> Markdown version of [/jobs/ext/2840270-cybersecurity-architect](https://www.wearedevelopers.com/jobs/ext/2840270-cybersecurity-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Architect - **Company:** Open Dealer Exchange - **Location:** Southfield, MI, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Microsoft Azure, Cyber Security, Information Systems, Data Security, Human Resources Information System (HRIS), Identity and Access Management, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Session Management, Microsoft Power Automate, HR Software, Information Technology, SailPoint, Serverless Computing, Workday - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/3589a943-8104-4de0-977a-f6c432cd532f/cybersecurity-architect ## About the Role * 5+ years of hands-on IAM engineering experience, with at least 3 years focused on Entra ID (Azure AD) in enterprise environments. * Deep working knowledge of Active Directory, including group policy, OU design, domain trust models, and hybrid identity patterns. * Demonstrated experience designing and implementing RBAC models at scale in complex or legacy environments. * Hands-on experience with Entra ID Governance, including access reviews, entitlement management, lifecycle workflows, and Privileged Identity Management (PIM). * Strong working knowledge of OAuth 2.0, OIDC, and SAML, sufficient to review developer implementations and identify security risk. * Practical experience automating identity lifecycle events using Logic Apps, Azure Functions, PowerShell, or the Microsoft Graph API. * Ability to communicate risk clearly to non-technical stakeholders and produce compliance-ready documentation. * Will accept any suitable combination of education, training, or experience. Preferred Skills & Experience * Experience in regulated industries such as financial services, fintech, or automotive with access control obligations. * Familiarity with FTC Safeguards Rule requirements or equivalent data security regulatory frameworks. * Prior experience integrating an HRIS platform (Workday, BambooHR, UKG, or similar) with Entra ID via SCIM or custom connector. * Exposure to IGA platforms such as SailPoint, Saviynt, or Omada. * Experience advising development teams on token validation, scope design, role claims, and secure session management. * Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent professional experience. * Relevant certifications: SC-300 (Microsoft Identity and Access Administrator), AZ-500 (Microsoft Azure Security Technologies), or equivalent ## Description * Design and implement enterprise RBAC: Build a cohesive role-based access control model across Entra ID, Active Directory, and Entra External ID, replacing ad hoc access grants with governed, role-aligned entitlements. * Lead identity lifecycle automation: Integrate the HR system with Entra ID to automate provisioning and deprovisioning, ensuring access changes are event-driven and auditable at the point of hire, transfer, and termination. * Govern directory structure and access hygiene: Define and enforce naming conventions, group structures, and access review cadences across all directory platforms. * Manage non-human identities: Govern service accounts, including managed identities, service principals, and app registrations, enforcing least privilege and credential hygiene across all environments. * Advise development teams on identity security: Provide architectural guidance on token handling, session management, and federation patterns for teams building or maintaining identity adjacent systems. * Drive Conditional Access and PIM: Lead Conditional Access policy design and own Privileged Identity Management configuration and the privileged access model for admin roles across Azure and M365. * Support Entra External ID governance: Advise teams on External ID tenant configuration, custom policy, user flows, and external identity federation. * Produce compliance-ready documentation: Maintain IAM documentation including access control matrices, provisioning runbooks, and audit-ready entitlement inventories supporting FCRA and FTC Safeguards Rule obligations. * Collaborate across the security program: Align IAM initiatives with the broader security roadmap and participate in change management and architecture review processes alongside security engineers and the Cybersecurity Manager. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Destigmatizing the Workplace: Building Real Inclusion](https://www.wearedevelopers.com/videos/1492-destigmatizing-the-workplace-building-real-inclusion) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)