> Markdown version of [/jobs/ext/2717725-sr-enterprise-identity-architect](https://www.wearedevelopers.com/jobs/ext/2717725-sr-enterprise-identity-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Enterprise Identity Architect - **Company:** KLA-Tencor - **Location:** Milpitas, CA, United States - **Experience:** Expert - **Salary:** $137,800.0 - $234,300.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon Web Services, Authentication Protocols, Microsoft Azure, Software as a Service, Cloud Computing, Databases, Identity and Access Management, OAuth, OpenID, Ping (Networking Utility), Role-Based Access Control, Azure Active Directory, Cloud Services, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Single Sign-On, Computer Networking Systems, Cloud Platform System, Okta, Multi-Cloud, HR Software, Cloud Migration, Network Server - **Published:** September 4, 2026 - **Apply:** https://kla.wd1.myworkdayjobs.com/Search/job/Milpitas-CA/Sr-Identity-Architect_2634243 ## About the Role * Minimum eight (8) years of proven experience in large enterprise companies. * Minimum five (5) years of proven experience architecting and designing enterprise grade solutions. * Hands on experience in IAM systems like Ping or Okta or Azure EntraID. * Experience working with IGA tools like Sailpiont, Savyint etc., and PIM tools like CyberArc or BeyondTrust etc., * Experience with multi-cloud identity (AWS, GCP). * Experience driving large-scale identity modernization or cloud transformation programs. * Knowledge of regulatory frameworks like SOX, HIPAA, PCI, ISO 27001, or NIST. * Certifications in Identity and Security areas a huge plus. ## Description We are seeking a highly experienced Sr. Enterprise Identity Architect to lead the design and modernization of enterprise identity security across on-prem and cloud environments. This role provides deep technical expertise and strategic direction across Identity & Access Management (IAM), Identity Governance & Administration (IGA), Privileged Identity Management (PIM), Single Sign-On (SSO), Cloud Identity, Active Directory, and Entra ID (Azure AD). As a senior architect, you will define enterprise identity architecture, drive Zero Trust initiatives, and collaborate with cross-functional teams to implement scalable, secure, and compliant identity solutions., * Develop and maintain the enterprise identity architecture blueprint across IAM, IGA, SSO, PIM, and cloud identity services. * Establish identity standards, patterns, and reference architectures for on-premises and cloud environments. * Define and drive Zero Trust identity strategy, modern authentication roadmap, and identity lifecycle transformation. * Assess identity risk posture and recommend controls aligned with business and compliance requirements. * Architect and implement identity lifecycle and governance solutions including role modeling, access certification, and automated provisioning/deprovisioning. * Integrate IGA platforms with HR systems, AD/Entra ID, cloud applications, and SaaS platforms. * Define RBAC/ABAC frameworks and enforce least privilege across the enterprise. * Design and oversee PIM and privileged access architectures including just-in-time access, privileged session management, and secure admin tiering. * Align privileged access models across AD, Entra ID, cloud workloads, servers, databases, and network systems. * Provide architectural oversight for privileged access tools and secure credential management.Architect SSO integrations using SAML, OAuth, OIDC, WS-Fed, and modern authentication protocols. * Define centralized authentication patterns for cloud and on-prem applications. * Implement effective MFA, Conditional Access, and continuous authentication strategies. * Provide architecture direction for Active Directory tiers, domain services, Group Policy structure, and identity security hardening. * Lead hybrid identity design involving Entra ID, AAD Connect, federation, and modern authentication migration. * Optimize identity infrastructure for scalability, resilience, and security. * Architect cloud identity solutions across Azure, multicloud, and SaaS platforms. * Guide modern identity adoption including passwordless, FIDO2, device identity, workload identity, and identity segmentation. * Integrate cloud identity controls into enterprise identity governance and access workflows. * Act as the senior subject matter expert (SME) for identity architecture across security, cloud, application, and infrastructure teams. * Lead evaluation and adoption of new IAM, IGA, SSO, and PIM technologies. * Provide architecture governance, design reviews, and mentorship to engineering teams. * Partner with compliance and risk teams to support audits, certification processes, and regulatory reporting. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Seriously gaming your cloud expertise: from cloud tourist to cloud native](https://www.wearedevelopers.com/videos/373-seriously-gaming-your-cloud-expertise-from-cloud-tourist-to-cloud-native) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)