IAM Architect

Arrowstreet Capital, Limited Partnership

Boston (MA)

On-site

USD 181,000 - 244,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Arrowstreet Capital, a Boston-based investment firm, seeks a senior Identity Management and IGA Architect to define and execute the firm’s long-term identity strategy, governance model, target-state architecture, and technology roadmap.

This role combines strategic leadership with hands-on delivery as you assess current Identity Provider and IGA landscapes, close gaps, and architect a next-generation, secure identity platform across the enterprise.

Qualifications

  • Demonstrated experience defining enterprise Identity and Access Management strategies, architectures, operating models in complex environments.
  • Experience evaluating, selecting, and implementing identity technologies, including leading platform assessments, proof-of-concepts, vendor evaluations, and architecture review processes.
  • Proven ability to influence and partner with senior technology, cybersecurity, risk, compliance, and business stakeholders to drive identity transformation initiatives and align identity capabilities with organizational objectives.
  • Proven experience leading or supporting identity and IGA transformation programs in a large enterprise environment.
  • Strong hands-on knowledge of IGA capabilities, including access request, approval workflows, provisioning, deprovisioning, joiner/mover/leaver processes, entitlement management, access certification, role-based access control, and application onboarding.
  • Experience with major IGA platforms such as SailPoint, Saviynt, Omada, One Identity, Microsoft Entra ID Governance, or equivalent solutions.
  • Deep technical knowledge of Microsoft Entra ID, on-premises Active Directory, AWS IAM, Kerberos, LDAP, federation, and hybrid identity environments.
  • Strong understanding of OpenID Connect, OAuth 2.0, SAML, delegated authorization, On-Behalf-Of flows, and service-to-service authentication.
  • Experience with non-human identity management, including service accounts, workload identities, machine identities, API identities, secret management, ownership models, and lifecycle controls.
  • Experience with AI agentic workload identity, permission delegation, and autonomous or automated access patterns is strongly preferred.
  • Strong understanding of SOC1 controls, audit readiness, access governance, privileged access controls, and identity-related risk management.
  • Prior experience in a similar identity architecture, IGA, or security leadership role in another enterprise firm.

Responsibilities

  • Define and lead the firm's Identity and Access Management strategy, target-state architecture, operating model, and multi-year roadmap across identity governance, access management, privileged access, and non-human identities.
  • Evaluate, select, and implement identity technologies and platforms, leading architecture reviews, technology assessments, proof-of-concepts, and vendor selection initiatives to support evolving business, security, and regulatory requirements.
  • Establish enterprise identity standards, governance frameworks, and success metrics, while partnering with technology and business leaders to drive adoption, manage risk, and continuously mature the firm's identity capabilities.
  • Own and lead the firm’s Identity Management, Identity Provider, and Identity Governance & Administration strategy and roadmap.
  • Assess current identity solutions, IGA processes, access models, legacy integrations, and control gaps across the firm.
  • Architect the next-generation identity and IGA framework covering human identities, non-human identities, privileged accounts, service accounts, workload identities, API identities, and AI agentic workload identities.
  • Define and implement governance standards for joiner/mover/leaver processes, access requests, approvals, provisioning, deprovisioning, entitlement management, access reviews, and role models.
  • Design modern authentication, authorization, federation, and delegation patterns using technologies such as OpenID Connect, OAuth 2.0, SAML, Kerberos, LDAP, Microsoft Entra ID, AWS IAM, Active Directory, and Secret Management platforms.
  • Establish governance and lifecycle controls for non-human identities, including ownership, risk classification, access review, secret rotation, and least-privilege enforcement.
  • Design identity patterns for On-Behalf-Of workflows, delegated permissions, service-to-service access, application impersonation, and AI/agent-based access scenarios.
  • Lead the smooth migration of legacy applications and systems to the next-generation Identity Provider and IGA architecture.
  • Partner with IT stakeholders to understand current challenges and define practical, secure, and scalable identity solutions.
  • Own and improve SOC1-related controls for Identity Provider and IGA processes, including audit evidence, control documentation, access reviews, and remediation tracking.
  • Remain hands-on in building and implementing identity solutions, integrations, workflows, standards, and proof-of-concepts.

