Cybersecurity IAM Architect - Staff Engineer

Onemain Holdings, Inc.
Baltimore, MD, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Software as a Service Cloud Computing Cyber Security Identity and Access Management Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) OAuth OpenID Role-Based Access Control Azure Active Directory
+9 more
Zero Trust Network Access Security Assertion Markup Language (SAML) Policy as Code Enterprise Software Applications Okta Large Language Models Software Security Virtual Agents Devsecops

Job description

Experteer Overview As an IAM Architect, you will design enterprise-wide identity security architectures aligned to NIST standards and Zero Trust principles. You will translate business and regulatory needs into secure blueprints and reusable patterns, guiding cross-functional teams through secure-by-design implementation. You’ll lead architecture reviews, identify identity-related gaps, and drive governance and risk-mitigation across cloud, on-premises, SaaS, and hybrid environments. This role offers impact at scale, shaping secure identity for critical enterprise systems and AI-enabled services. Compensation / Benefits * Design and review enterprise IAM architectures across cloud, on-premises, SaaS, and hybrid environments * Develop secure design patterns for human and non-human identities and API access * Translate requirements into blueprints, reference architectures, and reusable identity patterns * Establish least-privilege models (RBAC, ABAC, PBAC) with context-aware controls * Drive governance, security reviews, and risk mitigation for IAM tech and AI agent identities * Collaborate with engineering, cloud, infrastructure, and AI teams to ensure secure deployment * Provide secure-by-design guidance throughout the system development lifecycle * Participate in governance boards and maintain IAM standards and policies * Mentor junior architects and communicate complex concepts to leadership Tasks * 7-10 years in cybersecurity with 3+ years in IAM/security architecture or related role * Deep working knowledge of NIST CSF, SP 800-53, SP 800-171, and SP 800-207 * Experience designing IAM architectures for enterprise systems, cloud, SaaS, APIs, and hybrid environments * Strong understanding of IAM domains: identity lifecycle, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties * Hands-on familiarity with Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies * Strong understanding of LLMs, AI/GenAI, agent identity governance, and auditability of agent actions * Experience in regulated environments aligning identity controls to compliance frameworks * Excellent communication, collaboration, and executive-facing presentation skills * Preferred certifications (CISSP, CISM, CISA, CCSP) and experience with policy-as-code and DevSecOps Key requirements *

Requirements

with governance, security reviews, and risk mitigation for IAM tech and AI agent identities * Collaborate with engineering, cloud, infrastructure, and AI teams to ensure secure deployment * Provide secure-by-design guidance throughout the system development lifecycle * Participate in governance boards and maintain IAM standards and policies * Mentor junior architects and communicate complex concepts to leadership Tasks * 7-10 years in cybersecurity with 3+ years in IAM/security architecture or related role * Deep working knowledge of NIST CSF, SP 800-53, SP 800-171, and SP 800-207 * Experience designing IAM architectures for enterprise systems, cloud, SaaS, APIs, and hybrid environments * Strong understanding of IAM domains: identity lifecycle, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties * Hands-on familiarity with Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies * aa aaK_ understanding of LLMs, AI/GenAI, agent identity governance, and auditability of agent actions * Experience in regulated environments aligning identity controls to compliance frameworks * Excellent communication, collaboration, and executive-facing presentation skills * Preferred certifications (CISSP, CISM, CISA, CCSP) and experience with policy-as-code and DevSecOps Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all