Identity, Authentication and Authorization Architect

IAA, Inc.
New York, NY, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Amazon Web Services Application Integration Architecture Audit Trail User Authentication Microsoft Azure Bash Shell Client Server Models Cloud Computing Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Cyber Security
+43 more
Continuous Integration Data Security Desktop Virtualization Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management IT Management Virtual Private Networks (VPN) Mobile Application Software Kerberos (Protocol) Key Management Lightweight Directory Access Protocols (LDAP) Massachusetts Comprehensive Assessment Systems Network Segmentation OAuth OpenID Open Web Application Security Windows PowerShell Role-Based Access Control Azure Active Directory Cloud Services Kusto Query Language Zero Trust Network Access Security Assertion Markup Language (SAML) Systems Architecture Transport Layer Security Cloud Platform System Okta Office365 ReactJS Istio Software Security Azure Powershell Firewalls (Computer Science) Pingfederate Kubernetes Information Technology Front End Software Development Terraform Api Management Docker Vulnerability Analysis Microservices

Job description

We are seeking a highly skilled Identity, Authentication and Authorization Architect (IAA) with deep expertise in various security products, authentication, authorization, access management, governance, controls, regulatory requirements and agentic identities etc. As a key member of Workforce Identity, Authentication and Authorization (IAA), you will play a vital role in ensuring the secure and compliant implementation of various solutions (Hybrid and Cloud). Requirements/Responsibilities Design identity centric Workforce Security solutions to ensure secure and efficient authentication and access management aligned with the industry frameworks and standards (NIST CSF, COBIT, OC, GDPR etc). Well versed with agentic architectures and identity concerns. Guides the architectural development of identity solutions, access patterns, modern protocols practicing Zero Trust, least privilege, defense in depth principles. Review and provide feedback on Identity, Authentication and Access Management related security solutions proposed by stakeholders and can provide consultation to the partners and IT management. Acts as cybersecurity expert to participate in solutions from IAA perspective spanning end-user computing, proxy solutions, MFA, SSO, conditional access, device based authentication, VPN solutions, Desktop virtualization solutions, Passwordless, YubiKey, MDM, governance scenarios, network segmentation, Secrets Management, Certificates Management, Automation, role based access control, Privileged Identity Management, end user computing, Just in Time access, data protection solutions etc. Thoroughly understand and provides solutions considering Security technology choices, such as design, protocols support, secrets management, data security, client server communication, identity management, credential vaulting, OIDC/OAuth based authorization patterns, identity segregation, cloud architectures, cryptography, cloud native services, static security etc. Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure continuous improvement in Security Posture by providing consultations to application teams. Design target architectures and roadmaps considering IAM security control frameworks and audit requirements. Awareness of Cyber Security Risk management principles and frameworks, supply chain risk and third party risk assessment controls.

Requirements

Understanding and application of threat modeling concepts and methodologies. Displays a balanced, cross-functional perspective under information security, liaising with other towers and business to help improve Security centric designs. In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, M365, AWS Security. Knowledge on Okta, PingFederate, Entitlement Management solutions. In-depth knowledge of various cybersecurity frameworks, standards, and identity governance and administration. Strong knowledge on Identity management on Azure AD with OAuth, OIDC, SAML SSO, MFA, Conditional Access policies, MFA, Kerberos, LDAP, Identity Federations etc. Experience in providing security solutions for Java based Microservices, React based frontends and Android/iOS based mobile applications on Azure. Hands-on experience in JWT, session handling, Code Signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc. Exposure to API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc. Deeper understanding of Application security, OWASP standards, security best practices, browser compatibilities/storage/cookies. Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, Privileged Access Management etc. Authentication/Authorization/Auditing/Accounting frameworks and hands-on experience, Privileged Identity/Access Management on the cloud. Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc. Understanding of IaC, CI/CD pipeline, automation, and vulnerability scanning tools, Terraform, PowerShell, Bash script, Azure CLI. Very good understanding of concepts related to Docker Security, container orchestrations/Kubernetes, mTLS, Dapr, Service Mesh and security scenarios., Bachelor’s degree in Computer Science or a related discipline and experience in information security, or an equivalent combination of education and work experience. Deep knowledge of application or infrastructure systems architecture, usually having experience with multiple system technologies. Excellent consultative and communication skills, and the ability to work effectively with clients, partners, and IT management and staff. Fifteen years of experience in the Information Security role. Seven years of experience as an IAM Architect. CISSP, CSSP, or Cloud Security certification preferred. Certifications on Azure, AWS Security will be preferred. Strong collaboration skills and analytical ability.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all