Identity and Access Management Architect

Tata Consultancy Services

New York (NY)

Hybrid

USD 100,000 - 130,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Discretionary Incentive
Comprehensive Medical Coverage
Maternal & Parental Leaves
Identity Theft Protection
Commuter Benefits
Certification & Training Reimbursement

Job summary

Tata Consultancy Services in New York City offers an Identity and Access Management Architect role in a hybrid setting. The position requires extensive IAM and cloud security experience, including SSO/MFA, RBAC optimization, and automation of identity workflows across on‑prem and cloud environments.

You will engage with senior leadership to define security architecture, govern IAM strategy, and lead complex projects within a fast-paced enterprise.

Qualifications

  • In depth knowledge delivering IAM and cloud security capabilities in a hybrid hosting model.
  • RBAC controls optimization and certification based on segregation of duties / role.
  • Extensive knowledge of IAM technologies and protocols (SSO, MFA, Federation, PAM, OIDC, OAuth, SAML, and SCIM) and ability to automate / streamline identity workflow scenarios.
  • Knowledge of NIST CSF, HIPAA/HITECH security concepts and ability to review / perform security assessments.
  • Ability to work effectively under pressure in a fast-paced team setting.
  • Demonstrated capacity to acquire new skills and blend technical with business perspective.
  • Able to make decisions guided by precedent and policy.
  • Able to coordinate with others and handle controversial issues tactfully.
  • 10+ years in a technical services function in a complex distributed enterprise environment.
  • Hands-on experience managing IAM technologies and services (SailPoint IdentityIQ, Active Directory / EntraID).
  • Ability to automate complex access management policies for on‑prem and cloud apps.

Responsibilities

  • Define security architecture, design, and roadmap documents; present strategies to management.
  • Deliver complex customized IAM designs aligned to defense in depth strategies; collaborate with peers, vendors, and stakeholders.
  • Test and evaluate IAM technologies to inform broader security decisions with business and operational metrics.
  • Track developments in the security landscape to ensure applications are protected by existing controls.
  • Provide technical direction, scope, and quality metrics for security projects.
  • Set baseline security configuration standards for operating systems, apps, network, and IAM usage.
  • Enable resolution of complex security and IAM issues throughout project lifecycles.
  • Collaborate across technical, customer, and management groups to ensure timely service delivery.
  • Perform additional duties as assigned.

Skills

IAM technologies
SSO MFA SAML
RBAC optimization
NIST CSF HIPAA
Identity workflow automation
EntraID/Azure AD
Security architecture
Leadership & collaboration
Cloud security
Technical services experience

