Information Security Solution Architect - Identity & Access Management

Allianz Group
Madrid, Spain
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Artificial Intelligence User Authentication Authentication Protocols Cyber Security Federated Identity Management Identity and Access Management OAuth Ping (Networking Utility) Role-Based Access Control Azure Active Directory Elearning Zero Trust Network Access
+4 more
Security Assertion Markup Language (SAML) Okta Generative AI Information Technology

Job description

130 years of trust, time to shape what’s next.Allianz Group is one of the world’s leading insurers and asset managers - built on over a century of stability, expertise, and financial strength.Allianz Services is where that legacy meets the future.8,200+ people.Eight countries.Three continents.We deliver specialized services to clients within Allianz Group, powered by AI, advanced analytics, and a mindset that refuses to stand still.From core insurance operations to engineering and consulting services, we reimagine how insurance works.What truly sets us apart are our people and the trusted partnerships we build, anchored in our values of expertise, integrity, and empowerment.We don’t support the business.We shape it.Role Overview We are looking for an experienced IS Solution Architect - Identity & Access Management Security to drive the design, governance, and evolution of enterprise IAM architectures.The role combines deep technical expertise in identity lifecycle management, privileged access, and access governance with strong security governance capabilities - ensuring robust identity controls, Zero Trust adoption, and regulatory compliance across complex, multi-geography environments.What You Do Design and maintain enterprise IAM architectures: identity lifecycle management, access governance, authentication/authorization frameworks, directory services, and Privileged Access Management (PAM) - aligned with Zero Trust Identity principles including least privilege, continuous verification, and adaptive authentication.Provide architectural guidance on enterprise IAM platforms (Microsoft Entra ID, Sail Point, Cyber Ark, Okta, Ping Identity, Forge Rock) and modern authentication protocols (SAML, OAuth 2.0, Open ID Connect, FIDO2/passkeys), ensuring secure identity federation and SSO across the enterprise.Draft, review, and maintain identity security policies, access governance standards, and technical baselines; support formal governance processes for IAM architecture decisions, access exception approvals, privilege escalation sign-off workflows, and time-bound access derogations.Define and track KPIs/KRIs for IAM posture (privileged account coverage, MFA adoption rates, orphaned account metrics, access certification completion rates) and present governance reporting to security committees and senior leadership.Contribute to or lead IAM design authority and architecture review board (ARB) processes - ensuring IAM security requirements are embedded at design phase across infrastructure, application, and cloud projects; act as identity security advisor to IT and business teams.What You Bring Higher education degree in Information Security, Computer Science, Engineering, or related technical field.5+ years of experience in Identity & Access Management Architecture or IAM Engineering in enterprise environments.Hands?on experience designing and implementing enterprise IAM architectures: identity lifecycle management, access governance, authentication/authorization frameworks, and directory services.Strong understanding of Zero Trust Identity principles: least privilege, continuous verification, conditional access, and adaptive authentication.Experience with enterprise IAM platforms (Microsoft Entra ID, Sail Point, Cyber Ark, Okta, Ping Identity, Forge Rock, One Identity) and Privileged Access Management (PAM) strategy, implementation, and operational governance.Knowledge of identity federation, SSO, and modern authentication protocols: SAML, OAuth 2.0, Open ID Connect, FIDO2/passkeys, and certificate-based authentication.Experience with access governance: RBAC, ABAC, access reviews, and segregation of duties (So D).Familiarity with DORA, NIS2, ISO **, NIST CSF, and GDPR (data access controls).Excellent English skills (written and spoken).We highly welcome candidates with a genuine interest and affinity for Information Technology (IT) and Generative Artificial Intelligence (Gen AI), as these attributes are considered valuable assets to our team.What We Offer We offer a hybrid work model which recognizes the value of striking a balance between in-person collaboration and remote working incl.up to 25 days per year working from abroad We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location) From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered Flexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach About Allianz Allianz Group is one of the most trusted insurance and asset management companies in the world.Caring for our employees, their ambitions, dreams and challenges is what makes us a unique employer.We are united by a shared commitment: to put our customers first and at the center of everything we do.Their needs inspire our thinking and guide our actions.Together, we can build an environment where everyone feels empowered and confident to explore, grow and shape a better future - for our customers and for the world around us.At Allianz, we stand for unity: we believe that a united world is a more prosperous world, and we are dedicated to consistently advocating for equal opportunities for all.The foundation for this is our inclusive workplace, where people and performance both matter, and where integrity, fairness, inclusion and trust are at the heart of our culture.We therefore welcome applications regardless of ethnicity or cultural Internal background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations.Join us.Let’s care for tomorrow.#J-**-Ljbffr

Requirements

What You Bring Higher education degree in Information Security, Computer Science, Engineering, or related technical field. 5+ years of experience in Identity & Access Management Architecture or IAM Engineering in enterprise environments. Hands?on experience designing and implementing enterprise IAM architectures: identity lifecycle management, access governance, authentication/authorization frameworks, and directory services. Strong understanding of Zero Trust Identity principles: least privilege, continuous verification, conditional access, and adaptive authentication. Experience with enterprise IAM platforms (Microsoft Entra ID, Sail Point, Cyber Ark, Okta, Ping Identity, Forge Rock, One Identity) and Privileged Access Management (PAM) strategy, implementation, and operational governance. Knowledge of identity federation, SSO, and modern authentication protocols: SAML, OAuth 2.0, Open ID Connect, FIDO2/passkeys, and certificate-based authentication. Experience with access governance: RBAC, ABAC, access reviews, and segregation of duties (So D). Familiarity with DORA, NIS2, ISO *****, NIST CSF, and GDPR (data access controls). Excellent English skills (written and spoken).

About the company

Allianz Group is one of the world’s leading insurers and asset managers - built on over a century of stability, expertise, and financial strength. Allianz Services is where that legacy meets the future. 8,200+ people. Eight countries. Three continents. We deliver specialized services to clients within Allianz Group, powered by AI, advanced analytics, and a mindset that refuses to stand still. From core insurance operations to engineering and consulting services, we reimagine how insurance works. What truly sets us apart are our people and the trusted partnerships we build, anchored in our values of expertise, integrity, and empowerment. We don’t support the business. We shape it., up to 25 days per year working from abroad We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location) From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered Flexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach About Allianz Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges is what makes us a unique employer. We are united by a shared commitment: to put our customers first and at the center of everything we do. Their needs inspire our thinking and guide our actions. Together, we can build an environment where everyone feels empowered and confident to explore, grow and shape a better future - for our customers and for the world around us. At Allianz, we stand for unity: we believe that a united world is a more prosperous world, and we are dedicated to consistently advocating for equal opportunities for all. The foundation for this is our inclusive workplace, where people and performance both matter, and where integrity, fairness, inclusion and trust are at the heart of our culture. We therefore welcome applications regardless of ethnicity or cultural Internal background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations. Join us. Let’s care for tomorrow. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

4:27 min

Centralizing access with open source identity management providers

Den Prysukhin · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all