Enterprise Identity & Access Management Architect

State Street

Quincy (MA)

Hybrid

USD 120,000 - 203,000

Full time

6 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

State Street is seeking an Enterprise IAM Architect to define and drive the IAM strategy across hybrid cloud, SaaS, and on‑prem environments. You will partner with cybersecurity, technology, risk, and business stakeholders to deliver secure, scalable identity capabilities that protect the firm while enabling growth.

You will lead the design and governance of identity services (IGA, PAM, SSO, MFA, Federation, Directory), develop secure identity architecture patterns for workforce, customers,

Qualifications

  • Degree in Computer Science, Information Security, Information Technology, Engineering, or a related discipline.
  • 10+ years of experience in cybersecurity, security architecture, Identity & Access Management, or related technology disciplines.
  • Experience designing and implementing enterprise-scale IAM solutions across cloud, SaaS, and on-premises environments.
  • Deep understanding of IGA, PAM, SSO, MFA, and federated identity technologies.
  • Experience with leading IAM platforms including Microsoft Entra ID, SailPoint, Saviynt, CyberArk, Okta, Ping Identity, ForgeRock, or equivalent technologies.
  • Professional certifications such as CISSP, CCSP, TOGAF, SABSA, or equivalent are highly desirable.

Responsibilities

  • Define and maintain the enterprise IAM strategy, architecture, standards, and roadmap.
  • Lead the design and governance of identity services, including Identity Governance, Privileged Access Management, Authentication, Authorization, Federation, and Directory Services.
  • Develop secure identity architecture patterns and reference architectures for workforce, customer, third‑party, and machine identities.
  • Partner with engineering, cloud, application, and cybersecurity teams to embed identity controls into enterprise platforms and services.
  • Drive the adoption of Zero Trust principles, strong authentication, least privilege, and secure‑by‑design practices while providing architectural oversight and governance for strategic initiatives.

Skills

IAM domain
Security architecture
Strategic thinking
Leadership
Stakeholder management

Education

Degree in Computer Science, Information Security, Information Technology, Engineering, or related

Tools

Microsoft Entra ID
SailPoint
Saviynt
CyberArk
Okta
Ping Identity
ForgeRock

Job description

Who We Are Looking For

We are looking for an Enterprise Identity & Access Management Architect. You will be responsible for defining and driving the enterprise Identity & Access Management (IAM) strategy, architecture, standards, and governance across hybrid cloud, SaaS, and on-premises environments. You will partner with cybersecurity, technology, risk, and business stakeholders to deliver secure, scalable, and resilient identity capabilities that protect the firm while enabling business growth.

Who We Are Looking For

We are looking for an Enterprise Identity & Access Management Architect. You will be responsible for defining and driving the enterprise Identity & Access Management (IAM) strategy, architecture, standards, and governance across hybrid cloud, SaaS, and on-premises environments. You will partner with cybersecurity, technology, risk, and business stakeholders to deliver secure, scalable, and resilient identity capabilities that protect the firm while enabling business growth.

Why This Role Is Important To Us

The team you will be joining is part of the Security Architecture organization, a function that is critical to the firm's ability to securely deliver technology services, manage cybersecurity risk, and meet regulatory obligations. As identity remains a cornerstone of modern security and Zero Trust architectures, this role is responsible for establishing the strategic direction, governance, and architectural standards that protect enterprise identities, privileged access, and critical business services.

What You Will Be Responsible For
  • Define and maintain the enterprise IAM strategy, architecture, standards, and roadmap.
  • Lead the design and governance of identity services, including Identity Governance, Privileged Access Management, Authentication, Authorization, Federation, and Directory Services.
  • Develop secure identity architecture patterns and reference architectures for workforce, customer, third‑party, and machine identities.
  • Partner with engineering, cloud, application, and cybersecurity teams to embed identity controls into enterprise platforms and services.
  • Drive the adoption of Zero Trust principles, strong authentication, least privilege, and secure‑by‑design practices while providing architectural oversight and governance for strategic initiatives.
What We Value

These skills will help you succeed in this role

  • Strong security architecture and IAM domain expertise coupled with strategic thinking and sound risk‑based decision-making.
  • Demonstrated ability to influence enterprise‑wide technology and architecture decisions.
  • Strong leadership, communication, and stakeholder management skills.
  • Experience leading complex, large‑scale technology transformation programs across global organizations.
  • Ability to balance security, operational resilience, regulatory requirements, and business enablement through practical architectural solutions.
Education & Preferred Qualifications
  • Degree in Computer Science, Information Security, Information Technology, Engineering, or a related discipline.
  • 10+ years of experience in cybersecurity, security architecture, Identity & Access Management, or related technology disciplines.
  • Experience designing and implementing enterprise‑scale IAM solutions across cloud, SaaS, and on‑premises environments.
  • Deep understanding of Identity Governance & Administration (IGA), Privileged Access Management (PAM), Single Sign‑On (SSO), Multi‑Factor Authentication (MFA), and federated identity technologies.
  • Experience with leading IAM platforms including Microsoft Entra ID, SailPoint, Saviynt, CyberArk, Okta, Ping Identity, ForgeRock, or equivalent technologies.
  • Professional certifications such as CISSP, CCSP, TOGAF, SABSA, SailPoint, CyberArk, or equivalent security and IAM certifications are highly desirable.
Additional Requirements
  • Experience operating within highly regulated industries, preferably financial services.
  • Ability to work effectively with global teams and stakeholders across multiple regions.
  • Limited travel may be required based on business needs.
Work Requirement

Hybrid: Expected to work in accordance with State Street's hybrid work model.

Shift: Standard business hours with flexibility to support global stakeholders across multiple time zones.

Salary Range

$120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long‑term disability, and other optional additional coverages; paid‑time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance‑based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax‑advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work‑life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Job ID: R-793763

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Enterprise Identity & Access Management Architect
Enterprise Identity & Access Management Architect

State Street • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
Enterprise Identity & Access Management Architect
Enterprise Identity & Access Management Architect

STATE STREET CORPORATION • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
401K with company match
Insurance coverage
Paid time off
+3
Identity and Access Management Engineer
Identity and Access Management Engineer

State Street • Princeton (NJ)

On-site
USD 125,000 - 226,000
401K with company match
Medical, dental, vision
Paid time off
+1
Identity and Access Management Engineer
Identity and Access Management Engineer

State Street • Clifton (NJ)

On-site
USD 125,000 - 226,000
401K plan
Healthcare
Paid time off
IAM Business Analyst, Assistant Vice President
IAM Business Analyst, Assistant Vice President

State Street • Princeton (NJ)

On-site
USD 100,000 - 168,000
CIAM Senior Architect Manager, VP
CIAM Senior Architect Manager, VP

State Street • Clifton (NJ)

On-site
USD 125,000 - 226,000
Senior Data Security Architect
Senior Data Security Architect

State Street • Quincy (MA)

On-site
USD 120,000 - 202,500
401K with company match
Health insurance
Paid time off
+1
Senior Application Security Architect
Senior Application Security Architect

State Street • Clifton (NJ)

Hybrid
USD 120,000 - 203,000
401K with company match
Comprehensive benefits program
Paid time off
Senior Application Security Architect
Senior Application Security Architect

State Street • Austin (TX)

Hybrid
USD 120,000 - 203,000
401K match
Medical, dental, vision insurance
Paid time off
+1
Enterprise Identity & Access Management Architect
Enterprise Identity & Access Management Architect

Jobtailor • Massachusetts

On-site
USD 150,000 - 210,000