Network Security Architect

OpenKyber LLC
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Apple Mac Systems Authentication Protocols Microsoft Azure Cyber Security Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management Network Security Lightweight Directory Access Protocols (LDAP) OAuth
+8 more
Role-Based Access Control Openid Connect Zero Trust Network Access Security Assertion Markup Language (SAML) Reliability of Systems Togaf Information Technology Cloud Migration

Job description

Job Overview: Architect and modernize Active Directory environments including forests, domains, trusts, DNS, and group policy structures. Define security standards, privileged access models, and administration frameworks. Lead directory services consolidation, migration, and upgrade initiatives. Design federation architectures and integrate applications using modern authentication protocols. Transition legacy authentication systems to cloud native identity solutions. Architect and optimize identity platforms including tenant design, lifecycle management, and access governance. Define and implement identity protection, conditional access, and privileged identity strategies. Design enterprise endpoint management strategies across Windows, macOS, and other platforms. Implement device compliance, encryption, patching, and configuration baselines. Integrate endpoint posture with Zero Trust and identity driven security controls. Define enterprise identity and access management architecture and roadmap. Enforce authentication and authorization models including RBAC, ABAC, and multi factor authentication. Produce architecture documentation, standards, and design guidelines. Provide technical leadership and support incident resolution and root cause analysis. Collaborate with cross functional teams to deliver integrated security solutions.

Requirements

Requirements/Must Have: Deep expertise in Active Directory, federation services, and cloud identity platforms. Strong knowledge of identity and access management concepts including SSO, MFA, and access governance. Hands on experience with endpoint management tools and device compliance frameworks. Strong understanding of authentication protocols such as SAML, OAuth, OpenID Connect, and LDAP. Experience designing enterprise scale identity and endpoint architectures. Experience with cloud transformation and Zero Trust security models. Strong analytical, problem solving, and communication skills.

Experience: 8 to 12 plus years of experience in identity, directory services, or security architecture roles.

Responsibilities: Lead identity and endpoint architecture initiatives across the organization. Define and enforce security and governance standards. Review and approve solution designs for application integrations. Support incident management and ensure system resilience. Drive continuous improvement in identity and endpoint security practices.

Skills: Identity and access management. Endpoint security and device management. Cloud identity and federation. Zero Trust architecture. Security governance and compliance. Technical leadership and collaboration.

Qualification And Education: Bachelor s degree in Computer Science, Information Technology, or related field. Certifications such as CISSP, CISM, Azure Identity, TOGAF, or ITIL are preferred. Experience with privileged access management, identity governance, or customer identity platforms is preferred.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all