Cybersecurity Architect - Identity

Envestnet

Kentucky

On-site

USD 168,000 - 209,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Paid time off (PTO)
401k company match
Paid parental leave
Education reimbursement
Disability coverage
Mental health & wellness support

Job summary

Envestnet is seeking a Security Governance Architect to shape identity programs and secure enterprise systems. You will architect and implement identity controls, collaborate with IT, engineering, and product teams, and lead governance modernization efforts across cloud and on‑prem environments.

The role requires deep identity governance expertise, strong communication, and the ability to translate risk into actionable controls.

Qualifications

  • Deep experience with identity governance, IAM, IGA, PAM, access reviews, approvals, and evidence generation.
  • Strong working knowledge of AD, Entra ID, Okta, cloud identity, SSO, MFA, federation, and conditional access.
  • Experience governing SaaS and client identity controls and lifecycle automation.
  • Ability to define and communicate identity metrics, KPIs/KRIs, and risk reduction outcomes.

Responsibilities

  • Architect, design, and implement security infrastructure and services for enterprise identities.
  • Interface daily with IT, security, clients, and vendors to meet global security needs.
  • Provide cybersecurity architecture guidance across program and solution levels.
  • Develop systems and solutions for cyber systems and networks, ensuring security requirements.
  • Lead engineering standards, governance frameworks, and modernization initiatives.
  • Analyze risks to information systems and propose innovative mitigation approaches.

Skills

Identity governance
Identity platforms
SSO MFA
Automation & tooling
Risk metrics
Communication
PowerShell & APIs
SaaS identity controls

Tools

AD
Entra ID
Okta

Job description

The application window will close October 15, 2026.

Job Location

The primary work location for this role is remote with a remote work model.

About Envestnet

Envestnet is an adaptiveWealthTechcompany that isredefining the future of wealth management byhelpingadvisors meet the moment with its comprehensive technology, actionable insights, and industry leading support.Backed byover25 years of experience and approximately$7.0 trillionin platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs.

The Team You’ll Join

The Security Governance team plays a critical role in protecting and enabling Envestnet’s wealth management technology platform by embedding security, risk management, and regulatory compliance into the fabric of the business. Partnering closely with engineering, product, cloud, data, HR, and compliance teams, the group develops security architecture, governance frameworks, and resilient controls that safeguard critical financial systems while helping teams innovate quickly and securely. What sets this team apart is its forward-looking approach to security, leveraging automation and AI to modernize risk management, strengthen customer trust, and ensure secure adoption of emerging technologies.

How You'll Contribute

Responsible for the overall architecture and design of security infrastructure, including engineering, implementation, integration and technical services and support. Defines specifications for operating system applications and modifies / maintains existing applications. Designs, integrates and implements infrastructure including hardware, software and various configurations. Designs and deploys systems based on business and user requirements. Plans, conducts and directs the analysis of business problems to be solved with automated systems.

  • Interfaces daily with IT and security counterparts, clients and third-parties to ensure an overall integrated approach to understanding and meeting global technical and security needs.
  • Provides cybersecurity architecture advice and consultation across major program and solution levels.
  • Designs and develops new systems, applications and solutions for cyber systems and networks.
  • Ensures system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security testing and evaluation.
  • Contributes to the creation of cybersecurity architecture principles, standards and patterns, publishing and distributing as appropriate.
  • Actively drives the definition of engineering standards and technologies / frameworks and leads associated working groups.
  • Provides complex analysis of potential risks to information systems security and recommends innovative solutions.
  • Integrates network security controls into an environment to identify risks and reduce their impact.
  • Define the enterprise identity governance architecture, roadmap, and control framework across AD, Entra ID, Okta, IGA, PAM, cloud, SaaS, workforce, client, privileged, and non-human identities.
  • Govern identity lifecycle controls, including provisioning, deprovisioning, access requests, certifications, entitlement management, segregation of duties, remediation, monitoring, and evidence generation.
  • Lead IGA and PAM modernization through workflow automation, connectors, application onboarding, certification engines, integrations, reporting, vaulting, session management, just-in-time access, reviews, exceptions, and monitoring.
  • Design and maintain authentication, authorization, and access governance controls, including SSO, MFA, federation, conditional access, RBAC/ABAC, tenant separation, client administration, entitlement design, and privileged client access.
  • Partner with HR, engineering, cloud, product, and IT to automate lifecycle management, improve identity data quality, and reduce identity sprawl, dormant accounts, unmanaged access, lifecycle risk, and SaaS identity gaps.
  • Align identity controls to enterprise policy, risk appetite, audit, regulatory, client assurance, NIST CSF, NIST 800-53, NIST 800-63, and applicable ISO 42001 expectations.
What You'll Need to Bring
  • Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
  • Deep experience with identity governance, IAM, IGA, PAM, access reviews, requests, approvals, certifications, entitlement management, RBAC/ABAC, segregation of duties, control monitoring, and evidence generation.
  • Strong working knowledge of AD, Entra ID, Okta, cloud identity, SSO, MFA, federation, conditional access, group governance, directory modernization, identity data quality, and access architecture.
  • Experience improving provisioning, deprovisioning, joiner/mover/leaver processes, authoritative source integration, IGA workflows, certification readiness, remediation tracking, reporting, control monitoring, evidence collection, and lifecycle automation.
  • Knowledge of non-human identity governance for AI agents, service accounts, API keys, machine identities, workload identities, service principals, tokens, secrets, automation accounts, and data access governance.
  • Ability to partner with engineering and product teams on PowerShell, APIs, workflow automation, governance automation standards, reporting, authentication, authorization, privileged access, and control assurance.
  • Experience governing SaaS and client identity controls, including client identity hygiene, tenant administration, entitlement design, privileged client access, authentication, authorization, and assurance expectations.
  • Ability to define and communicate identity metrics, KPIs/KRIs, control maturity, remediation progress, reporting, and risk reduction outcomes for governance, audit, and leadership audiences.
  • Strong influence and communication skills, with the ability to explain identity risk, control gaps, architecture decisions, remediation priorities, and risk reduction to technical and non-technical stakeholders, leadership, audit, risk, compliance, and product teams.
Nice-to-Haves
  • 10+ years in cybersecurity, identity governance, IAM, access management, or technology risk, including senior IC experience in financial services, fintech, SaaS, or another regulated environment.
Why You’ll Enjoy Working at Envestnet

