Remotery

Principal Security, IAM Architect

Posted 2 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Define and take ownership of the future-state security and access management architecture for the MyCDW ServiceNow platform.

• Lead the integration of Entra, Okta, and native ServiceNow authentication into a cohesive identity model.

• Architect the migration from SailPoint to Microsoft Entra ID Governance and develop the ServiceNow RBAC/access-tier model.

• Design workflows for access requests, approvals, certifications, and joiner/mover/leaver processes.

• Ensure that security and identity architecture complies with PCI DSS v4.0.1, SOC 2, and corporate policy standards.

• Establish governance for identity and security across ITSM processes and the MyCDW platform.

• Define a phased transition that separates coworker and customer identities while minimizing disruptions.

• Collaborate with principal architects to ensure alignment of identity and security designs with the target-state architecture.

• Assess identity, security, and IGA technologies through benchmarking, proofs of concept, and risk/cost evaluations.

• Implement security monitoring, threat detection, identity analytics, and platform health insights.

• Conduct risk assessments, threat modeling, and design reviews, providing guidance for remediation.

• Lead, mentor, and establish standards for the Managed Services security and IAM engineering team.

• Work in partnership with development, engineering, infrastructure, compliance, and product stakeholders.

• Maintain architecture roadmaps, design decisions, control mappings, and technical specifications.

• Resolve complex security and identity challenges during design, migration, and operational phases.

• Make cost-effective, risk-based decisions that balance security, budget, and user experience.

• Engage with vendors, negotiate contracts, and manage technology partnerships.

• Stay informed on emerging security and identity threats, standards, and industry trends.


⛳️ Requirements

• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field along with 10 years of experience in IT, including security architecture and IAM, OR 14 years of experience in IT, security, and IAM.

• Extensive hands-on expertise in enterprise security and IAM architecture.

• Proficient in authentication, authorization, federation (SAML/OAuth/OIDC), SSO, MFA, and privileged access management.

• Strong experience with Microsoft Entra ID, Entra ID Governance, and identity governance platforms such as SailPoint.

• Expertise in RBAC/ABAC, access certification, and lifecycle automation for joiner/mover/leaver processes.

• Knowledge of PCI DSS v4.0.1, SOC 2, and corporate security and hardening standards.

• Experience securing SaaS and ITSM platforms, with ServiceNow being strongly preferred.

• Experience or research in applying artificial intelligence principles to security, identity analytics, anomaly/threat detection, and AI-agent access governance.

• Capability to develop and implement security and identity strategies that reduce risk and cost.

• Experience leading project teams architecturally and influencing strategic decisions.

• Proven ability to drive security transformation initiatives and manage change effectively.

• Comprehensive understanding of network architecture, security principles, infrastructure management, and cloud security.

• Exceptional problem-solving and strategic planning capabilities.

• Strong communication, collaboration, leadership, influencing, and conflict-resolution skills.

• Ability to manage multiple projects in a fast-paced environment.

• Demonstrated experience designing and implementing large-scale security and identity solutions.

• Extensive experience across applications, data, infrastructure, security, and cloud services.

• Relevant certifications such as CISSP, CISM, SailPoint, or Microsoft Identity & Access Administrator (SC-300) are advantageous.

• A Master's degree is a plus.


🏝️ Benefits

• Annual bonus target of 10% subject to the terms and conditions of the plan.

• Comprehensive benefits package (details available at https://cdw.benefit-info.com/).

• Geographic salary differentials may apply.

• Support for professional growth and learning opportunities.

• A collaborative work environment.

• Culture of AI experimentation and learning.

People also viewed

ASG Technologies7 hours ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike7 hours ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International8 hours ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape8 hours ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity9 hours ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist11 hours ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers