.
  • 15+ years of experience in security or identity engineering, including significant experience as an Identity or Security Architect in large enterprise environments.
  • Proven experience leading enterprise-scale identity security modernization initiatives from architecture through production deployment.
  • Deep expertise in at least two of the following platforms, with working knowledge of the others:
  • BeyondTrust
  • Microsoft Entra ID
  • Active Directory
  • Okta
  • SailPoint IdentityNow (IDN)
  • Strong knowledge of identity and access management concepts, including:
  • Authentication and authorization protocols (SAML, OAuth 2.0/OIDC, SCIM, Kerberos, LDAP)
  • Identity federation
  • Multi-factor authentication (MFA) and phishing-resistant authentication
  • Role-Based and Attribute-Based Access Control (RBAC/ABAC)
  • Least privilege principles
  • Tiered administration
  • Zero Trust architecture
  • Experience designing and executing identity integrations and migrations across hybrid and multi-cloud environments.
  • Experience establishing enterprise architecture standards and serving as the design authority across multiple engineering teams.
  • Excellent communication and stakeholder management skills with the ability to present architectural decisions and trade-offs to both technical and executive audiences.
  • Ability to work independently in a fast-paced environment managing multiple concurrent initiatives., * Industry certifications such as CISSP, SABSA, TOGAF, Microsoft Identity & Access Administrator (SC-300), or SailPoint Certified Engineer.
  • Experience with Infrastructure as Code (Terraform, Ansible) and CI/CD pipelines supporting identity platform deployments.
  • Experience with Identity Threat Detection and Response (ITDR) and integrating identity telemetry into SIEM/SOAR platforms.
  • Experience supporting large-scale retail, e-commerce, or other high-transaction enterprise environments.

About the company

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

Videos

See all

Related articles

See all