Identity Architect

Insight Global
Saint Paul, MN, United States
11 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) Cyber Security Information Systems Identity and Access Management JSON Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) OAuth OpenID Azure Active Directory Security Assertion Markup Language (SAML)
+8 more
Single Sign-On Systems Integration Scripting Cloud Platform System IT General Controls (ITGC) Software Security Information Technology SailPoint

Job description

Define and maintain target-state enterprise identity architecture across IAM, IGA, PAM, directories, federation, authentication, authorization, certificate lifecycle, and external identity platforms.

  • Establish identity architecture patterns, standards, guardrails, and decision frameworks that support secure and repeatable implementation across teams.

  • Serve as the design authority for identity-related solutions that introduce new access models, integrations, trust boundaries, privileged access paths, or audit implications.

  • Partner with platform owners, engineering teams, application teams, audit, risk, compliance, and security operations to align identity capabilities with business and regulatory requirements.

  • Drive integration across identity platforms so lifecycle, access governance, privileged access, authentication, and audit evidence operate as a cohesive enterprise ecosystem.

  • Translate audit findings, control gaps, operational issues, and security risks into sustainable architectural improvements.

  • Guide modernization efforts across cloud identity, privileged access, identity governance, directory security, external identity, and non-human identity management.

  • Develop and maintain roadmaps for identity platform evolution, including technology transitions, capability rationalization, automation opportunities, and risk reduction priorities.

  • Provide architectural direction for incident response, major identity issues, remediation planning, and root-cause prevention.

  • Communicate identity architecture decisions, risks, tradeoffs, and recommendations clearly to technical teams, leadership, and business stakeholders.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global’s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Requirements

Bachelor’s degree in computer science, information systems, cybersecurity, engineering, business, or related discipline.

  • 10+ years of experience in information technology, cybersecurity, infrastructure, application security, or identity and access management.

  • 5+ years of experience designing or governing enterprise identity solutions in complex hybrid or cloud environments.

  • Experience with identity solutions and architecture across areas such as Active Directory, Microsoft Entra ID, identity governance and administration, privileged access management, single sign-on, federation, conditional access, certificates, and external customer identity.

  • Experience translating security, audit, compliance, and operational requirements into practical architecture standards and implementation guidance.

  • Strong understanding of identity lifecycle processes, access governance, privileged access models, authentication flows, authorization concepts, role-based access, and least privilege principles.

  • Ability to evaluate technical risk, define architectural options, document decisions, and influence stakeholders across multiple teams.

  • Effective communication skills with the ability to engage technical teams, business partners, audit partners, vendors, and leadership. - Experience with platforms or capabilities such as Microsoft Entra ID, Active Directory, Saviynt or similar IGA tools, BeyondTrust or similar PAM tools, certificate lifecycle management, external identity, and directory security recovery or monitoring solutions.

  • Experience leading identity modernization, platform migration, rationalization, or decommissioning efforts.

  • Knowledge of SOX, ITGC, SOC, audit evidence automation, access certifications, segregation of duties, and control design.

  • Experience designing identity solutions for human identities, privileged identities, service accounts, application identities, certificates, and other non-human identities.

  • Familiarity with automation, APIs, scripting, JSON, OAuth, OIDC, SAML, SCIM, LDAP, Kerberos, and modern cloud identity patterns.

  • Demonstrated ability to balance security, usability, scalability, cost, resiliency, and auditability in enterprise architecture decisions.

  • Experience working in a global, matrixed, regulated, or highly distributed technology environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all