IAM Architect

HUB International

Chicago (IL)

Hybrid

USD 120,000 - 150,000

Full time

46 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Life insurance
Disability insurance
401(k)

Job summary

HUB International is seeking an IAM Architect to design, build, and evolve our enterprise identity and access management program across cloud, SaaS, and on-prem environments. You will translate security requirements into reference architectures and roadmaps.

The role emphasizes leadership, governance, and collaboration with cybersecurity, infrastructure, and application teams, with a hybrid Chicago-office setup and a salary range of $120k–$150k.

Qualifications

  • 7+ years IAM experience with at least 3 years in architecture/leadership.
  • Proven experience designing and implementing enterprise IGA/IAM solutions.
  • Strong understanding of Zero Trust architecture and security frameworks.
  • Experience integrating IAM platforms with HR systems and ITSM tools.

Responsibilities

  • Lead the IAM/IGA architecture across enterprise environments.
  • Define architecture standards, governance models, and best practices.
  • Design scalable identity lifecycle processes including Joiner, Mover, and Leaver workflows.
  • Architect integrations with AD, Azure Entra ID, Workday, ServiceNow, LDAP, SAP and cloud platforms.
  • Maintain IAM diagrams, roadmaps, and as-built documentation.
  • Mentor engineers and lead governance discussions.

Skills

Zero Trust
IAM architecture
Enterprise IAM
Stakeholder communication
Mentoring engineers

Education

Bachelor’s degree in technology or security

Tools

SailPoint ISC
IdentityNow
Saviynt
Azure AD/Entra ID
Active Directory

Job description

At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.

HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions

Job Description

We are seeking an experienced IAM Architect to design, build, and evolve our enterprise Identity and Access Management (IAM) program. This role oversees and drives the IAM architectural standards for authentication, authorization, provisioning, and privileged access across cloud, SaaS, and on-premises environments. You will translate business and security requirements into reference architectures, technical standards, and multi-year roadmaps that support workforce, and privileged identities.

The ideal candidate has deep hands-on experience with modern IAM/IGA platforms (e.g., SailPoint Identity Security Cloud/IdentityNow, Okta, Azure AD/Entra ID, or similar), a strong understanding of Zero Trust principles, and a track record of leading identity initiatives that reduce risk, complexity, and operational cost while improving the end-user experience.

