IAM Lead Architect

Nationmind

New Jersey

Hybrid

USD 180,000 - 210,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Nationmind is seeking an Onsite IAM Lead Architect to own end-to-end IAM delivery for the customer environment, focusing on Microsoft Entra ID, SailPoint, and Delinea. The role blends management, architecture, engineering, and operations with strong governance and reporting responsibilities.

Responsibilities include establishing IAM strategy, onboarding applications, and managing identity governance across HR and downstream systems, while coordinating with vendors and stakeholders.

Qualifications

  • Minimum 10 years of cyber security, IAM, directory services, or enterprise security operations experience.
  • Minimum 5 years of hands-on Microsoft Entra ID / Azure AD with strong admin and engineering capability.
  • Strong hands-on experience in Entra SSO, MFA, CA, Identity Protection, B2B/B2C, SCIM, SAML, OAuth, OIDC integrations.
  • Proven experience with SailPoint Identity Governance and Delinea PAM including lifecycle management and RBAC.

Responsibilities

  • Lead IAM product strategy, governance, and stakeholder management with delivery accountability.
  • Design and operate Microsoft Entra ID capabilities including SSO, MFA, and CA policies.
  • Onboard applications using OAuth, OpenID Connect, SAML, LDAP, and SCIM.
  • Develop design documents, runbooks, SOPs, and knowledge articles for IAM solutions.
  • Oversee Privileged Access Management and PAM operations, including vaulting and rotation.
  • Coordinate vendor relations and IAM delivery governance with stakeholders.

Skills

Microsoft Entra ID
SailPoint IGA
Delinea PAM
OAuth / OIDC / SAML
Active Directory / Hybrid Identity
PowerShell scripting
ITSM & ServiceNow
Documentation & Governance

Education

Bachelor degree in Computer Science / IT / Cyber Security
Master degree or equivalent certification (preferred)

Tools

SailPoint
Delinea PAM
LDAP/AD tooling
ServiceNow

Job description

Role: Onsite IAM Lead Architect
Location: Union Beach, NJ 07735
Duration: 1 Year

Hybrid Role (must be on-site 3 times a week)

Role Overview

The IAM Product Manager / Lead Architect will own end-to-end Identity and Access Management support and delivery for the customer environment, with primary focus on Microsoft Entra ID. The role is a blend of managerial, product ownership, architecture, engineering, and operational support responsibilities.
The selected resource must be capable of independently managing IAM initiatives and operations across Microsoft Entra ID, SailPoint, and Delinea without requiring day-to-day guidance from the customer. The position requires strong technical depth, stakeholder communication, vendor coordination, and delivery governance.

Key Responsibilities
Product Strategy, Governance and Stakeholder Management

Develop and execute a comprehensive IAM product strategy and vision that consistently delivers value to customers and improves user satisfaction.
Assist senior management with planning and scoping of IT and security initiatives related to Identity and Access Management.
Establish, monitor, and report key success metrics including cost, feature functionality, risk posture, reliability, adoption, and operational performance.
Ensure accurate capacity reporting to support demand projections, optimize resource utilization, and enable timely delivery of IAM initiatives.
Provide timely progress reporting to stakeholders, including achievements, delivery risks, dependencies, and mitigation strategies.

Microsoft Entra ID Engineering and Operations

Design, implement, and manage Microsoft Entra ID capabilities including SSO, MFA, Conditional Access, Identity Protection, B2B, B2C, custom domains, and application integrations.
Develop, implement, and manage integrations with Entra Single Sign-On, SCIM provisioning, Conditional Access rules, authentication policies, and sign-in policies.
Develop password, sign-on, and MFA policies, rules, and procedures for users and applications based on business and security requirements.
Create authentication and multifactor policies based on network zones, routing rules, risk posture, and business use cases.
Understand and provide solutions for Active Directory and legacy authentication protections including LDAP, Kerberos, NTLM, and hybrid identity requirements.

Application Onboarding and Technical Solutioning

Conduct and attend technical discussion sessions with application vendors, development teams, and application owners to identify suitable IAM security solutions.
Work with standard security protocols including OAuth, OpenID Connect, SAML, LDAP, and SCIM for application onboarding and integrations.
Contribute to requirement gathering, solution design, design documentation, and implementation planning for Identity, Access, and PAM solutions.
Create and maintain design documents, SOPs, runbooks, knowledge articles, operational handover documents, and support procedures.

Identity Governance and SailPoint

Manage Identity Governance and Administration activities including lifecycle management, provisioning, de-provisioning, access request, RBAC, and access certification.
Work with HR Service Center and HR IT teams to maintain integrations between HR, IAM, and downstream target systems.
Support identity governance processes such as role-based access control, access request workflows, access reviews, certification campaigns, and audit evidence reporting.

Privileged Access Management and Delinea

Manage PAM operations using Delinea, including privileged account onboarding, vaulting, password rotation, access control, and session governance.
Integrate PAM solutions with LDAP providers, Windows servers, UNIX/Linux servers, databases, network devices, middleware, and custom applications.
Troubleshoot PAM components and operational issues including access failure, authentication issue, session issue, connector issue, and integration issue.
Maintain IAM and PAM servers, services, agents, connectors, patching, upgrades, and platform health.

Operational Support, Vendor Management and Documentation

Provide expert-level technical support to operations teams including ServiceNow, Wintel, HRIT, Office 365, Digital Workspace, application teams, and knowledge acquisition teams.
Manage documentation for problems, known errors, root cause analysis, and vendor resolution tracking.
Work with application vendors and internal teams to resolve incidents, problems, defects, and integration issues.
Support IAM service operations, platform reliability, incident response, change execution, and continuous improvement activities.

Technical / Functional Skills Skill Area Required Competencies

Microsoft Entra ID - Primary Hands-on expertise in Entra ID administration, SSO, MFA, Conditional Access, Identity Protection, B2B, B2C, custom domains, access reviews, SCIM provisioning, application integrations, and hybrid identity support.
SailPoint IGA Experience with lifecycle management, provisioning, de-provisioning, access request, RBAC, certification campaigns, reconciliation, role governance, and audit support.
Delinea PAM Practical experience with privileged account management, vaulting, password rotation, session monitoring, platform integrations, troubleshooting, and operations support.
Identity Protocols Strong understanding of OAuth, OpenID Connect, SAML, LDAP, Kerberos, NTLM, SCIM, federation, advanced authentication, and legacy authentication protections.
Directory Services Active Directory, enterprise directory architecture, virtual directories, hybrid identity, directory consolidation, and M&A directory integration support.
Automation / Scripting PowerShell automation, REST API usage, report extraction, operational automation, and support scripting for IAM activities.
ITSM and Operations Experience with ServiceNow or equivalent ITSM tools for incident, service request, change, problem, and audit evidence management.
Documentation and Governance Ability to create HLD, LLD, SOP, KB articles, runbooks, access governance documents, risk reports, and stakeholder progress reports.

Mandatory Skills

Minimum 10 years of cyber security, IAM, directory services, or enterprise security operations experience.
Minimum 5 years of hands-on Microsoft Entra ID / Azure AD experience with strong administration and engineering capability.
Strong hands-on experience in Entra SSO, MFA, Conditional Access, Identity Protection, B2B, B2C, SCIM, SAML, OAuth, and OIDC integrations.
Experience with SailPoint Identity Governance including lifecycle management, provisioning, RBAC, access request, and certification.
Experience with Delinea PAM including privileged access onboarding, credential vaulting, password rotation, session monitoring, and troubleshooting.
Ability to manage IAM operations, stakeholder communication, technical workshops, reporting, vendor coordination, and delivery risks independently.
Good understanding of Active Directory, LDAP, Kerberos, NTLM, hybrid identity, directory architecture, and legacy authentication protection.
PowerShell scripting experience for IAM reporting, support automation, and operational tasks.
Excellent documentation, communication, and customer-facing skills.

Preferred Skills / Certifications

Microsoft Certified: Identity and Access Administrator Associate (SC-300).
Microsoft Certified: Cybersecurity Architect Expert (SC-100).
SailPoint IdentityIQ / Identity Security Cloud certification or equivalent implementation experience.
Delinea Certified Administrator or equivalent PAM administration experience.
CISSP, CISM, CCSP, or other relevant security certifications.
Experience supporting M&A identity integration, directory consolidation, Zero Trust initiatives, and enterprise IAM modernization.

Managerial Skills

Ability to independently lead customer discussions, technical workshops, and IAM governance forums.
Strong product ownership mindset with roadmap planning, prioritization, backlog management, and value delivery focus.
Capacity planning, demand forecasting, resource utilization tracking, and delivery governance.
Risk management, issue resolution, stakeholder reporting, executive communication, and escalation management.
Ability to mentor operational teams and guide application teams during onboarding and integration activities.

Education

Bachelor degree in Computer Science, Information Technology, Cyber Security, or related discipline.
Master degree or equivalent professional certification is preferred

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Architect
IAM Architect

Conexess Group • Farmington Hills (MI)

On-site
USD 130,000 - 170,000
Senior IAM Engineer – Entra ID, AD
Senior IAM Engineer – Entra ID, AD

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Identity and Access Management Architect
Identity and Access Management Architect

Deal Exchange, LLC • Southfield (MI)

Hybrid
USD 110,000 - 140,000
Sr. Identity & Access Management (IAM) Engineer
Sr. Identity & Access Management (IAM) Engineer

NKC Health • Kansas City (MO)

On-site
USD 100,000 - 130,000
IAM Lead Architect - Entra ID & PAM Strategy (Hybrid)
IAM Lead Architect - Entra ID & PAM Strategy (Hybrid)

Nationmind • New Jersey

Hybrid
USD 180,000 - 210,000
Identity and Asset Management Architect
Identity and Asset Management Architect

Vortalsoft Inc • New Jersey

On-site
USD 120,000 - 150,000
Sr Identity and Access Management Analyst
Sr Identity and Access Management Analyst

Chicago Bridge & Iron Company • The Woodlands (TX)

On-site
USD 100,000 - 130,000
Infrastructure Engineer
Infrastructure Engineer

Huxley • Boston (MA)

On-site
USD 120,000 - 150,000
Sr. IAM Engineer, Infrastructure Services
Sr. IAM Engineer, Infrastructure Services

Scorpion Therapeutics • Bridgewater (MA)

On-site
USD 120,000 - 180,000