> Markdown version of [/jobs/ext/202659-network-security-architect](https://www.wearedevelopers.com/jobs/ext/202659-network-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security Architect - **Company:** OpenKyber LLC - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Apple Mac Systems, Authentication Protocols, Microsoft Azure, Cyber Security, Domain Name System (DNS), Multi-Factor Authentication, Identity and Access Management, Network Security, Lightweight Directory Access Protocols (LDAP), OAuth, Role-Based Access Control, Openid Connect, Zero Trust Network Access, Security Assertion Markup Language (SAML), Reliability of Systems, Togaf, Information Technology, Cloud Migration - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=98377eb4ee64e5dd ## About the Role Requirements/Must Have: Deep expertise in Active Directory, federation services, and cloud identity platforms. Strong knowledge of identity and access management concepts including SSO, MFA, and access governance. Hands on experience with endpoint management tools and device compliance frameworks. Strong understanding of authentication protocols such as SAML, OAuth, OpenID Connect, and LDAP. Experience designing enterprise scale identity and endpoint architectures. Experience with cloud transformation and Zero Trust security models. Strong analytical, problem solving, and communication skills. Experience: 8 to 12 plus years of experience in identity, directory services, or security architecture roles. Responsibilities: Lead identity and endpoint architecture initiatives across the organization. Define and enforce security and governance standards. Review and approve solution designs for application integrations. Support incident management and ensure system resilience. Drive continuous improvement in identity and endpoint security practices. Skills: Identity and access management. Endpoint security and device management. Cloud identity and federation. Zero Trust architecture. Security governance and compliance. Technical leadership and collaboration. Qualification And Education: Bachelor s degree in Computer Science, Information Technology, or related field. Certifications such as CISSP, CISM, Azure Identity, TOGAF, or ITIL are preferred. Experience with privileged access management, identity governance, or customer identity platforms is preferred. ## Description Job Overview: Architect and modernize Active Directory environments including forests, domains, trusts, DNS, and group policy structures. Define security standards, privileged access models, and administration frameworks. Lead directory services consolidation, migration, and upgrade initiatives. Design federation architectures and integrate applications using modern authentication protocols. Transition legacy authentication systems to cloud native identity solutions. Architect and optimize identity platforms including tenant design, lifecycle management, and access governance. Define and implement identity protection, conditional access, and privileged identity strategies. Design enterprise endpoint management strategies across Windows, macOS, and other platforms. Implement device compliance, encryption, patching, and configuration baselines. Integrate endpoint posture with Zero Trust and identity driven security controls. Define enterprise identity and access management architecture and roadmap. Enforce authentication and authorization models including RBAC, ABAC, and multi factor authentication. Produce architecture documentation, standards, and design guidelines. Provide technical leadership and support incident resolution and root cause analysis. Collaborate with cross functional teams to deliver integrated security solutions. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)