Principal Domain Architect - Identity and Access Security at ABB

ABB

Kraków

Hybrid

PLN 450,000 - 750,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Career growth opportunities

Job summary

ABB Kraków is seeking a Principal Domain Architect for Identity and Access Security to lead global IAM strategy and architecture. You will guide Solution Architects, standardize across environments, and drive advanced identity controls in a hybrid on-site setup.

The role emphasizes Zero Trust, strong authentication, RBAC/ABAC/PBAC models, and cross-functional collaboration with security, IS, and HR teams. 15+ years of security architecture experience is expected.

Qualifications

  • Proven expertise in enterprise security architecture and roadmapping.
  • 15+ years in security architecture with Identity Security focus.
  • Cloud security knowledge across public cloud providers.
  • Experience with ISO 27002 and NIST 800-53.

Responsibilities

  • Define and maintain the global IAM architecture vision and roadmap.
  • Establish standards and reference architectures for identity lifecycle and access governance.
  • Architect IAM capability landscape including IGA, PAM, AM, CIAM and secret management.
  • Drive Zero Trust Identity principles and strong authentication across environments.
  • Lead design for RBAC, ABAC, PBAC models and least-privilege access.
  • Integrate IAM with cloud, on-premises, and hybrid platforms and ensure policy enforcement.
  • Design secure IAM integration with applications including SSO and just-in-time provisioning.
  • Architect IAM observability with monitoring, analytics, and automated responses.
  • Partner with HR and security teams to embed IAM controls in joiner/mover/leaver processes.
  • Embed resilience through high availability, DR, and continuity planning.
  • Guide incident response and lessons learned to preventive IAM controls.
  • Rationalize IAM tools to reduce complexity and cost.
  • Stay ahead of IAM threats like MFA bypass and credential stuffing.
  • Mentor globally distributed IAM architects and engineers.

Skills

Security architecture
Zero Trust
Cloud security
Roadmapping
Archimate
UML
Architectural leadership
Security governance

Education

Bachelor’s degree in Computer Science or related field
CISSP
SABSA
TOGAF

Tools

ArchiMate
UML

Job description

Principal Domain Architect - Identity and Access Security at ABB in Kraków, ML, PL. This Full time on site position offers great opportunities for career growth. At ABB, we help industries run leaner and cleaner—and every person here makes that happen. You’ll be empowered to lead, supported to grow, and proud of the impact we create together. Join us and help run what runs the world.

This position reports to: IS Manager __

In this role, you will have the opportunity to act as the architectural authority for your technology area of responsibility.

Each day, you will guide and lead Solution Architects to ensure the integrity of the technology architecture. You will also showcase your expertise by realizing the benefits from standardization, synergy, and optimization of the technology landscape across business and domains.

The work model for the role is: #LI_hybrid

This role is contributing to the Security Risk and Compliance Organization Globally. Main stakeholders are Security teams, Information Systems teams across global services and business areas.

