Jobgether
Jobgether

IAM Solutions Architect

engineeringfull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities:

    • Lead non-human identity program architecture covering discovery, inventory, lifecycle management, ownership, credential and secret management, rotation, attestation, and decommissioning.
    • Design reference architectures for workforce, customer, and non-human identity environments, including workloads, machine identities, service accounts, API credentials, bots, and AI agents.
    • Assess AI agent identity models, lifecycles, and control requirements as organizations adopt increasingly autonomous technologies.
    • Develop architecture review and cybersecurity artifacts, including reference architecture diagrams, data and process flows, detailed security diagrams, and technical documentation.
    • Lead program assessments, vendor and technology evaluations, future-state architecture, governance model design, platform architecture reviews, and product health checks.
    • Own solution architecture and design authority across non-human identity implementations and SailPoint engagements.
    • Lead design workshops and proofs of concept, establish technical decisions, and provide clear direction for engineering teams.
    • Define integration patterns, data models, access models, and non-functional requirements covering security, scalability, resiliency, and performance.
    • Communicate architecture decisions and implementation progress to technical and non-technical client stakeholders, supporting successful adoption of proposed solutions.
    • Provide technical guidance to resolve complex identity challenges while remaining engaged enough to understand implementation realities.
    • Support roadmap development, certification strategy, configuration and tuning, and program reporting.
    • Lead knowledge transfer and operating-model design to enable client teams to independently operate and evolve their identity programs.
    • Contribute to proposals, statements of work, and solution scoping when appropriate.
    • Requirements:

      • 8+ years of experience in identity and access management, including significant experience as a solutions architect, technical lead, principal engineer, or similar senior technical role.
      • Strong expertise in at least one identity domain, such as identity governance, privileged access management, or identity provider and authentication platforms.
      • Experience with technologies such as SailPoint IdentityIQ or Identity Security Cloud, Saviynt, CyberArk, Delinea, BeyondTrust, Okta, Microsoft Entra ID, or Ping is highly relevant.
      • Broad understanding of IAM capabilities, including governance, privileged access, secrets management, certificate management, authentication, MFA, identity providers, and authorization.
      • Strong understanding of workforce, customer, and non-human identities, with the ability to identify and assess different NHI types and their lifecycle characteristics.
      • Ability to assess enterprise environments and identify non-human identities, ownership models, authentication methods, and lifecycle requirements.
      • Working knowledge of AI agent types, lifecycles, and associated identity and security controls; direct experience governing agent fleets is not required.
      • Ability to create detailed technical and security artifacts suitable for architecture review boards and cybersecurity reviews.
      • Strong client-facing communication skills, with the ability to engage technical architects and clearly explain complex decisions to non-technical stakeholders.
      • Ability to challenge client assumptions constructively, explain technical risks, and recommend practical solutions.
      • Comfortable working independently on smaller engagements and taking ownership of the client relationship and technical outcome.
      • Demonstrated curiosity and continuous learning, including evidence of self-directed technical development such as home labs, side projects, or independently acquired skills.
      • U.S.-based and authorized to work in the United States.
      • Experience with NHI, machine identity, secrets management, certificate lifecycle management, cloud identity, Zero Trust, or regulated industries is a plus.
      • SailPoint, CyberArk, Okta, Microsoft Entra, CISSP, or similar certifications are helpful but are not required.
      • Prior experience with a formal architect title is not required when equivalent technical depth and architecture experience can be demonstrated.
      • Benefits:

        • Remote-first position for U.S.-based professionals.
        • Flexible working hours, with client time zones taking priority when required.
        • 20 days of paid time off, provided as an annual bucket.
        • Paid holidays.
        • Medical, dental, and vision coverage through Aetna.
        • 401(k) with company match, including a full match on the first 3% and half match on the next 2%.
        • Annual performance-based bonus eligibility.
        • Sponsored training and professional certifications across relevant identity platforms.
        • Structured enablement for emerging non-human identity technologies.
        • Direct client exposure and meaningful ownership of complex identity architecture initiatives.
        • Opportunity to contribute to the development of a growing identity services practice.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now