Objectives of this Role
  • Develop and maintain the enterprise IAM framework, including authentication, authorization, provisioning, and privileged access systems.
  • Rationalize identity platforms and standardize integration patterns to reduce complexity, cost, and operational risk.
  • Ensure high availability, resilience, and audit readiness of identity services.
  • Improve onboarding/offboarding (Joiner-Mover-Leaver) efficiency and reduce identity-related security incidents such as credential compromise or orphaned accounts.
  • Serve as the technical leader for IAM initiatives, driving scalable identity architecture and governance standards across cloud and on-prem environments.
  • Ensure identity operations practices provide a sound foundation that utilizes tools and processes for rapid identification of security events to address and mitigate risks.
  • Engage with peers regularly on security operations functions, project status, activities, and achievements.
  • Lead "Continuous Improvement" efforts, in respect to HUB’s information security identity tooling and systems.
  • Lead/Assist in plan, organize, and execute multiple responsibilities to achieve project goals and provide technical leadership to move operational projects to completion.
  • Contribute to security requirements, standards, procedures, and reference architectures to comply with policies and technical standards.
Daily and Monthly Responsibilities
  • Lead the architecture, design, implementation and integration of IAM/IGA solutions (e.g., SailPoint ISC) across enterprise environments.
  • Define IAM architecture standards, governance models, and best practices.
  • Design scalable identity lifecycle processes including Joiner, Mover, and Leaver workflows.
  • Architect integrations with Active Directory, Azure AD/Entra ID, Workday, ServiceNow, LDAP, SAP, cloud platforms, and REST APIs.
  • Maintain all IAM architectural diagrams, as-built documentation, and roadmaps.
  • Lead application onboarding, provisioning, deprovisioning, and access certification initiatives.
  • Provide architecture guidance for compliance, audit readiness, and regulatory requirements (e.g., SOX, HIPAA, GDPR, PCI-DSS).
  • Collaborate with cybersecurity, infrastructure, cloud, and application teams to align IAM strategy with enterprise security goals.
  • Mentor engineers, developers, and analysts on IAM platform best practices and technical standards.
  • Participate in roadmap planning, technical governance, and solution architecture reviews.
  • Support Agile delivery, sprint planning, and technical design workshops.
Skills and Qualifications
  • Bachelor’s degree in technology, Security, or equivalent experience.
  • 7+ years of experience in identity and access management, with at least 3 years in an architecture or technical leadership role.
  • Proven experience designing and implementing enterprise IGA/IAM solutions (e.g., SailPoint ISC/IdentityNow, Saviynt, or similar).
  • Experience with access certifications, provisioning workflows, lifecycle management, and governance controls.
  • Strong understanding of Zero Trust architecture and enterprise security frameworks.
  • Expertise with IGA platforms, Active Directory, EntraID, LDAP, SSO, RBAC, Rest APIs and/or JSON / XML.
  • Expertise with SAML, OIDC, oAuth, and SCIM.
  • Experience integrating IAM platforms with HR systems (e.g., Workday), ITSM tools (e.g., ServiceNow, JIRA), business applications, and cloud platforms (AWS, Azure, GCP).
  • Solid understanding of compliance and audit requirements related to identity and access.
  • Excellent communication skills, with the ability to translate technical concepts for both technical and non-technical stakeholders.
  • Experience mentoring engineers and leading technical governance discussions.
  • Familiarity with Agile delivery methodologies.
  • Knowledge of industry security standards, guidelines, and regulatory/compliance requirements related to information security such as ISO 27001, NIST 800-53, SOC2, PCI, SOX, etc.
  • This position reports into Chicago and is hybrid.
  • Willingness to travel up to 10% of working time.
JOIN OUR TEAM

Do you believe in the power of innovation, collaboration, and transformation? Do you thrive in a supportive and client focused work environment? Are you looking for an opportunity to help build and drive change in a rapidly growing and evolving organization? When you join HUB International, you will be part of a community of learners and doers focused on our Core Values: entrepreneurship, teamwork, integrity, accountability, and service.

The expected salary range for this position is $ 120,000 to $150,000 and will be impacted by factors such as the successful candidate’s skills, experience and working location, as well as the specific position’s business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays. In addition, eligible annual bonuses, equity and commissions may be available for some positions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Privilege Access Management Engineer
Privilege Access Management Engineer

HUB International • Chicago (IL)

On-site
USD 100,000 - 120,000
Comprehensive benefits package
Lead IAM Engineer
Lead IAM Engineer

Blue Cross and Blue Shield of Massachusetts, Inc. • Boston (MA)

On-site
USD 163,000 - 200,000
Paid time off
Medical insurance
Dental insurance
+2
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)

Koitecc Solutions • Washington, Northern (KY)

On-site
USD 140,000 - 200,000
Benefits eligible
Discretionary incentive plan
IAM Architect
IAM Architect

Compunnel, Inc. • Chicago (IL)

On-site
USD 150,000 - 180,000
Sr. IAM Engineer
Sr. IAM Engineer

IDMWORKS • Oregon (WI)

Hybrid
USD 115,000 - 160,000
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)

Bank of America • Boston (MA)

On-site
USD 140,000 - 200,000
Discretionary incentive eligibility
Industry-leading benefits
Software Architect (Python)
Software Architect (Python)

HUB International • Minneapolis (MN), Saint Paul (MN)

On-site
USD 170,000 - 193,000
Health insurance
401(k) and retirement benefits
Paid time off and holidays
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)

Bank of America • Denver (CO)

On-site
USD 140,000 - 200,000
Industry-leading benefits
Paid time off
Support for professional growth
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)
Identity and Access Management (IAM) Senior Consultant (Cloud experience required)

Bank of America • Washington

On-site
USD 140,000 - 200,000
Industry-leading benefits
Discretionary annual performance bonus
Senior IAM Engineer
Senior IAM Engineer

xAI • Washington

On-site
USD 100,000 - 258,000
Equity
Medical coverage
Vision and dental
+4