Accountabilities
  • Defining and maintaining the global IAM architecture vision and roadmap, aligned with enterprise security strategy, regulatory requirements, and business needs.
  • Establishing standards, patterns, and reference architectures to identity lifecycle management, authentication, authorization, and access governance across all environments.
  • Architecting and maintaining the full IAM capability landscape - Identity Governance & Administration (IGA), Privileged Access Management (PAM), Access Management (AM), Customer IAM (CIAM), master data and identity data management, secrets management, machine identity management, and emerging IAM domains.
  • Driving Zero Trust Identity principles, implementing strong authentication, adaptive access, and continuous verification to minimize identity-related risks.
  • Architecting role-based, attribute-based, and policy-based access control (RBAC, ABAC, PBAC) models to ensure least privilege access for users, devices, and services.
  • Integrating IAM capabilities into cloud, on-premises, and hybrid platforms, including SaaS, IaaS, PaaS, and containerized workloads, ensuring consistent policy enforcement.
  • Designing secure integration between IAM platforms and business applications, covering SSO, federation, just-in-time provisioning, and privileged access management.
  • Architecting IAM observability: access monitoring, anomaly detection, behavioral analytics, and automated response to suspicious identity activities.
  • Partnering with HR, application, infrastructure, and security teams to embed IAM controls into joiner-mover-leaver processes and change workflows without disrupting operations.
  • Driving secure credential, secrets, and key management strategies, including password less authentication and integration with hardware-based security modules where appropriate.
  • Embedding IAM resilience principles – high availability, failover, disaster recovery, and service continuity – into architecture patterns.
  • Providing architectural guidance during identity-related security incidents, ensuring lessons learned are integrated into preventive and detective IAM controls.
  • Ensuring rationalization of IAM tools and platforms, consolidating overlapping capabilities across identity providers, MFA solutions, PAM systems, and access governance tools to reduce complexity and cost.
  • Staying ahead of emerging IAM threats such as MFA bypass, deepfake-enabled impersonation, credential stuffing, and supply chain compromises in identity services.
  • Leading and mentoring a globally distributed team of IAM architects and engineers, building capability and ensuring architecture adoption.
  • Acting as a trusted advisor to leadership, translating identity risk and architecture priorities into business impact.
Qualifications
  • Proven expertise in enterprise security architecture, with hands-on experience in architecture tools and technology road mapping.
  • 15+ years of experience in security architecture and significant portion of it in Identity Security, including Zero Trust implementation.
  • Cloud Expertise: Deep knowledge of public cloud security principles (identity management, network isolation, and encryption) regardless of the specific provider.
  • Process Driven: Experience mapping technical security controls to global standards like ISO 27002 and NIST 800-53.
  • Hands-on Capability: You are comfortable moving from a high-level architectural drawing to a technical prototype to prove a concept works.
  • Architecture certifications like CISSP, SABSA and TOGAF are preferred.
  • Hands‑on experience in architectural modeling using structured languages such as ArchiMate and UML.
  • Strong global experience, especially in collaborating with distributed teams on security topics.
  • Deep understanding of security architecture design models and frameworks.
  • Bachelor’s degree in Computer Science or related field (preferred).
  • Excellent communication and presentation skills, possessing confidence when engaging senior stakeholders.

Building a cleaner, smarter future takes all kinds of minds: the curious, the courageous, and the creative. That's why we welcome people from all backgrounds and experiences.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IAM Architect – Identity & Access Security (Hybrid)
Senior IAM Architect – Identity & Access Security (Hybrid)

ABB • Kraków

Hybrid
PLN 450,000 - 750,000
Hybrid work model
Career growth opportunities
Applications and Architecture Specialist at ABB
Applications and Architecture Specialist at ABB

ABB • Kraków

On-site
PLN 140,000 - 180,000
Global organization collaboration
International projects
IT Architect Cyber Security (m/k)
IT Architect Cyber Security (m/k)

SMA Solar Technology AG • Kraków

On-site
PLN 240,000 - 340,000
Multisport card
Medical care
Group insurance
+6
Global Applications & IAM Architecture Specialist
Global Applications & IAM Architecture Specialist

ABB • Kraków

On-site
PLN 140,000 - 180,000
Global organization collaboration
International projects
Senior Security Solutions Architect – Data and Network Protection
Senior Security Solutions Architect – Data and Network Protection

ITDS • Kraków

Hybrid
PLN 180,000 - 280,000
IAM Domain Specialist
IAM Domain Specialist

BELVEDERE • Warszawa

Hybrid
PLN 180,000 - 240,000
Applications and Architecture Specialist
Applications and Architecture Specialist

ABB • Kraków

On-site
PLN 120,000 - 180,000
Cybersecurity Architect - Warsaw - On site
Cybersecurity Architect - Warsaw - On site

SEIDOR • Warszawa

On-site
PLN 250,000 - 360,000
Expert IAM Solution Architect – Cloud and Zero Trust Security
Expert IAM Solution Architect – Cloud and Zero Trust Security

ITDS Polska Sp. z o.o. • Kraków

Hybrid
PLN 230,000 - 340,000
Hybrid work model
Medical package
Multisport program
+2
IS Software Architect
IS Software Architect

BlackBerry Inc. • Kraków

Hybrid
PLN 220,000 - 340,000