> Markdown version of [/jobs/ext/478008-identity-and-access-management-leader](https://www.wearedevelopers.com/jobs/ext/478008-identity-and-access-management-leader). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management Leader - **Company:** Collective Insights - **Location:** Atlanta, GA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Software as a Service, Cyber Security, Continuous Integration, Human Resources Information System (HRIS), Identity and Access Management, Issue Tracking Systems, Python (Programming Language), Key Management, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, PCI Data Security Standards, Ping (Networking Utility), Windows PowerShell, Role-Based Access Control, Azure Active Directory, Kusto Query Language, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Simple Object Access Protocol (SOAP), Extensible Markup Language (XML), Oracle Access Manager, Okta, Cyberark, Microsoft Power Automate, Siteminder, Information Technology, Sentry, Bicep, Hashicorp, Graphql, SailPoint, Terraform - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7965315db2c76b60 ## About the Role Do you have experience in Identity and access management (IAM) architecture design?, Do you have a Bachelor's degree?, * Experience: 5-8+ years in IAM across at least two subdomains (IAM/SSO/MFA, IGA, PAM/PIM/EPM, machine identity) with enterprise delivery experience. * Education: Bachelor's in Computer Science, Information Security, or related field (or equivalent experience). Master's/MBA preferred. * Technical Expertise: Deep knowledge of Entra ID/Entra ID Governance, Okta, Ping, SiteMinder/OAM; SailPoint or Saviynt; CyberArk/BeyondTrust/Delinea EPM; Azure Key Vault, managed identity, AKS workload identity federation; protocols (OIDC/OAuth2/SAML, SCIM); policy and automation (Conditional Access, PIM, IaC, CI/CD). Development of scripts using tools like powershell/python/javascript/Logic Apps/Power Automate/Flow/Automation Accounts utilizing APIs including Graph API/Rest/SOAP/XML. * Solution Design and Implementation Experience: Proven ability to craft secure, scalable architectures, patterns, and reference implementations with clear trade-off analyses and decision logs. Hands-on guidance of build teams; integration with HRIS/AD/LDAP/SaaS; migration from legacy WAM to modern identity; non-functional requirements (HA/DR/scale) and observability/KQL. * Problem-Solving & Communication: Structured thinking, root-cause analysis, and optioning (good-better-best) aligned to risk and business value. Clear written and verbal communication from engineering to executive levels; workshop facilitation; executive-ready materials. * Industry Knowledge: Understanding of sector-specific constraints (e.g., healthcare payer, financial services, public sector, etc) and auditor expectations. * Client-Facing Skills: History of successful client engagements, stakeholder alignment, and outcome-based delivery. * Demonstrated Passion: Continuous learning, community contribution, and awareness of emerging identity trends (e.g., passkeys, external identities, identity threat detection). * Certifications (highly desirable): Microsoft SC-100, SC-300, AZ-500; Okta Professional/Consultant; Ping; SailPoint Architect/Engineer; Saviynt; CyberArk Defender/Sentry; BeyondTrust/Delinea; HashiCorp Terraform Associate; AZ-104/AZ-305. Additional Requirements: Availability for periodic client travel, conferences, and professional engagements. Commitment to ongoing education and staying current with identity standards, vendor capabilities, and threats. **Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future. ## Description Job Description: As an Identity & Access Management (IAM) Leader, you will design, implement, and optimize modern identity solutions across Identity & Access Management (IAM/SSO/MFA), Identity Governance & Administration (IGA), Privileged Access Management (PAM/PIM/EPM), including human, machine, workload, bot and device Identities & Secrets. You will translate business, security, and compliance needs into scalable architectures on platforms such as Microsoft Entra ID & Entra ID Governance (primary), Okta, Ping, SiteMinder/Oracle Access Manager, CyberArk, BeyondTrust, Delinea EPM, and Azure Key Vault / Entra workload identity federation (AKS, Managed Identity). You will partner closely with client stakeholders to align identity strategy to Zero Trust principles, regulatory obligations, and measurable value realization. What You Will Be Doing: * Solution Design: Lead the definition of target-state IAM architectures (OAuth2/OIDC/SAML, Conditional Access, FIDO2/Passkeys, B2B/B2C/External ID, RBAC/ABAC), IGA operating models (birthright access, lifecycle workflows, access reviews, role mining/SoD), PAM/PIM/EPM patterns (vaulting, JIT/JEA, session management, break-glass), and machine identity strategies (managed identity, AKS federation, certificate lifecycle, secret rotation). Ensure solutions are scalable, repeatable, secure, and aligned to industry best practices and Zero Trust. * Client Engagement: Facilitate discovery and architecture workshops; assess current state and risks; advise executives on roadmap options and operating model implications (helpdesk, audit, NOC/SOC). Communicate complex issues with structured narratives and clear recommendations. * Implementation: Guide the conversion of architecture into secure designs and implementation plans; collaborate with Technical Specialists to configure policies, connectors, and automation (Terraform/Bicep, PowerShell/Python, Graph API, CI/CD). Oversee integration, testing, cutover, and rollback strategies. * Compliance & Risk Management: Align identity controls to regulatory and security frameworks (e.g., NIST 800-53/63, ISO 27001, SOC 2, HIPAA/HITRUST, PCI-DSS, SOX, FedRAMP, NYDFS 23 NYCRR 500). Define controls for privileged access, least privilege, strong auth, and auditability; partner with risk/audit to close findings. * Technical Leadership: Serve as design authority; mentor engineers; run design reviews and threat modeling; establish non-functional requirements (availability, resiliency/DR, performance, observability). * Documentation & Reporting: Produce architecture diagrams, patterns, decision records, security requirements, test/acceptance criteria, and runbooks. Provide status, risk/issue tracking, and outcome reporting. * Continuous Improvement: Conduct post-implementation reviews; tune Conditional Access/PIM/EPM policies, provisioning performance, and cert/secret rotations; codify reusable modules. * Practice Development: Support pursuits (SoW scope, assumptions, pricing guardrails), demos/POCs, and market presence through presentations and publications. Supports innovation thru asset development that supports acceleration of value. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)