> Markdown version of [/jobs/ext/1646235-iam-senior-lead-architect](https://www.wearedevelopers.com/jobs/ext/1646235-iam-senior-lead-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM - Senior Lead / Architect - **Company:** Ampcus Inc - **Location:** Seattle, WA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, User Authentication, Microsoft Azure, Software as a Service, Cyber Security, Data Governance, Software Design Patterns, Multi-Factor Authentication, Federated Identity Management, Identity and Access Management, Intrusion Detection and Prevention, Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), Microsoft Software, OAuth, OpenID, Role-Based Access Control, Openid Connect, Azure Active Directory, Ansible, Phishing, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Deployment, Google Cloud, Application Enhancement Tool, Cloud Platform System, Okta, Multi-Cloud, Togaf, Information Technology, Deployment Automation, SailPoint, Terraform - **Published:** July 11, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17549861?backUrl=%2Fcareer%2F17549861%2FIam-Senior-Lead-Architect-Washington-Seattle ## About the Role * Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience. * 15+ years of experience in security or identity engineering, including significant experience as an Identity or Security Architect in large enterprise environments. * Proven experience leading enterprise-scale identity security modernization initiatives from architecture through production deployment. * Deep expertise in at least two of the following platforms, with working knowledge of the others: + BeyondTrust + Microsoft Entra ID + Active Directory + Okta + SailPoint IdentityNow (IDN) * Strong knowledge of identity and access management concepts, including: + Authentication and authorization protocols (SAML, OAuth 2.0/OIDC, SCIM, Kerberos, LDAP) + Identity federation + Multi-factor authentication (MFA) and phishing-resistant authentication + Role-Based and Attribute-Based Access Control (RBAC/ABAC) + Least privilege principles + Tiered administration + Zero Trust architecture * Experience designing and executing identity integrations and migrations across hybrid and multi-cloud environments. * Experience establishing enterprise architecture standards and serving as the design authority across multiple engineering teams. * Excellent communication and stakeholder management skills with the ability to present architectural decisions and trade-offs to both technical and executive audiences. * Ability to work independently in a fast-paced environment managing multiple concurrent initiatives., * Industry certifications such as CISSP, SABSA, TOGAF, Microsoft Identity & Access Administrator (SC-300), or SailPoint Certified Engineer. * Experience with Infrastructure as Code (Terraform, Ansible) and CI/CD pipelines supporting identity platform deployments. * Experience with Identity Threat Detection and Response (ITDR) and integrating identity telemetry into SIEM/SOAR platforms. * Experience supporting large-scale retail, e-commerce, or other high-transaction enterprise environments. ## Description * Define and own the target-state architecture and reference designs for the enterprise identity security platform across BeyondTrust (Password Safe, EPM, PRA), Microsoft Entra ID, Active Directory, and SailPoint IdentityNow (IDN). * Lead the architecture and deployment strategy for large-scale identity security modernization initiatives, including privileged access transformation, identity governance modernization, cloud identity adoption, Active Directory and hybrid identity modernization, and Zero Trust identity implementations. * Establish architecture standards, design patterns, integration blueprints, and governance guardrails for engineering teams, while serving as the design authority through architecture and design reviews. * Develop migration and deployment strategies, including sequencing, cutover planning, rollback procedures, and risk mitigation, to transition large user populations and enterprise systems to modern identity platforms with minimal business disruption. * Architect integrations across identity platforms, cloud environments (Azure, AWS, GCP), and enterprise/SaaS applications using APIs and identity standards such as SAML, OAuth 2.0/OpenID Connect (OIDC), SCIM, Kerberos, and LDAP. * Drive enterprise adoption of phishing-resistant authentication and least-privilege privileged access management (PAM) architecture. * Collaborate with engineering, security architecture, cloud/platform teams, product management, and program management to convert architectural vision into executable delivery roadmaps. * Provide technical leadership to engineering teams by reviewing solution designs and implementations to ensure compliance with architectural and security standards. * Identify, document, and communicate architectural risks, dependencies, and trade-offs to technical teams and executive stakeholders. * Ensure identity security solutions align with enterprise security, compliance, and data governance requirements. * Utilize AI-powered tools to improve architecture analysis, solution evaluation, and technical documentation. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)