> Markdown version of [/jobs/ext/1945439-identity-authentication-and-authorization-architect](https://www.wearedevelopers.com/jobs/ext/1945439-identity-authentication-and-authorization-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity, Authentication and Authorization Architect - **Company:** IAA, Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Amazon Web Services, Application Integration Architecture, Audit Trail, User Authentication, Microsoft Azure, Bash Shell, Client Server Models, Cloud Computing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Continuous Integration, Data Security, Desktop Virtualization, Domain Name System (DNS), Multi-Factor Authentication, Identity and Access Management, IT Management, Virtual Private Networks (VPN), Mobile Application Software, Kerberos (Protocol), Key Management, Lightweight Directory Access Protocols (LDAP), Massachusetts Comprehensive Assessment Systems, Network Segmentation, OAuth, OpenID, Open Web Application Security, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Cloud Services, Kusto Query Language, Zero Trust Network Access, Security Assertion Markup Language (SAML), Systems Architecture, Transport Layer Security, Cloud Platform System, Okta, Office365, ReactJS, Istio, Software Security, Azure Powershell, Firewalls (Computer Science), Pingfederate, Kubernetes, Information Technology, Front End Software Development, Terraform, Api Management, Docker, Vulnerability Analysis, Microservices - **Published:** August 6, 2026 - **Apply:** https://www.dice.com/job-detail/0237d1a1-096b-46e5-bc20-dc7ca6558536 ## About the Role Understanding and application of threat modeling concepts and methodologies. Displays a balanced, cross-functional perspective under information security, liaising with other towers and business to help improve Security centric designs. In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, M365, AWS Security. Knowledge on Okta, PingFederate, Entitlement Management solutions. In-depth knowledge of various cybersecurity frameworks, standards, and identity governance and administration. Strong knowledge on Identity management on Azure AD with OAuth, OIDC, SAML SSO, MFA, Conditional Access policies, MFA, Kerberos, LDAP, Identity Federations etc. Experience in providing security solutions for Java based Microservices, React based frontends and Android/iOS based mobile applications on Azure. Hands-on experience in JWT, session handling, Code Signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc. Exposure to API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc. Deeper understanding of Application security, OWASP standards, security best practices, browser compatibilities/storage/cookies. Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, Privileged Access Management etc. Authentication/Authorization/Auditing/Accounting frameworks and hands-on experience, Privileged Identity/Access Management on the cloud. Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc. Understanding of IaC, CI/CD pipeline, automation, and vulnerability scanning tools, Terraform, PowerShell, Bash script, Azure CLI. Very good understanding of concepts related to Docker Security, container orchestrations/Kubernetes, mTLS, Dapr, Service Mesh and security scenarios., Bachelor's degree in Computer Science or a related discipline and experience in information security, or an equivalent combination of education and work experience. Deep knowledge of application or infrastructure systems architecture, usually having experience with multiple system technologies. Excellent consultative and communication skills, and the ability to work effectively with clients, partners, and IT management and staff. Fifteen years of experience in the Information Security role. Seven years of experience as an IAM Architect. CISSP, CSSP, or Cloud Security certification preferred. Certifications on Azure, AWS Security will be preferred. Strong collaboration skills and analytical ability. ## Description We are seeking a highly skilled Identity, Authentication and Authorization Architect (IAA) with deep expertise in various security products, authentication, authorization, access management, governance, controls, regulatory requirements and agentic identities etc. As a key member of Workforce Identity, Authentication and Authorization (IAA), you will play a vital role in ensuring the secure and compliant implementation of various solutions (Hybrid and Cloud). Requirements/Responsibilities Design identity centric Workforce Security solutions to ensure secure and efficient authentication and access management aligned with the industry frameworks and standards (NIST CSF, COBIT, OC, GDPR etc). Well versed with agentic architectures and identity concerns. Guides the architectural development of identity solutions, access patterns, modern protocols practicing Zero Trust, least privilege, defense in depth principles. Review and provide feedback on Identity, Authentication and Access Management related security solutions proposed by stakeholders and can provide consultation to the partners and IT management. Acts as cybersecurity expert to participate in solutions from IAA perspective spanning end-user computing, proxy solutions, MFA, SSO, conditional access, device based authentication, VPN solutions, Desktop virtualization solutions, Passwordless, YubiKey, MDM, governance scenarios, network segmentation, Secrets Management, Certificates Management, Automation, role based access control, Privileged Identity Management, end user computing, Just in Time access, data protection solutions etc. Thoroughly understand and provides solutions considering Security technology choices, such as design, protocols support, secrets management, data security, client server communication, identity management, credential vaulting, OIDC/OAuth based authorization patterns, identity segregation, cloud architectures, cryptography, cloud native services, static security etc. Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure continuous improvement in Security Posture by providing consultations to application teams. Design target architectures and roadmaps considering IAM security control frameworks and audit requirements. Awareness of Cyber Security Risk management principles and frameworks, supply chain risk and third party risk assessment controls. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)