IAM Architect

Everforth Apex
Charlotte, NC, United States
4 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows User Authentication Cyber Security Federated Identity Management Identity and Access Management Network Service OAuth OpenID Windows PowerShell Azure Active Directory Phishing Zero Trust Network Access
+5 more
Security Assertion Markup Language (SAML) Microsoft Power Automate Graphql SailPoint Terraform

Job description

We are seeking a Cyber Security Architect to contribute to the design and implementation of our identity and access management (IAM) solutions. This role involves collaborating with various technology teams to develop and deploy secure, scalable IAM patterns. The position focuses on enhancing security through modern authentication methods and ensuring robust access controls across the enterprise., * Collaborate with Cyber and Enterprise architecture teams to select and develop appropriate IAM patterns and translate them into engineering designs.

  • Partner with subject matter experts across technology teams, including End User tech and Network services, on IAM design, configuration, and implementation.
  • Work with the Project Management team to identify and estimate technical tasks for program deliverables.
  • Configure Entra ID identity, trust settings, and entitlement management.
  • Implement Conditional Access with phishing-resistant MFA (FIDO2) and risk-based controls.
  • Migrate federated applications and validate authentication flows.
  • Develop and support processes for procuring and managing FIDO2 keys and passkeys, and support Windows Hello for Business rollouts.
  • Enable step-up authentication for sensitive operations and secure privileged access paths.

Requirements

Education: A Bachelor’s Degree is not required for this position., * Identity & Access Management (IAM) Architecture, including designing and implementing enterprise identity patterns and authentication models.

  • Microsoft Entra ID Administration & Engineering, including configuration of tenants, trust relationships, and application integrations.
  • Zero Trust & Conditional Access Design, with experience in implementing risk-based access controls and adaptive security measures.
  • Strong Authentication Technologies such as FIDO2, Passkeys, and Windows Hello for Business (WHfB).
  • Identity Federation & Application Migration, including the ability to migrate federated applications and validate SAML/OIDC/OAuth flows.
  • Privileged Access Management (PAM) & Secure Administration to secure privileged accounts and implement least-privilege models.
  • IAM Program Delivery & Cross-Functional Engineering to collaborate with various teams to deploy IAM solutions at an enterprise scale., * Experience with Identity Governance & Administration (IGA) tools such as SailPoint, Saviynt, or Entra ID Governance.
  • Knowledge of Identity Threat Detection & Incident Response using solutions like Microsoft Defender XDR, Entra Identity Protection, or Sentinel.
  • Experience with Identity Governance Automation using PowerShell, Graph API, Logic Apps, or Terraform.

About the company

Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:52 min

Generating APIs with the Neo4j GraphQL library

William Lyon · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all