Tools

SailPoint IdentityIQ
Active Directory / EntraID

Job description

Role - Identity and Access Management Architect
Location - New York City - Hybrid
Type of hire - Full Time
Job Description
Must Have Technical/Functional Skills
  • In depth knowledge delivering IAM and cloud security capabilities in a hybrid hosting model.
  • Optimize RBAC controls and map workflows for individuals / groups and perform certification based on segregation of duties / role.
  • Extensive knowledge of IAM technologies and protocols (SSO, MFA, Federation, PAM, OIDC, OAuth, SAML, and SCIM) and the ability to automate / streamline identity workflow scenarios.
  • Knowledge of NIST CSF, Health Insurance Portability and Accountability Act (HIPAA)/Health Information Technology for Economic and Clinical Health (HITECH) security concepts where capable of reviewing / performing security assessments for project solutions.
  • Ability to work effectively under pressure and function in a fast-paced collaborative team setting.
  • Demonstrated capacity to acquire new skills efficiently and ability to blend technical expertise and business perspective.
  • Able to make logical decisions regarding the best method to accomplish goals or solve a problem and is guided by precedent and general policy in making decisions.
  • Able to coordinate and obtain cooperation with others and to handle controversial issues tactfully.
  • At least ten (10) years of experience in a technical services function in a complex distributed enterprise network and application environment.
  • Hands-on experience in managing and designing IAM technologies and services (e.g. SailPoint IdentityIQ, Active Directory / EntraID IAM solutions in a large environment is required.
  • Ability to automate complex access management and authentication policies for on-prem and cloud hosted applications at an expert level required.
  • Skilled at collaborating with peers and socializing IAM governance and strategy with senior leadership and executives.
  • Working knowledge of Microsoft Purview, Azure IaaS security and data protection controls (e.g. data loss, encryption, conditional access, data classification).
  • Experienced in the following areas: security architecture, design, implementation, and integration management for full stack IT infrastructure (applications, scripting, databases, operating systems, hardware, IP network, and test planning in a dynamic continuous improvement environment.
Generic Managerial Skills
  • Responsible for the evaluation, architecture and delivery of advanced technology solutions while demonstrating a high degree financial awareness and consideration of final objectives.
  • Determine requirements, develop, and recommend security solutions, capabilities, and controls that are aligned with business objectives, technology, and threat drivers.
  • Evaluate, assess, and recommend improvements to statements of work and proposals from vendors to ensure that adequate security protections are in place for security-rel ated deficiencies and required "user controls," and report any findings to the CISO and vendor management teams.
  • Develop and maintain security architecture, design, and roadmap documents. Develop and present detailed strategies, designs, and implementation plans to management.
  • Deliver complex customized designs and solutions aligned to defense in depth strategies by self and by collaborating with peers, vendors, and stakeholders.
  • Test, evaluate, and review security technologies, tools, and services aligned to business goals and make recommendations to the broader security team for their use based on security, financial and operational metrics.
  • Track developments and changes in the digital business and threat environments to ensure that the YNHHS healthcare applications' landscape is adequately protected by existing security controls.
  • Responsible for setting technical direction, scope, quality metrics, planning, execution and closing of technical projects.
  • Determine baseline security configuration standards for operating systems, applications, network segmentation, and identity and access management.
  • Provide high level of technical skill to enable resolution of complex security and identity and access related technology problems throughout the project lifecycle.
  • Work collaboratively across technical, customer, and management constituencies to ensure quality and timely service delivery.
  • Perform other job duties and responsibilities as assigned.
Salary Range: $100,000-$130,000 a year
TCS Employee Benefits Summary
  • Discretionary Annual Incentive.
  • Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
  • Family Support: Maternal & Parental Leaves.
  • Insurance Options: Auto & Home Insurance, Identity Theft Protection.
  • Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement.
  • Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Identity Architect
AI Identity Architect

Tata Consultancy Services • Chicago (IL)

On-site
USD 130,000 - 140,000
Discretionary Annual Incentive
Comprehensive Medical Coverage
Family Support
+4
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • Frankfort (KY)

On-site
USD 86,400 - 138,600
IAM/PAM Architect
IAM/PAM Architect

Tata Consultancy Services • New York (NY)

On-site
USD 120,000 - 130,000
Discretionary Annual Incentive
Medical Coverage
Parental Leaves
+3
Senior Security Advisor, Identity
Senior Security Advisor, Identity

MRO • United States

On-site
USD 120,000 - 150,000
Annual cash bonus
Comprehensive benefits offering
401(k) plan
IAM Architect
IAM Architect

Tata Consultancy Services • Alpharetta (GA)

On-site
USD 120,000 - 130,000
Discretionary incentive
Comprehensive medical coverage
Family support leaves
+5
Identity Access Management (IAM) Architect
Identity Access Management (IAM) Architect

Casella Waste Systems, Inc. • Rutland (VT)

On-site
USD 115,000 - 145,000
Medical, Dental, Vision
401K
Parental Leave
+1
Cybersecurity Engineer
Cybersecurity Engineer

SSA Marine • Seattle (WA)

Hybrid
USD 130,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+11
IAM Security Architect
IAM Security Architect

Cambia Health Solutions • Portland (OR)

Hybrid
USD 140,000 - 175,000
Medical, dental, and vision coverage
Annual employer contribution to health savings account
Generous paid time off
+3
Identity & Access Management Specialist (Active Directory • Microsoft Entra ID • CyberArk) - Hybrid
Identity & Access Management Specialist (Active Directory • Microsoft Entra ID • CyberArk) - Hybrid

M&T Bank • Wilmington (DE)

Hybrid
USD 62,000 - 104,000
Sr Cybersecurity Engineer
Sr Cybersecurity Engineer

Fairview Health Services • Minneapolis (MN)

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+3