Skills

Identity Management
Identity Governance
Architecture Leadership
Stakeholder Collaboration
OpenID Connect
OAuth 2.0
SAML
SOC1 Controls

Tools

SailPoint
Saviynt
Omada
One Identity
Microsoft Entra ID Governance
Microsoft Entra ID
AWS IAM
Active Directory

Job description

We are seeking a senior Identity Management and Identity Governance & Administration (IGA) Architect to define and execute the firm's long-term identity strategy, governance model, target-state architecture, and technology roadmap.

This individual will serve as the firm's identity subject matter expert, partnering with technology, cybersecurity, risk, compliance, audit, and business stakeholders to modernize the organization's identity capabilities and establish identity as a foundational security control across the enterprise.

This role will assess the current Identity Provider and IGA landscape, including existing solutions, use cases, legacy systems, access governance processes, entitlement models, and application integrations. The candidate will identify what is working well, where gaps and risks exist, and define a clear path toward a modern, secure, scalable next-generation Identity Provider and IGA framework.

This is a highly visible role requiring both strategic leadership and hands-on execution. The successful candidate will architect and help build the next-generation identity platform, manage the transition from legacy systems, strengthen SOC1-related identity controls, and partner closely with IT, security, cloud, application, infrastructure, risk, compliance, and audit stakeholders.

Responsibilities
  • Define and lead the firm's Identity and Access Management strategy, target-state architecture, operating model, and multi-year roadmap across identity governance, access management, privileged access, and non-human identities.
  • Evaluate, select, and implement identity technologies and platforms, leading architecture reviews, technology assessments, proof-of-concepts, and vendor selection initiatives to support evolving business, security, and regulatory requirements.
  • Establish enterprise identity standards, governance frameworks, and success metrics, while partnering with technology and business leaders to drive adoption, manage risk, and continuously mature the firm's identity capabilities.
  • Own and lead the firm’s Identity Management, Identity Provider, and Identity Governance & Administration strategy and roadmap.
  • Assess current identity solutions, IGA processes, access models, legacy integrations, and control gaps across the firm.
  • Architect the next-generation identity and IGA framework covering human identities, non-human identities, privileged accounts, service accounts, workload identities, API identities, and AI agentic workload identities.
  • Define and implement governance standards for joiner/mover/leaver processes, access requests, approvals, provisioning, deprovisioning, entitlement management, access reviews, and role models.
  • Design modern authentication, authorization, federation, and delegation patterns using technologies such as OpenID Connect, OAuth 2.0, SAML, Kerberos, LDAP, Microsoft Entra ID, AWS IAM, Active Directory, and Secret Management platforms.
  • Establish governance and lifecycle controls for non-human identities, including ownership, risk classification, access review, secret rotation, and least-privilege enforcement.
  • Design identity patterns for On-Behalf-Of workflows, delegated permissions, service-to-service access, application impersonation, and AI/agent-based access scenarios.
  • Lead the smooth migration of legacy applications and systems to the next-generation Identity Provider and IGA architecture.
  • Partner with IT stakeholders to understand current challenges and define practical, secure, and scalable identity solutions.
  • Own and improve SOC1-related controls for Identity Provider and IGA processes, including audit evidence, control documentation, access reviews, and remediation tracking.
  • Remain hands-on in building and implementing identity solutions, integrations, workflows, standards, and proof-of-concepts.
Requirements
  • Demonstrated experience defining enterprise Identity and Access Management strategies, architectures, operating models in complex environments.
  • Experience evaluating, selecting, and implementing identity technologies, including leading platform assessments, proof-of-concepts, vendor evaluations, and architecture review processes.
  • Proven ability to influence and partner with senior technology, cybersecurity, risk, compliance, and business stakeholders to drive identity transformation initiatives and align identity capabilities with organizational objectives.
  • Proven experience leading or supporting identity and IGA transformation programs in a large enterprise environment.
  • Strong hands-on knowledge of IGA capabilities, including access request, approval workflows, provisioning, deprovisioning, joiner/mover/leaver processes, entitlement management, access certification, role-based access control, and application onboarding.
  • Experience with major IGA platforms such as SailPoint, Saviynt, Omada, One Identity, Microsoft Entra ID Governance, or equivalent solutions.
  • Deep technical knowledge of Microsoft Entra ID, on-premises Active Directory, AWS IAM, Kerberos, LDAP, federation, and hybrid identity environments.
  • Strong understanding of OpenID Connect, OAuth 2.0, SAML, delegated authorization, On-Behalf-Of flows, and service-to-service authentication.
  • Experience with non-human identity management, including service accounts, workload identities, machine identities, API identities, secret management, ownership models, and lifecycle controls.
  • Experience with AI agentic workload identity, permission delegation, and autonomous or automated access patterns is strongly preferred.
  • Strong understanding of SOC1 controls, audit readiness, access governance, privileged access controls, and identity-related risk management.
  • Prior experience in a similar identity architecture, IGA, or security leadership role in another enterprise firm.

