> Markdown version of [/jobs/ext/1768206-principal-cybersecurity-architect-identity-iam-zero-trust](https://www.wearedevelopers.com/jobs/ext/1768206-principal-cybersecurity-architect-identity-iam-zero-trust). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cybersecurity Architect - Identity, IAM & Zero Trust - **Company:** World Wide Technology - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $150,400.0 - $188,000.0 - **Contract:** Permanent contract - **Skills:** Access Network, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Business Software, Software as a Service, Cyber Security, Identity and Access Management, Key Management, Microsoft Software, OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Azure Active Directory, Phishing, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Google Cloud, Okta, Cyberark, Software Security, Mitre Att&ck, Togaf, Hashicorp, SailPoint - **Published:** July 8, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9019930/principal-cybersecurity-architect-identity-iam-zero-trust ## About the Role * 8+ years in information security, with 4+ years in an architecture or senior engineering role * Deep expertise in Zero Trust frameworks (NIST SP 800-207, BeyondCorp) and identity-centric security * Strong understanding of threat modeling methodologies (STRIDE, PASTA, ATT&CK) * Hands-on experience with enterprise IAM platforms - Microsoft Entra ID, Okta, Ping Identity, or equivalent * Strong grasp of federation protocols: SAML 2.0, OIDC, OAuth 2.0, SCIM * Experience with PAM platforms (CyberArk, BeyondTrust, Delinea) and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) * Familiarity with CIEM tooling and cloud IAM governance across at least two major cloud platforms * Experience designing and governing identity lifecycle and IGA processes (SailPoint, Saviynt, or equivalent a plus) * Strong understanding of threat modelling methodologies (STRIDE, ATT&CK) and their application to identity attack surfaces * Excellent communication skills - able to translate complex architecture into clear guidance for engineers, business stakeholders, and executives * Provan experience using diplomacy skills * Certifications (preferred):CISSP, SABSA, TOGAF, Microsoft SC-100, Okta Certified Architect, or equivalent ## Description * Partner with IT, infrastructure, and business stakeholders to integrate security into technology decisions * Mentor and guide security engineers on architecture standards and design decisions Zero Trust Architecture * Design and mature a Zero Trust architecture (ZTNA, MFA, PAM) spanning identity, device trust, network access, and application security - grounded in NIST SP 800-207 and BeyondCorp principles. * Define reference architectures, security patterns, and guardrails consumed across engineering and infrastructure teams * Lead threat modeling and security architecture reviews for major platform changes and initiatives * Evaluate and select security tooling (SASE, SSE, ZTNA, NDR, EDR) aligned to the overall architecture strategy * Drive continuous improvement of Zero Trust posture through gap assessments and maturity modelling Identity & Access Management (IAM) * Own the enterprise IAM architecture - covering workforce identity, B2B federation, machine identities, and cloud entitlements * Design and govern identity lifecycle management: provisioning, role assignment, access reviews, and deprovisioning - ensuring least privilege is enforced by default and not by exception * Architect federation and SSO standards across the enterprise: SAML 2.0, OIDC, OAuth 2.0 - including integrations with third-party SaaS, partner tenants, and customer-facing portals * Define authentication assurance levels by resource sensitivity, aligning MFA requirements to NIST AAL2/AAL3 - with a clear roadmap toward phishing-resistant MFA (FIDO2/WebAuthn) for privileged and high-risk access * Lead the PAM architecture - credential vaulting, just-in-time privilege, session recording, and endpoint privilege management - in partnership with the security operations team * Govern cloud entitlements across AWS, Azure, and GCP through a CIEM framework: identify over-permissioned roles, enforce least privilege for service principals and IAM roles, and manage cross-account trust relationships * Establish and maintain a non-human identity strategy: service accounts, API keys, application credentials, and pipeline secrets - eliminating hardcoded credentials and enforcing dynamic secrets via a secrets management platform * Drive identity governance processes: access certification campaigns, segregation of duties (SoD) controls, and role-based access control (RBAC) model design * Partner with HR, IT, and business application owners to ensure joiner/mover/leaver processes are automated and auditable Governance & Stakeholder Engagement * Define security architecture standards, policies, and exception management processes * Mentor security engineers and serve as the escalation point for complex identity and access design decisions * Produce architecture artefacts - threat models, data flow diagrams, trust zone maps - suitable for both technical and executive audiences * Contribute to the security roadmap and annual planning, translating risk priorities into architectural investments, We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for All! ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)