Help shape the future of WealthTech. At Envestnet you’ll gain hands‑on experience and collaborate with some of the industry’s brightest minds to deliver meaningful, innovative solutions that make a real difference. We value flexibility in how and where work gets done, and we recognize strong performance with meaningful rewards— because your contributions should drive both business success and your own personal growth. If you’re looking for a place where your work has impact, your development is supported, and your contributions are truly valued, Envestnet is where you can build your future. The opportunity is now!

Sponsorship

This position is not open to candidates requiring visa sponsorship.

Our Investment in You

This role offers a base salary range of $167,500 to $209,400. The range listed represents a good‑faith estimate of base salary compensation for this position and does not include incentive compensation, equity or benefits. Individual pay will be determined based on factors including, but not limited to, relevant experience, skills, education, certifications, and geographic location, in accordance with applicable pay transparency laws. This role is eligible for an additional incentive component as part of the total rewards package. We provide a comprehensive suite of benefits - subject to Envestnet’s plan eligibility rules - that support your overall well‑being including medical insurance, paid time off (PTO), 401k company match, paid parental leave, education reimbursement, disability coverage and mental health & wellness support. Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us. Please visit our benefits page on our career site to learn more.

  • medical insurance
  • paid time off (PTO)
  • 401k company match
  • paid parental leave
  • education reimbursement
  • disability coverage
  • mental health & wellness support
Our Commitment to Inclusion & Belonging

Envestnet is an Equal Opportunity Employer and is committed to creating an inclusive environment for all employees and applicants. We welcome and value individuals of all backgrounds and do not discriminate based on race, color, religion, creed, sex (including pregnancy or related medical conditions), gender identity or expression, sexual orientation, national origin, ancestry, age, disability, genetic information, military or veteran status, citizenship status, or any other status protected by applicable law. We encourage individuals from all backgrounds to apply. We strive to provide an inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation, please contact us at[email protected]. Please include your full name, the title of the role you are applying for, and the accommodation necessary to assist you with the recruiting process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Governance Partner - Risk Management
Lead Security Governance Partner - Risk Management

Envestnet • Chesterbrook (PA)

Hybrid
USD 139,000 - 173,000
Medical insurance
401k company match
Paid time off
Lead Security Governance Partner - Risk Management
Lead Security Governance Partner - Risk Management

Envestnet • Raleigh (NC)

Hybrid
USD 139,000 - 173,000
Lead Information Security Engineer
Lead Information Security Engineer

Envestnet • Berwyn (PA)

Hybrid
USD 139,000 - 173,000
Medical insurance
PTO
401k match
+4
Lead Information Security Engineer
Lead Information Security Engineer

Envestnet • All (MO)

Hybrid
USD 139,000 - 173,000
Competitive compensation
Hybrid work model
Comprehensive benefits
Director, Data Intelligence
Director, Data Intelligence

Envestnet • Berwyn (PA)

Hybrid
USD 168,000 - 209,000
Medical insurance
Paid time off (PTO)
401k company match
+4
Director, Data Intelligence
Director, Data Intelligence

Envestnet • Chesterbrook (PA)

Hybrid
USD 168,000 - 209,000
Regional Director
Regional Director

Envestnet • All (MO)

Hybrid
USD 115,000 - 143,000
Senior Database Administrator
Senior Database Administrator

Envestnet • Berwyn (PA)

Hybrid
USD 104,000 - 130,000
Medical Insurance
PTO
401k match
+4
Lead Enterprise Applications Engineer - Salesforce
Lead Enterprise Applications Engineer - Salesforce

Envestnet • Chesterbrook (PA)

Hybrid
USD 115,000 - 143,000
Senior Database Administrator
Senior Database Administrator

Envestnet • Chesterbrook (PA)

Hybrid
USD 104,000 - 130,000
401k company match
Paid parental leave
Education reimbursement
+2