The base salary range for this position is $128,000 - $297,000 per year.

Arrowstreet Capital operates a robust talent acquisition program, and we also seek to compensate and reward our employees competitively within our industry and in line with our merit-based culture. Our approach to total compensation includes base salaries and annual discretionary bonuses, as well as a robust benefits package. The determination of a successful candidate’s base salary placement within the listed range will vary based on the candidate’s relevant experience and qualifications (which may also include relevant certifications, credentials and other education), the job responsibilities and scope, the commensurate resulting level of the position and other relevant factors. The listed range is also an estimate, and additional information regarding base salary and other elements of total compensation offered by Arrowstreet Capital to successful applicants will be communicated during the recruitment process.

Arrowstreet Capital is a Boston-based systematic investment firm that manages global equity portfolios for institutional investors around the world.

All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, ancestry, genetic information, age, pregnancy, medical condition, disability, veteran or military status, marital status or any other characteristic protected by federal, state, or local law.

  • Arrowstreet Capital is committed to working with and providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you need a reasonable accommodation for any part of the employment process due to a disability, contact us to discuss the nature of your request and contact information.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technology Risk and Governance
Technology Risk and Governance

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 110,000 - 315,000
Competitive compensation
Discretionary bonuses
Robust benefits package
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Arrowstreet Capital • Boston (MA)

On-site
USD 110,000 - 315,000
Senior Software Engineer, Investment Systems
Senior Software Engineer, Investment Systems

Arrowstreet Capital • Boston (MA)

On-site
USD 115,000 - 325,000
Investment Analytics Engineer
Investment Analytics Engineer

arrowstreetcapital • Boston (MA)

On-site
USD 100,000 - 215,000
Competitive salary
Annual bonus
Benefits package
Identity Access Professional
Identity Access Professional

Arrow Financial Corporation • City of Glens Falls (NY)

On-site
USD 75,000 - 85,000
Competitive compensation
Medical, dental, and vision insurance
401(k) and pension plans
+2
Identity Access Professional
Identity Access Professional

What’s Upstate • City of Glens Falls (NY)

On-site
USD 75,000 - 85,000
Medical Insurance
Tuition Reimbursement
Retirement Plans
+2
Senior IAM Architect: Next-Gen Identity & IGA Leader
Senior IAM Architect: Next-Gen Identity & IGA Leader

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 181,000 - 244,000
Senior Software Engineer, Investment Systems
Senior Software Engineer, Investment Systems

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 115,000 - 325,000
Annual discretionary bonuses
Robust benefits package
Senior Identity and Access Engineer
Senior Identity and Access Engineer

Morgan, Lewis & Bockius LLP • Pennsylvania

Hybrid
USD 120,000 - 150,000
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)

Bank of America • Boston (MA)

On-site
USD 140,000 - 200,000
Discretionary incentive eligibility
Industry-leading benefits