Non-Human Identity Architect - PAM and AuthN

The Information Technology
Tempe, AZ, United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$120,000.0 - $204,300.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence User Authentication Cloud Computing Cloud Engineering Cyber Security Identity and Access Management Information Security Management Intrusion Detection and Prevention Key Management Automation of Marketing
+9 more
Ping (Networking Utility) Public Key Infrastructure Azure Active Directory Zero Trust Network Access SSL Certificate Management Cyberark Kubernetes Hashicorp Devsecops

Job description

The Non-Human Identity Architect serves as a technical leader responsible for defining, designing, implementing, and governing enterprise identity security solutions across Authentication (AuthN), Privileged Access Management (PAM), Non-Human Identity (NHI), and AI Security domains. This role partners with engineering, architecture, cybersecurity, infrastructure, cloud, application, and business teams to establish future-state identity security capabilities, reduce organizational risk, and support business transformation initiatives.

What You’ll Do:

  • Establish an enterprise NHI governance program.

  • Develop AI identity security standards and controls.

  • Reduce organizational risk associated with machine and privileged identities.

  • Modernize identity security capabilities through adoption of industry standards, passwordless authentication, workload identity federation, credential-less architectures, ephemeral access models, modern trust frameworks, and cloud-native identity patterns

  • Deliver target-state identity security architecture for cloud, AI, and automation platforms.

  • Improve compliance, audit readiness, and operational maturity across AuthN and PAM programs.

  • Serve as the teams lead technical authority and partner with Enterprise Architecture for emerging identity security domains, including NHI, Machine Identity Security, and AI Security.

  • Develop and maintain enterprise NHI strategy for PAM and AuthN teams in partnership with IGA, Infrastructure, Cloud, Cybersecurity, Application, and Enterprise Architecture teams.

  • Establish governance and lifecycle management processes for:

  • Service Accounts

  • Application Accounts

  • API Identities

  • Service Principals

  • Managed Identities

  • Certificates

  • Machine Credentials

  • Robotic Process Automation (RPA) Identities

  • AI Agents

  • Agentic Identities

  • Delegated Workloads

  • Composite Workloads

  • Dynamic Client Registrations

  • Autonomous Service Identities

  • Lead initiatives to improve visibility, ownership, and control of non-human identities across the enterprise.

  • Define standards for credential rotation, ownership certification, and audit compliance.

  • Establish enterprise NHI inventory and risk-management frameworks, Establish enterprise inventory, governance standards, ownership models, and risk management practices for non-human identities.

Requirements

  • 10+ years of experience in Identity and Access Management, Cybersecurity, Infrastructure Engineering, or Enterprise Architecture.

  • Deep expertise in:

  • Authentication Technologies

  • MFA

  • Entra ID / Azure AD

  • Privileged Access Management

  • CyberArk

  • Hashicorp

  • Identity Governance

  • Secrets Management

  • Bitwarden

  • PingOne AIC

  • Powerbroker

  • Ping Federate

Ping Access

What Could Set You Apart:

  • Non-Human Identity (NHI) Governance

  • Machine Identity Security

  • Cloud Identity Architecture

  • AI Security and AI Governance

  • Workload Identity Federation

  • Zero Trust Architecture

  • DevSecOps Security

  • Kubernetes and Container Security

  • Certificate Lifecycle Management

  • Authorization Management

  • Policy Decision & Enforcement Frameworks

  • Policy Orchestration

  • Identity Threat Detection & Response (ITDR)

  • Identity Security Posture Management (ISPM)

  • Hybrid Identity Resilience

  • Ephemeral Credential Management
  • Experience designing and implementing enterprise-scale Identity Security Architectures, including Authentication, PAM, Non-Human Identity, Secrets Management, Credential Management, Workload Identity, PKI, Certificate Management, SPIFFE/SPIRE-based identity patterns, and AI/Agentic identity security architectures and partnering with enterprise-scale security architects.
  • Experience leading cross-functional initiatives and influencing technical direction across organizations.

Benefits & conditions

$120,000 - $204,300 a year - Full-time, Pulled from the full job description

  • AD&D insurance
  • 401(k)
  • Health insurance
  • Health savings account
  • Dental insurance
  • Flexible spending account
  • Employee assistance program, 120,000.00 - 204,300.00 Annual

Type

Full-time

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:39 min

Generating dynamic application secrets using HashiCorp Vault engines

Alex Soto Alex Soto · LIVE

Videos

See all

Related articles

See all