Identity and Access Management Architect- Manager
Role details
Job location
Tech stack
Job description
As an IAM Architect, you will serve as a strategic and technical leader helping organizations design, implement, and mature enterprise IAM programs. You will work with clients across industries to modernize identity capabilities, strengthen security posture, and enable digital transformation across cloud, on-premises, and hybrid environments.
This role is ideal for professionals who thrive in a fast-paced consulting environment, enjoy solving complex enterprise challenges, and are passionate about delivering practical, high-impact identity solutions.
As part of a growing IAM practice, this role may also support broader cybersecurity and risk engagements. This provides the opportunity to expand exposure across domains such as IT risk, security assessments, and regulatory compliance while helping build and scale Crowe's identity capabilities., * Lead IAM strategy development, roadmap creation, and reference architecture design aligned to client business objectives.
- Define and deliver enterprise IAM architecture, including authentication, authorization, identity lifecycle management, and privileged access management.
- Advise clients on Zero Trust principles and identity-centric security strategies.
- Present IAM strategies, architectures, and findings to technical and executive stakeholders, including C-suite leadership.
- Design and implement IAM solutions across cloud (Azure, AWS, GCP), on-premises, and hybrid environments.
- Architect and integrate IAM platforms with enterprise applications, directories, APIs, and DevOps pipelines.
- Provide guidance on modern authentication and authorization approaches (e.g., SSO, MFA, passwordless, RBAC, ABAC).
- Lead or support implementation of modern identity and authorization platforms, including fine-grained authorization and entitlement visibility solutions.
- Design and guide API-driven integrations between IAM platforms and enterprise systems, leveraging REST-based services and identity data flows.
- Lead or support implementation efforts, including identity governance, provisioning, access reviews, and privileged access controls.
- Partner with clients to accelerate onboarding and adoption of IAM and authorization capabilities, including requirements gathering, solution design, and enablement.
- Conduct IAM risk assessments, threat modeling, and control evaluations; support remediation and continuous improvement.
- Support regulatory compliance and alignment with frameworks such as NIST, ISO, CIS, and industry-specific requirements.
- Apply IAM expertise within the context of enterprise cybersecurity programs, collaborating across domains such as GRC, cloud security, and data protection.
- Contribute to broader cybersecurity engagements, including risk assessments, IT control evaluations, and security program maturity assessments, as needed to support client delivery and practice growth.
- Collaborate with cross-functional teams including security, cloud, application development, and risk/compliance.
Requirements
- Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Engineering, or related field.
- 7+ years of experience in IAM, cybersecurity architecture, or related roles (consulting or industry).
- Proven experience designing and implementing enterprise IAM solutions across cloud and hybrid environments.
- Strong knowledge of authentication and federation standards (OAuth2, OIDC, SAML, SCIM, LDAP).
- Experience with identity governance, privileged access management, and identity lifecycle processes.
- Hands-on experience with leading IAM tools such as Entra ID (Azure AD), SailPoint, Saviynt, CyberArk, Ping Identity, Okta, or similar.
- Broad understanding of cybersecurity domains (e.g., risk management, IT controls, cloud security, or compliance frameworks).
- Familiarity with Zero Trust principles and modern identity security approaches (e.g., MFA, passwordless, RBAC/ABAC).
- Experience with API-based integrations and identity data flows (e.g., REST APIs, JSON, or similar patterns).
- Familiarity with scripting or automation (e.g., Python, SQL, or similar) to support identity integrations or data analysis.
- Experience supporting or leading IAM implementations, transformations, or program development efforts.
- Understanding of non-human identities (e.g., service accounts, APIs, workloads, AI agents) and emerging identity considerations for AI/automation, including governance of machine and agent-based access.
- Strong analytical, problem-solving, and stakeholder management skills.
- Strong communication skills with the ability to translate technical concepts into business terms and engage with senior stakeholders.
- Professional certifications such as CISSP, CISM, CRISC, or IAM/vendor-specific certifications., * Experience in regulated industries (e.g., financial services, healthcare, government).
- Familiarity with AI/automation in cybersecurity or identity governance.
- Familiarity with workflow and governance platforms (e.g., ServiceNow), including support for identity-related processes such as access requests, approvals, and risk/compliance workflows., We are committed to a merit-based hiring process, evaluating all candidates consistently using objective, job-related criteria such as relevant experience, demonstrated skills, measurable impact, and alignment with the role's responsibilities, and making employment decisions in a fair and inclusive manner free from discrimination.