> Markdown version of [/jobs/ext/3429602-identity-and-access-management-architect](https://www.wearedevelopers.com/jobs/ext/3429602-identity-and-access-management-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management Architect - **Company:** Tiktok Usds - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $147,200.0 - $269,800.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Big Data, Cloud Computing, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Databases, Multi-Factor Authentication, Federated Identity Management, Apache Hive, Identity and Access Management, Information Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), MySQL, OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Redis, Azure Active Directory, Cloud Services, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Security Information and Event Management, Single Sign-On, SQL Databases, Systems Integration, User Provisioning Software, Software Vulnerability Management, Okta, Cyberark, Information Technology, Gsuite, SailPoint, Restful APIs, Programming Languages, Microservices - **Published:** September 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=65f74ba9d5edc68a ## About the Role Minium Qualifications: - Bachelor's degree or Master's Degree in a related field (e.g., Information Management, Computer Science, Business Analytics, Cyber Security). 5+ years in Identity and Access Management, specifically focused on IAM architecture - Hands-on Experience with authentication and authorization protocols eg: OIDC / OAuth 2.0 For securing APIs, SAML 2.0 For federated identity and SSO, SCIM For automated user provisioning, FIDO2 / WebAuthn For passwordless authentication strategies - Experience in industry-leading IAM product suites like Okta, Ping Identity,Microsoft Entra ID (Azure AD), SailPoint,Saviynt,CyberArk , BeyondTrust etc - Experience architecting IAM in AWS (IAM Roles, SCPs), Azure, or GCP. Deep knowledge of LDAP, Active Directory, and Azure AD - Proficient in at least one software programming language ( Python,Java, PowerShell etc) with experience developing automations and integrating IAM platforms with downstream applications via RESTful APIs - Experience in designing/deploying Access management solutions. xperience analysing large data sets across multiple database types (e.g., MySQL, Hive, Redis etc) leveraging SQL etc - Experience with industry frameworks, standards and regulations (e.g. ISO, NIST, SOC2, PCI etc). Experience with role-based access control frameworks and Conditional Access policies Preferred Qualifications: - Experience working with Microservices architecture - Comfortable working in a fast-paced, dynamic environment - Experience in automating access management workflows to reduce operational overhead - Experience with risk and controls frameworks including (ISO 27001, NIST CSF, NIST RMF, FAIR, COBIT, NIST RMF, ISO 31000 etc.) is a plus - Ability to look beyond immediate fixes and build a scalable security roadmap ## Description About the Team The Identity and Access Management vertical within USDS Data Protection Team is responsible for designing, operating and maintaining an identity and access management program with a mission to enforce the principle of security by design and least privilege. We strive to establish secure and compliant processes around provisioning, deprovisioning and governance of access to USDS data and infrastructure proactively identifying and reducing risks. About the Role As an Identity and Access Management Architect, you will be responsible for supporting the team along with a team of cross-functional cyber, privacy, engineering, and data protection analysts to define, implement, manage, and measure controls to protect data in accordance with USDS policies and standards relevant to geographical regulations, contractual commitments, and confidentiality requirements. The Identity and Access Management Architect will play a pivotal role in the design, deployment and operationalization of the identity ecosystem and access management programs in USDS. Responsibilities: - Develop enterprise-wide IAM strategies, including roadmaps for Workforce IAM, Identity Governance and Administration (IGA), Privileged Access Management (PAM) - Architect solutions for Single Sign-On (SSO), Multi-Factor Authentication (MFA), and directory services (Active Directory, Azure AD/Entra ID) - Engineer and support onboarding of applications onto IAM platforms (Azure AD, Google Workspace) - Define and implement automated workflows for user lifecycle management (joiners, movers, leavers). - Design and manage integrations between enterprise infrastructure components (identity provider, cloud services). Develop automated processes for privileged account lifecycle management - Ensure IAM solutions comply with global standards (ISO, SOC2, PCI) and Zero Trust architecture principles - Design identity and access management program that addresses data residency and fine-grained role-based access requirements and controls as necessitated by business need and regulations - Assist in the development and implementation of Access governance frameworks, policies, and procedures. - Integrate IAM solutions with cybersecurity technologies (SIEM, vulnerability management). - Engineer, deploy, and operationalize privileged access management (PAM) solutions (on-prem and Privilege Cloud). - Implement privileged session management, credential vaulting, and least privilege controls - Build and review technical and functional requirements for in-house or external technologies to support access management and assurance needs, including applying appropriate security measures - Operationalize access management workflows such as access reviews and access remediations to improve efficiency - Responsible for designing and reporting key metrics and visualizations for weekly, monthly and bimonthly cadences across multiple audiences - Participate in security reviews to ensure compliance with access governance policies. - Foster a principle of least privilege for access management - Collaborate with key stakeholders to ensure alignment of access governance initiatives with organizational goals. Communicating complex technical risks to non-technical executives and compliance teams. - Provide technical oversight and guidance for junior IAM engineers and administrators ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Accelerating Authentication Architecture: Taking Passwordless to the Next Level](https://www.wearedevelopers.com/videos/733-accelerating-authentication-architecture-taking-passwordless-to-the-next-level) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [The top 200 passwords of 2024 can be cracked in less than a second](https://www.wearedevelopers.com/magazine/502-the-top-200-passwords-of-2024-can-be-cracked-in-less-than-a-second) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)