Cybersecurity IAM Architect - Staff Engineer

Relha LLC

Baltimore (MD)

On-site

USD 160,000 - 210,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Relha LLC seeks an experienced Cybersecurity IAM Architect - Staff Engineer to design enterprise IAM security architectures across cloud and on-prem environments. You will lead architecture reviews, define secure patterns for human and non-human identities, and ensure least-privilege access using RBAC/ABAC/PBAC.

The role requires deep knowledge of NIST frameworks, SSO/MFA, federation, PAM, and identity standards (Okta, Entra ID, SAML, OAuth, OIDC).

Qualifications

  • 7–10 years of experience in cybersecurity, with 3+ years in IAM architecture, security architecture, or a similar solution design role
  • Deep working knowledge of NIST frameworks, including CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust
  • Demonstrated experience designing and reviewing IAM architectures for enterprise systems, cloud environments, SaaS platforms, APIs, and hybrid environments
  • Strong understanding of IAM domains including identity lifecycle management, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties
  • Hands-on familiarity with identity platforms and standards such as Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies
  • Strong understanding of LLMs, AI, and GenAI solutions, including agentic AI, MCP/tool hardening, non-human identity governance, agent-to-tool authorization, delegated access, and auditability of agent actions
  • Experience working in a large regulated environment and aligning identity controls to compliance frameworks
  • Excellent communication, collaboration, architecture documentation, and executive-facing presentation skills

Responsibilities

  • Develop enterprise-wide IAM and identity security architectures aligned to NIST standards, including NIST CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust principles
  • Design scalable identity solutions for authentication, authorization, federation, lifecycle management, access governance, privileged access, and policy enforcement across cloud, on-premises, SaaS, and hybrid environments
  • Define secure design patterns for AI agent identities, non-human identities, workload identities, service accounts, API access, secrets, delegated authority, and agent-to-tool interactions
  • Translate business, regulatory, and technical requirements into secure IAM solution blueprints, reference architectures, and reusable identity patterns
  • Establish least-privilege access models using RBAC, ABAC, PBAC, just-in-time access, dynamic credentials, and context-aware controls where appropriate
  • Lead IAM architecture and security reviews for new technologies, applications, AI agents, automation platforms, APIs, and enterprise systems
  • Identify identity-related gaps in proposed solutions, including over-permissioned roles, shared credentials, weak delegation models, insufficient audit trails, and unmanaged non-human identities
  • Advise on risk mitigation strategies for authentication, authorization, privileged access, identity lifecycle, secrets management, token use, tool binding, and agent runtime access
  • Collaborate with engineering, cloud, infrastructure, application, and AI platform teams to ensure secure deployment of identity-enabled systems and services
  • Provide technical guidance to project and product teams throughout the system development lifecycle, with emphasis on secure-by-design IAM controls
  • Governance & Standards: Develop and maintain IAM architecture standards, identity control frameworks, access governance policies, and secure design patterns in alignment with NIST and industry best practices
  • Participate in internal security governance boards and architecture review boards focusing on identity risk, Zero Trust, and AI agent access governance

Skills

IAM architecture
Security architecture
NIST frameworks
Okta
Microsoft Entra ID
SAML/OIDC
PAM
RBAC/ABAC/PBAC
Access governance
Non-human identity governance
AI agent security
Communication with executives

Tools

SCIM
LDAP
Kerberos
OAuth
OIDC

Job description

Cybersecurity IAM Architect - Staff Engineer

Develop enterprise-wide IAM and identity security architectures aligned to NIST standards, including NIST CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust principles

Design scalable identity solutions for authentication, authorization, federation, lifecycle management, access governance, privileged access, and policy enforcement across cloud, on-premises, SaaS, and hybrid environments

Define secure design patterns for AI agent identities, non-human identities, workload identities, service accounts, API access, secrets, delegated authority, and agent-to-tool interactions

Translate business, regulatory, and technical requirements into secure IAM solution blueprints, reference architectures, and reusable identity patterns

Establish least-privilege access models using RBAC, ABAC, PBAC, just-in-time access, dynamic credentials, and context-aware controls where appropriate

Lead IAM architecture and security reviews for new technologies, applications, AI agents, automation platforms, APIs, and enterprise systems

Identify identity-related gaps in proposed solutions, including over-permissioned roles, shared credentials, weak delegation models, insufficient audit trails, and unmanaged non-human identities

