> Markdown version of [/jobs/ext/1991165-iam-architect](https://www.wearedevelopers.com/jobs/ext/1991165-iam-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Architect - **Company:** Galaxy i Technologies, Inc - **Location:** Alpharetta, GA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Active Directory, Amazon Web Services, Audit Trail, User Authentication, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Identity and Access Management, Information Technology Operations, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Salesforce.Com, Security Assertion Markup Language (SAML), SAP (Applications), Security Information and Event Management, Scripting, Google Cloud, Enterprise Software Applications, Okta, Cyberark, IT Architecture, Software Security, SailPoint, Splunk, Workday - **Published:** August 8, 2026 - **Apply:** https://www.dice.com/job-detail/f619dabb-bf36-4c4a-bdfe-0e9afcb72c86 ## About the Role SSO, MFA, Federation protocols (SAML, OAuth 2.0, OpenID Connect) Identity lifecycle management Hands-on experience with IAM tools: Azure AD / Entra ID, Okta, SailPoint, Ping, CyberArk Strong understanding of: Active Directory / LDAP Cloud security (AWS IAM, Azure RBAC) API security Scripting/programming: PowerShell, Python, Java, or similar Skills: Cyber Security - IAM ProfessionaServices~l Cyber Ark Experience Required: 10 & Above ## Description An IAM Architect is responsible for designing, implementing, and governing identity and access management solutions that ensure secure access to enterprise systems, applications, and data. This role bridges business requirements, cybersecurity, and IT architecture to enforce robust identity governance and compliance. Key Responsibilities 1. Architecture & Design Design and develop enterprise IAM architecture aligned with security and business goals Define identity lifecycle management (joiner, mover, leaver processes) Architect solutions for: Authentication (SSO, MFA, passwordless) Authorization (RBAC, ABAC) Federation (SAML, OAuth, OIDC) Develop zero trust security models for identity 2. Implementation & Integration Lead implementation of IAM platforms such as: Azure AD / Entra ID Okta SailPoint CyberArk Ping Identity Integrate IAM systems with: Cloud platforms (AWS, Azure, Google Cloud Platform) On-prem systems (Active Directory, LDAP) Enterprise applications (SAP, Salesforce, Workday) Enable API security and identity federation 3. Governance, Risk & Compliance Establish Identity Governance & Administration (IGA) frameworks Design role models and access certification campaigns Ensure compliance with standards: SOX, GDPR, HIPAA, ISO 27001 Implement audit logging, monitoring, and reporting 4. Security & Risk Management Enforce least privilege & segregation of duties (SoD) Design solutions to mitigate identity-based threats Integrate IAM with: SIEM (e.g., Splunk, Sentinel) PAM (Privileged Access Management) Conduct risk assessments and threat modeling 5. Strategy & Roadmap Define IAM strategy and technology roadmap Evaluate and recommend IAM tools and platforms Drive cloud identity transformation initiatives Promote adoption of passwordless and Zero Trust frameworks 6. Stakeholder Collaboration Work with: Security teams IT operations Application owners Compliance and audit teams Provide technical leadership and mentorship to IAM engineers Communicate complex IAM concepts to non-technical stakeholders ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity)