
Principal IAM/PAM Security Architect
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in United States.
• Establish and uphold security architecture and standards for identity environments including Active Directory, Microsoft Entra ID, Okta, AWS, Azure, GCP, and OCI.
• Act as the primary authority for identity security decisions within a vast and intricate identity ecosystem.
• Lead architecture evaluations and risk assessments concerning identity integrations, platform transitions, and mergers & acquisitions.
• Set enterprise benchmarks for Agentic Identity governance, lifecycle, authentication, and authorization for AI agents and other non-human identities.
• Monitor the landscape of agentic AI and non-human identities, providing leadership with insights on risks, standards, and vendor capabilities.
• Define security specifications for and spearhead the company-wide deployment of the Delinea PAM platform, including Secret Server and Privilege Manager.
• Design controls for least-privilege, JIT/JEA, session monitoring, and credential rotation in both on-premises and cloud settings.
• Supervise the onboarding of privileged accounts and systems.
• Generate audit-ready evidence for PAM controls in alignment with SOX, HIPAA, PCI, and ISO 27001.
• Manage enterprise policy and lifecycle standards for API keys, OAuth/OATH tokens, service account credentials, and certificates.
• Lead efforts to detect and resolve hardcoded, unmanaged, or compromised secrets within source code, configuration files, and CI/CD pipelines.
• Establish metrics and reporting mechanisms for secrets governance maturity and compliance.
• Participate in and assist in leading architecture review boards, governance forums, and risk committees.
• Maintain reference architectures, standards documentation, and roadmaps for identity, PAM, and secrets governance.
• Advise stakeholders on identity risk and control framework for new projects.
• Mentor engineers in the implementation of identity, PAM, and secrets solutions.
• Fulfill annual performance review or goal-setting duties along with assigned special projects and other responsibilities.
• Bachelor’s degree in a technology-related field or equivalent professional experience.
• Over 8 years of experience in identity and access management, privileged access management, or security architecture roles.
• Experience in large, complex enterprise environments.
• Proficiency in designing security standards for hybrid identity environments.
• Practical experience with a PAM platform at an architectural or lead engineering capacity; Delinea is preferred.
• Familiarity with Active Directory, Microsoft Entra ID, and Okta, encompassing federation, conditional access, and hybrid identity synchronization.
• Experience with AWS, Azure, GCP, and OCI IAM, including IAM roles/policies, workload identity, federation, and cross-cloud access patterns.
• Knowledge of AI agent architectures, service/workload identities, and emerging standards related to non-human identity governance.
• Hands-on experience with Delinea Secret Server and Privilege Manager.
• Experience with HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, and secrets-detection tools.
• Understanding of Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA.
• Familiarity with SOX, HIPAA, PCI DSS, and ISO 27001 as they pertain to identity, privileged access, and secrets controls.
• Experience with PowerShell, Python, and REST APIs for automating identity/PAM/secrets lifecycle processes.
• Proven experience embedding identity, PAM, and secrets controls into CI/CD pipelines and infrastructure-as-code using Terraform, ARM, and CloudFormation.
• Strong analytical and architectural problem-solving capabilities.
• Ability to distill complex, multi-domain identity environments into clear standards.
• Proficiency in communicating architectural and risk-related decisions to both technical and business audiences.
• Relevant security certifications are preferred, such as CISSP, CISM, SABSA, or CCSP.
• Must be capable of performing duties with or without reasonable accommodation.
• Must ensure high-speed internet access/connectivity and maintain an appropriate office setup.
• Must provide a dedicated and secure workspace.
• Consideration for discretionary bonuses.
• Coverage for medical insurance.
• Coverage for dental insurance.
• Coverage for vision insurance.
• Coverage for disability insurance.
• Coverage for life insurance.
• Participation in a 401(k) savings plan.
• Paid family leave.
• 9 paid holidays throughout the year.
• 17–27 days of Paid Time Off (PTO) annually, based on tenure and level.
• High-speed internet access/connectivity and office setup and maintenance provided by the team member.
• Dedicated, secure workspace provided by the team member.
Cisco
Arctiq
Twilio
SimSpace
Get handpicked remote jobs straight to your inbox weekly.