Identity Architect

Job Cloud Inc.
Dallas, United States
4 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Active Directory Application Programming Interfaces (APIs) Amazon Web Services Application Integration Architecture Audit Trail User Authentication Microsoft Azure Cyber Security Information Systems Multi-Factor Authentication Identity and Access Management
+18 more
Intrusion Detection and Prevention Information Systems Security Architecture Professional Python (Programming Language) Key Management OAuth Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Security Assertion Markup Language (SAML) Single Sign-On Data Streaming Systems Integration IT General Controls (ITGC) Cyberark IT Architecture Multi-Cloud SailPoint

Job description

Position Overview: The Identity Architect will define and guide an enterprise identity architecture that connects authentication, identity governance, privileged access, secrets management, identity security, and multi-cloud identity into a cohesive operating model. This role will help evolve identity and access management (IAM) from platform-specific activities into an identity-as-a-service capability that enables the business while improving security, auditability, and user experience. The architect will combine technical depth, practical judgment, and strong communication to guide technical and business stakeholders through architecture decisions and implementation paths., · Own and maintain the target-state IAM architecture, reference patterns, principles, standards, and technology roadmap.

· Assess current identity capabilities and recommend improvements across Microsoft Active Directory, Microsoft Entra ID, hybrid identity, cloud identity, authentication, authorization, identity governance, privileged access management (PAM), secrets management, and identity security.

· Design how identity governance, PAM, multifactor authentication (MFA), secrets management, directories, applications, and security tooling should work together.

· Establish architecture patterns for human identities, service accounts, application identities, workload identities, privileged identities, and other non-human identities.

· Define identity lifecycle, joiner/mover/leaver, access request, access review, role, entitlement, privileged access, and exception management patterns.

· Guide single sign-on (SSO), MFA, Conditional Access, federation, identity proofing, adaptive access, and application integration decisions.

· Evaluate integration approaches using application programming interfaces (APIs), connectors, System for Cross-domain Identity Management (SCIM), Security Assertion Markup Language (SAML), OAuth 2.0, OpenID Connect, and related protocols.

· Provide architecture guidance for identity across Microsoft Azure and Amazon Web Services (AWS), including cloud identity models, account structures, roles, permissions, and governance.

· Translate business, security, regulatory, and operational requirements into architecture decisions, detailed requirements, implementation sequencing, and transition plans.

· Review proposed designs and implementations for least privilege, resiliency, supportability, auditability, and alignment with approved standards.

· Partner with IAM leadership, identity engineers, analysts, application teams, cloud teams, security operations, audit, compliance, and organizational change management.

· Use PowerShell, Python, APIs, data exports, or other practical techniques when a platform limitation requires an alternate solution or automation path.

· Maintain architecture documentation, decision records, data flows, integration diagrams, control mappings, and operational standards.

· Support remediation planning for identity data quality, orphaned accounts, stale identities, over-provisioned access, service-account ownership, and privileged-access risk.

· Advise on identity monitoring, detection, incident response, and integration with existing security tooling.

Requirements

· 10 or more years of progressive experience in identity, access management, cybersecurity, infrastructure, enterprise architecture, or a closely related discipline.

· 7 or more years of hands-on IAM architecture or senior IAM engineering experience in a large enterprise environment.

· Strong experience with Microsoft Active Directory and Microsoft Entra ID, including hybrid identity, directory synchronization, authentication, authorization, Conditional Access, MFA, and privileged access.

· Demonstrated experience designing or integrating at least two enterprise IAM platforms, with Saviynt preferred and SailPoint accepted.

· Experience with CyberArk or a comparable PAM platform, secrets management, and privileged identity controls.

· Strong understanding of IAM governance, lifecycle management, access reviews, role-based access control, segregation of duties, least privilege, and audit evidence.

· Practical knowledge of AWS and Azure identity and security models.

· Experience with APIs, application integration patterns, federation, SAML, OAuth 2.0, OpenID Connect, SCIM, and automation.

· Ability to analyze complex environments, make architecture decisions, document them clearly, and influence stakeholders without direct authority.

· Ability to work onsite in the Dallas-Fort Worth area approximately 2 to 3 days per week.

· Preferred qualifications:

· Experience in electric utilities, critical infrastructure, North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP), Sarbanes-Oxley Act (SOX), IT general controls, or similarly regulated environments.

· Microsoft identity or security certification, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Saviynt, SailPoint, CyberArk, AWS, or Azure certification.

· Experience with identity threat detection and response, identity security posture management, service-account governance, or non-human identity programs.

· Experience building identity standards, operating models, roadmaps, and governance forums.

Tools and Technologies:

  • Microsoft Active Directory
  • Microsoft Entra ID
  • Azure
  • AWS
  • Saviynt or SailPoint
  • CyberArk or comparable PAM platforms
  • MFA solutions
  • Secrets-management technologies
  • PowerShell
  • Python
  • APIs
  • SCIM
  • SAML
  • OAuth 2.0
  • OpenID Connect

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

46 sec

Brokering third-party APIs with OAuth federation

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all