IAM Architect Role Overview
We are seeking an experienced IAM Architect to lead the design, architecture, and governance of enterprise Identity and Access Management (IAM) solutions. The ideal candidate will have strong hands-on expertise in Microsoft Entra ID and SailPoint (ISC/IIQ), along with architecture-level knowledge of platforms such as Okta, Delinea, CyberArk, and Ping Identity. This role will drive identity transformation initiatives, Zero Trust adoption, and identity governance across hybrid and multi-cloud environments.
Key Responsibilities
- Define and execute enterprise IAM and Identity Governance architecture strategy and roadmap.
- Architect and implement Microsoft Entra ID capabilities including Conditional Access, MFA, Passwordless Authentication, SSO, Identity Governance, PIM, Access Reviews, and Entitlement Management.
- Design and architect SailPoint ISC/IIQ solutions aligned with security, compliance, and business requirements.
- Lead Identity Lifecycle Management (Joiner, Mover, Leaver), provisioning, and deprovisioning processes.
- Architect integrations with Entra ID, Active Directory, HR systems, ServiceNow, cloud platforms, databases, and enterprise applications.
- Define governance models including RBAC, Segregation of Duties (SoD), access certifications, and policy management.
- Provide architectural guidance across IAM/PAM platforms including Okta, Delinea, CyberArk, Saviynt, Ping Identity, and ForgeRock.
- Collaborate with Security, Infrastructure, Cloud, and Application teams to implement Zero Trust and modern identity controls.
- Mentor engineering teams and support audit, risk, and compliance initiatives.
Required Experience
- 9-14 years of overall IT experience, with significant experience in IAM/IGA solution design and architecture.
- Strong hands-on expertise in Microsoft Entra ID and hybrid identity environments.
- Proven experience with SailPoint Identity Security Cloud (ISC) and/or IdentityIQ (IIQ).
- Experience designing enterprise-scale IAM, IGA, and PAM solutions.
- Strong understanding of authentication, federation, and identity governance frameworks.
- Experience working with one or more IAM platforms such as Okta, Delinea, CyberArk, Saviynt, Ping Identity, or ForgeRock.
Technical Skills
- Microsoft Entra ID (Azure AD), Active Directory, Entra Connect / Cloud Sync
- SailPoint ISC and/or SailPoint IIQ
- Identity Governance & Administration (IGA)
- Conditional Access, MFA, SSO, PIM, Lifecycle Management
- SAML, OAuth 2.0, OIDC, SCIM
- Okta, Delinea, CyberArk, Saviynt, Ping Identity, ForgeRock
- PowerShell, Microsoft Graph API, REST APIs
- Zero Trust Architecture, RBAC, SoD, Access Certifications
Preferred Certifications:
Microsoft Identity & Access Administrator, Microsoft Cybersecurity Architect, SailPoint Certifications, CISSP/CISM, Okta or Delinea Certifications.