> Markdown version of [/jobs/ext/590685-identity-access-management-architect](https://www.wearedevelopers.com/jobs/ext/590685-identity-access-management-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity & Access Management Architect - **Company:** The C.A.S.E. Engineering Group - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $105,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, User Authentication, Cloud Computing Security, Configuration Management Databases, CompTIA Security+, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Information Systems Security Architecture Professional, Network Security, OAuth, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Okta, Information Technology, SailPoint - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=744f6a8ce403777e ## About the Role Do you have experience in Identity and access management (IAM) architecture design?, Do you have a Bachelor's degree?, Education & Certification * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred (or equivalent experience) * Certified Information Systems Security Professional (CISSP) certification required * One or more of the following strongly preferred: Microsoft Certified: Identity and Access Administrator Associate (SC-300); a platform identity certification (e.g., SailPoint, Okta, or Ping Identity); Cloud Security Alliance Certificate of Competence in Zero Trust (CCZT); CompTIA Security+; ITIL 4 Foundation, * At least 10 years of progressive experience in identity and access management and security architecture * Deep, hands-on expertise with enterprise directories, single sign-on, multi-factor authentication, and federation * Experience assessing privileged access, identity governance, and joiner/mover/leaver lifecycle in large, complex enterprise environments; federal experience preferred * Proven track record designing centralized, well-governed identity models and reducing identity sprawl Technical Expertise * Enterprise directories and identity stores (e.g., Active Directory, Microsoft Entra ID / Azure AD) * Single sign-on (SSO), multi-factor authentication (MFA), and federation (SAML, OAuth 2.0, OpenID Connect) * Authentication and authorization flows across applications and services * Privileged access management (PAM) and least-privilege models * Identity governance and administration (IGA) and joiner/mover/leaver (JML) lifecycle * Identity as the first pillar of Zero Trust (NIST SP 800-207), and unique-identifier concepts for one persistent identity per person * Working knowledge of federal frameworks (e.g., NIST SP 800-53 and Federal Identity, Credential, and Access Management - FICAM) Additional Skills * Excellent written and verbal communication, including briefing senior leadership and federal stakeholders * Strong documentation discipline and attention to detail * Strong analytical, problem-solving, and risk-identification skills * Effective at collaborating with cross-functional teams to align technical work with program outcomes * Adaptability in a fast-paced, evolving environment with shifting priorities Clearance * Must be a U.S. citizen and be able to obtain a federal background investigation ## Description This position supports a mission-critical federal program focused on enterprise IT portfolio rationalization, modernization, and governance within a federal agency's Office of the Chief Information Officer (OCIO). Our team discovers, documents, and rationalizes a large and complex enterprise IT estate - spanning networks, infrastructure, applications, data, and identity - to establish an authoritative baseline and chart a clear path toward a consolidated, well-governed target state. We seek professionals who are not only technically proficient but also adaptable, analytical, and dedicated to excellence, ensuring that we continue to provide our clients with the best expertise available., The Identity & Access Management (IAM) Architect serves as the authoritative technical lead for understanding and rationalizing how identity works across the enterprise. This role thinks in enterprise identity - not just user logins - discovering identity stores, trusts, and federation relationships; mapping how people authenticate and what they can access; and assessing privileged access and lifecycle hygiene. The IAM Architect defines the path toward one persistent, trusted identity per person, aligned to the enterprise unique-identifier framework, and treats identity as the front door to every system and the first pillar of Zero Trust. This is a full-time, onsite role based in Washington, D.C., requiring availability during normal business hours, with occasional night and weekend work as needed based on program demands. The IAM Architect works closely with executive leadership and cross-functional engineering teams - partnering in particular with the CMDB and service management team on the enterprise unique-identifier framework and with the Network Security & Zero Trust Architect on identity as the first Zero Trust pillar - and supports governance processes and milestone reviews throughout the program. Key Responsibilities * Discover and document identity stores, domains, trusts, and federation relationships * Map authentication and authorization flows across applications and services * Assess privileged access, multi-factor authentication (MFA) coverage, and joiner/mover/leaver (JML) lifecycle hygiene * Define how every person carries one persistent identity, conforming to the enterprise unique-identifier framework, in partnership with the CMDB and service management team * Frame the target-state identity model and the path toward a centralized, well-governed identity fabric * Align the identity approach to Zero Trust as its first pillar, partnering with the Network Security & Zero Trust Architect * Partner with application, cloud, network, and enterprise architecture teams to align identity with modernization objectives * Produce professional-grade identity architecture artifacts, diagrams, and documentation * Support governance processes, technical reviews, and milestone gates, and brief findings to leadership and federal stakeholders * Identify opportunities for risk reduction and continuous improvement in partnership with the broader team ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)