> Markdown version of [/jobs/ext/1975570-telecommute-principal-cybersecurity-architect-identify-iam-zero-trus](https://www.wearedevelopers.com/jobs/ext/1975570-telecommute-principal-cybersecurity-architect-identify-iam-zero-trus). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TELECOMMUTE Principal Cybersecurity Architect Identify, IAM & Zero Trus - **Company:** Ecco - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Access Network, Amazon Web Services, Microsoft Azure, Business Software, Software as a Service, Cloud Computing, Cyber Security, Identity and Access Management, Key Management, Microsoft Software, OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Azure Active Directory, Phishing, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Single Sign-On, Google Cloud, Okta, Cyberark, Software Security, Mitre Att&ck, Togaf, Information Technology, Hashicorp, SailPoint - **Published:** August 7, 2026 - **Apply:** https://www.dice.com/job-detail/27fd9096-2bdc-4af1-ade0-a56fb4efacbe ## About the Role * At least 8 years of experience in information security, with a minimum of 4 years in an architecture or senior engineering capacity. * Deep, hands-on expertise in Zero Trust security frameworks (NIST SP 800-207, BeyondCorp) and identity-centric security architectures. * Expertise in threat modeling methodologies (such as STRIDE, PASTA, or MITRE ATT&CK), with the ability to apply them to identity and authorization attack surfaces. * Practical, hands-on experience administering and architecting enterprise IAM platforms (Microsoft Entra ID, Okta, Ping Identity, or similar). * Proficient in federation and SSO protocols including SAML 2.0, OIDC, OAuth 2.0, and SCIM. * Experience with PAM solutions (CyberArk, BeyondTrust, Delinea) and modern secrets management platforms (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault). * Experience with Cloud Infrastructure Entitlements Management (CIEM) tools and governance of cloud IAM on at least two leading cloud providers (AWS, Azure, Google Cloud Platform). * Knowledge and hands-on experience designing and governing identity lifecycle management and Identity Governance & Administration (IGA) processes (SailPoint, Saviynt, or similar is a plus). * Strong understanding and experience designing processes for access governance, access reviews, RBAC model design, and SoD controls. * Excellent verbal and written communication skills, with the ability to translate sophisticated technical concepts into clear and actionable guidance for technical teams, business stakeholders, and executives. * Demonstrated ability to use diplomacy and influence to drive consensus and decision-making across diverse technical and business teams. Qualifications: * Bachelor's degree in Computer Science, Information Security, or a related field preferred; advanced degree is a plus. * Professional certifications such as CISSP, SABSA, TOGAF, Microsoft SC-100, Okta Certified Architect, or similar are highly desirable. ## Description As the Principal Cybersecurity Architect specializing in Identity, Access Management (IAM), and Zero Trust, you will serve as a senior individual contributor responsible for shaping and governing the enterprise-wide security architecture. You will guide major architectural decisions on how people, machines, and workloads authenticate, authorize, and access resources across a complex technology landscape., * Partnering with IT, infrastructure, and business teams to integrate security into all technology decision-making processes. * Mentoring and guiding security engineers on architectural standards and decision-making. * Leading the design and evolution of Zero Trust architectures, including ZTNA, MFA, and PAM, across identity, device trust, network access, and application security, with principles grounded in NIST SP 800-207 and BeyondCorp. * Defining, maintaining, and communicating reference architectures, security design patterns, and guardrails for engineering and infrastructure teams. * Conducting threat modeling and security architecture reviews for all major technology projects and platform changes. * Evaluating and selecting security tooling (such as SASE, SSE, ZTNA, NDR, and EDR) aligned with the organization's security strategy. * Performing gap assessments and driving continuous improvement of Zero Trust maturity across the enterprise. * Owning the IAM architecture for the enterprise, spanning workforce identity, B2B federations, machine identities, and cloud entitlements. * Designing robust identity lifecycle management processes (provisioning, access reviews, deprovisioning) that enforce least privilege by default. * Architecting standards for federation and Single Sign-On (SSO) protocols (SAML 2.0, OIDC, OAuth 2.0) and integrating them with third-party SaaS, partner, and customer applications. * Defining authentication assurance levels by resource sensitivity, implementing MFA aligned to NIST AAL2/AAL3, and creating a roadmap for phishing-resistant MFA (FIDO2/WebAuthn) for privileged access. * Leading the architecture of Privileged Access Management (PAM) solutions, including credential vaulting, just-in-time privilege, session recording, and endpoint privilege management, in collaboration with Security Operations. * Governing cloud entitlements on platforms such as AWS, Azure, and Google Cloud Platform using a CIEM framework and enforcing least privilege access. * Establishing and maintaining non-human identity strategies (service accounts, keys, application credentials), eliminating hard-coded credentials, and enforcing dynamic secrets management. * Driving identity governance processes including access certification, segregation of duties (SoD), and role-based access control (RBAC) model design. * Working closely with HR, IT, and business application owners to automate and ensure auditable joiner/mover/leaver processes. * Defining security architecture standards, policies, and exception management processes. * Serving as an escalation point for complex identity and access design decisions and mentoring security engineering teams. * Producing architectural artifacts-such as threat models, data flow diagrams, and trust zone maps-for both technical and executive audiences. * Contributing to the broader security roadmap, annual planning, and translating risk priorities into strategic architectural investments. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)