Our client is a global technology leader at the forefront of advanced semiconductor manufacturing and innovation. They are seeking a Senior Enterprise Identity Architect to take ownership of enterprise identity architecture and help shape the next generation of IAM, security, and Zero Trust capabilities across a highly complex global environment.
This is a high-visibility individual contributor role for an architect who enjoys both strategic ownership and hands-on technical work. You will work closely with IT leadership, Security, Infrastructure, Engineering, and Enterprise Architecture to define the identity roadmap while remaining deeply involved in the design, prototyping, and modernization of solutions.
The Opportunity
The organization operates a unique combination of modern cloud technologies and extensive legacy/on-premise infrastructure, creating an unusually complex identity environment.
You will be responsible for determining where the current identity architecture needs to evolve, establishing the roadmap, and then working directly with engineering teams and technology partners to make it happen.
Approximately 40% of the role is strategic architecture and roadmap development, with 60% focused on hands-on technical architecture, prototyping, design reviews, and implementation guidance.
Key Responsibilities
- Own and evolve the enterprise identity architecture across IAM, IGA, PAM/PIM, SSO, Active Directory, Entra ID, cloud identity, and SaaS
- Define enterprise identity standards, patterns, reference architectures, and technology roadmaps
- Lead the organization’s Zero Trust identity strategy and modernization of authentication and authorization
- Assess the existing identity environment and identify opportunities to improve security, scalability, user experience, and operational efficiency
- Design identity lifecycle and governance solutions covering provisioning, deprovisioning, role management, access certification, and least privilege
- Architect and modernize privileged access management, including JIT access, privileged sessions, secure credential management, and administrative tiering
- Lead hybrid identity architecture across Active Directory, Entra ID, on-premise infrastructure, and cloud environments
- Design modern authentication solutions using SAML, OAuth, OIDC, MFA, Conditional Access, passwordless authentication, FIDO2, and device identity
- Provide architecture direction for legacy identity infrastructure while developing migration paths toward modern platforms
- Partner with engineering teams and MSP/technology partners on implementation, troubleshooting, and technical delivery
- Build prototypes and proof-of-concepts to validate new identity technologies and approaches
- Mentor engineers and provide hands-on technical guidance rather than simply handing designs off for implementation
- Participate in enterprise architecture governance and represent Identity at architecture review boards
- Partner with Cybersecurity, HR, Infrastructure, Applications, Risk, and Compliance teams to align identity strategy with business requirements
- Evaluate emerging IAM technologies and industry trends, including identity for AI and emerging agent-based applications
- Support enterprise security initiatives and present identity strategy, risks, and recommendations to senior IT leadership
What We’re Looking For
- 8+ years of experience working in large enterprise environments
- 5+ years designing and architecting enterprise-grade identity solutions
- Deep hands-on experience with one or more major IAM platforms such as Okta, Ping Identity, or Microsoft Entra ID
- Strong experience with Identity Governance & Administration (IGA) platforms such as SailPoint or Saviynt
- Strong Privileged Access Management (PAM/PIM) experience with platforms such as CyberArk or BeyondTrust
- Extensive Active Directory and hybrid identity experience
- Experience across Azure and multi-cloud environments, ideally including AWS and/or GCP
- Proven experience leading enterprise identity modernization or cloud transformation programs
- Strong understanding of Zero Trust, least privilege, RBAC/ABAC, identity lifecycle management, and modern authentication
- Experience with SAML, OAuth, OIDC, SCIM and API-based identity integrations
- Strong understanding of security and compliance frameworks such as SOX, HIPAA, PCI, ISO 27001, and/or NIST
- Ability to move comfortably between strategic architecture discussions and hands-on technical implementation
- Excellent communication skills and the ability to present complex technical concepts to senior leadership