> Markdown version of [/jobs/ext/1984920-cybersecurity-iam-architect-staff-engineer](https://www.wearedevelopers.com/jobs/ext/1984920-cybersecurity-iam-architect-staff-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity IAM Architect - Staff Engineer - **Company:** Onemain Holdings, Inc. - **Location:** Baltimore, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software as a Service, Cloud Computing, Cyber Security, Identity and Access Management, Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Policy as Code, Enterprise Software Applications, Okta, Large Language Models, Software Security, Virtual Agents, Devsecops - **Published:** August 8, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/cybersecurity-iam-architect-staff-engineer-baltimore-md-usa-58853937 ## About the Role with governance, security reviews, and risk mitigation for IAM tech and AI agent identities * Collaborate with engineering, cloud, infrastructure, and AI teams to ensure secure deployment * Provide secure-by-design guidance throughout the system development lifecycle * Participate in governance boards and maintain IAM standards and policies * Mentor junior architects and communicate complex concepts to leadership Tasks * 7-10 years in cybersecurity with 3+ years in IAM/security architecture or related role * Deep working knowledge of NIST CSF, SP 800-53, SP 800-171, and SP 800-207 * Experience designing IAM architectures for enterprise systems, cloud, SaaS, APIs, and hybrid environments * Strong understanding of IAM domains: identity lifecycle, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties * Hands-on familiarity with Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies * aa aaK_ understanding of LLMs, AI/GenAI, agent identity governance, and auditability of agent actions * Experience in regulated environments aligning identity controls to compliance frameworks * Excellent communication, collaboration, and executive-facing presentation skills * Preferred certifications (CISSP, CISM, CISA, CCSP) and experience with policy-as-code and DevSecOps Key requirements * ## Description Experteer Overview As an IAM Architect, you will design enterprise-wide identity security architectures aligned to NIST standards and Zero Trust principles. You will translate business and regulatory needs into secure blueprints and reusable patterns, guiding cross-functional teams through secure-by-design implementation. You'll lead architecture reviews, identify identity-related gaps, and drive governance and risk-mitigation across cloud, on-premises, SaaS, and hybrid environments. This role offers impact at scale, shaping secure identity for critical enterprise systems and AI-enabled services. Compensation / Benefits * Design and review enterprise IAM architectures across cloud, on-premises, SaaS, and hybrid environments * Develop secure design patterns for human and non-human identities and API access * Translate requirements into blueprints, reference architectures, and reusable identity patterns * Establish least-privilege models (RBAC, ABAC, PBAC) with context-aware controls * Drive governance, security reviews, and risk mitigation for IAM tech and AI agent identities * Collaborate with engineering, cloud, infrastructure, and AI teams to ensure secure deployment * Provide secure-by-design guidance throughout the system development lifecycle * Participate in governance boards and maintain IAM standards and policies * Mentor junior architects and communicate complex concepts to leadership Tasks * 7-10 years in cybersecurity with 3+ years in IAM/security architecture or related role * Deep working knowledge of NIST CSF, SP 800-53, SP 800-171, and SP 800-207 * Experience designing IAM architectures for enterprise systems, cloud, SaaS, APIs, and hybrid environments * Strong understanding of IAM domains: identity lifecycle, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties * Hands-on familiarity with Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies * Strong understanding of LLMs, AI/GenAI, agent identity governance, and auditability of agent actions * Experience in regulated environments aligning identity controls to compliance frameworks * Excellent communication, collaboration, and executive-facing presentation skills * Preferred certifications (CISSP, CISM, CISA, CCSP) and experience with policy-as-code and DevSecOps Key requirements * ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Headless by Design: Building Enterprise Systems That Agents Can Actually Use](https://www.wearedevelopers.com/videos/100092-headless-by-design-building-enterprise-systems-that-agents-can-actually-use) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [The Private AI Platform: Why Agentic Apps Need a Private Application Platform](https://www.wearedevelopers.com/videos/100162-the-private-ai-platform-why-agentic-apps-need-a-private-application-platform) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)