Advise on risk mitigation strategies for authentication, authorization, privileged access, identity lifecycle, secrets management, token use, tool binding, and agent runtime access

Collaborate with engineering, cloud, infrastructure, application, and AI platform teams to ensure secure deployment of identity-enabled systems and services

Provide technical guidance to project and product teams throughout the system development lifecycle, with emphasis on secure-by-design IAM controls

Governance & Standards

Develop and maintain IAM architecture standards, identity control frameworks, access governance policies, and secure design patterns in alignment with NIST and industry best practices

Participate in or lead internal security governance boards and architecture review boards with a focus on identity risk, Zero Trust alignment, and AI agent access governance

Ensure solutions meet internal risk, compliance, and regulatory requirements, including CMMC, PCI DSS, and audit expectations for identity controls

Define governance expectations for joiner/mover/leaver processes, entitlement reviews, separation of duties, privileged access, service account ownership, non-human identity inventories, and exception management

Contribute to maturity assessments and continuous improvement efforts for IAM architecture, identity governance, and AI agent identity management capabilities

Act as a subject matter expert on IAM, Zero Trust identity, non-human identity governance, and AI agent identity security for stakeholders across IT, engineering, compliance, risk, and AI product teams

Mentor junior architects and security engineers on identity architecture, secure access patterns, and governance-driven solution design

Communicate complex identity, access, AI agent, and risk concepts clearly to business leaders and non-technical audiences

Stay up to date on emerging threats, identity technologies, AI agent security patterns, and changes to the NIST ecosystem

Required Qualifications

7–10 years of experience in cybersecurity, with 3+ years in IAM architecture, security architecture, or a similar solution design role

Deep working knowledge of NIST frameworks, including CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust

Demonstrated experience designing and reviewing IAM architectures for enterprise systems, cloud environments, SaaS platforms, APIs, and hybrid environments

Strong understanding of IAM domains including identity lifecycle management, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties

Hands-on familiarity with identity platforms and standards such as Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies

Strong understanding of LLMs, AI, and GenAI solutions, including agentic AI, MCP/tool hardening, non-human identity governance, agent-to-tool authorization, delegated access, and auditability of agent actions

Experience working in a large regulated environment and aligning identity controls to compliance frameworks

Excellent communication, collaboration, architecture documentation, and executive-facing presentation skills

Preferred

Industry certifications such as CISSP, CISM, CISA, CCSP, or identity-focused certifications

Experience with Zero Trust Architecture, modern identity security models, and enterprise access governance programs

Experience with policy-as-code, DevSecOps, infrastructure-as-code security, and automated identity control validation

Experience developing governance models for non-human identities, machine identities, workload identities, AI agents, service accounts, secrets, and API credentials

OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity IAM Architect - Staff Engineer
Cybersecurity IAM Architect - Staff Engineer

OneMain Financial • Baltimore (MD)

On-site
USD 150,000 - 190,000
Cybersecurity IAM Architect - Staff Engineer
Cybersecurity IAM Architect - Staff Engineer

OneMain Financial • Maryland

On-site
USD 140,000 - 190,000
IAM Solutions Architect
IAM Solutions Architect

Compunnel, Inc. • Chicago (IL)

On-site
USD 120,000 - 160,000
IAM Automation & DevOps Engineer(AI)
IAM Automation & DevOps Engineer(AI)

Centraprise • Boston (MA)

On-site
USD 120,000 - 150,000
IAM Engineer
IAM Engineer

JPS Tech Solutions • Indiana (PA)

On-site
USD 130,000 - 190,000
AI IAM Architect
AI IAM Architect

LPL Financial LLC • Town of Charlotte (NY), Fort Mill (SC)

On-site
USD 153,000 - 256,000
AI Identity Architect
AI Identity Architect

Q1 Technologies, Inc. • Chicago (IL)

Hybrid
USD 150,000 - 200,000
AI-Driven IAM Architect for Cloud Identities
AI-Driven IAM Architect for Cloud Identities

Compunnel, Inc. • Chicago (IL)

On-site
AVP, IAM AI Engineer
AVP, IAM AI Engineer

lplfinancial • Fort Mill (SC)

On-site
USD 160,000 - 210,000
IAM Solutions Architect - Pre-Sales (Machine and Agent Identity Focus)
IAM Solutions Architect - Pre-Sales (Machine and Agent Identity Focus)

Inspira Enterprise • Dallas (TX)

On-site
USD 140,000 - 180,000