Identity and Access Management Architect

Deloitte France

Philadelphia (Philadelphia County)

On-site

USD 150,000 - 210,000

Full time

13 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Deloitte Technology seeks a Senior IAM Architect to define and drive the enterprise IAM strategy across on-prem, cloud, and hybrid environments, collaborating with senior leadership and product teams to secure identities and improve user experience across digital channels.

You will lead architecture design, oversee risk assessments, mentor staff, and coordinate with security, product, and engineering to deliver scalable IAM solutions while balancing security and usability, in a fast-paced,

Qualifications

  • 10+ years of IAM experience with progressive technical leadership.
  • Proven track record delivering enterprise IAM across cloud and on-prem.
  • Deep knowledge of authentication/authorization protocols and modern IAM architectures.
  • Hands-on with two major IAM technologies (Entra ID/Azure AD, CyberArk, SailPoint, Ping Identity).
  • Strong stakeholder management and ability to present to executives.
  • Advanced degree and/or certifications (CISSP, CISM, SABSA, TOGAF).
  • Experience with zero-trust, identity governance, PAM, and modern auth modalities.
  • Experience in high-regulation industries is a plus.
  • Ability to balance strategic thinking with hands-on delivery.
  • Identity Providers / Directories: Entra ID/Azure AD, Microsoft AD
  • Identity Governance and PAM: SailPoint, CyberArk
  • Authentication & Federation: Ping Identity, OAuth2/OIDC, SAML
  • Cloud & DevOps integration: AWS/Azure/GCP identity services, CI/CD tooling

Responsibilities

  • Partner with Senior IAM leadership to define enterprise IAM architecture and roadmaps.
  • Engage in executive conversations, translate business goals into IAM requirements.
  • Lead technical design for authentication, authorization, provisioning, and privileged access.
  • Champion IAM innovation and balance security with usability.
  • Architect secure integrations between IAM platforms and apps, directories, and cloud services.
  • Oversee risk assessments, threat modeling, and remediation with security/compliance teams.
  • Lead incident response coordination and post-incident analysis for identity incidents.
  • Drive adoption through technical guidance, diagrams, and executive briefings.
  • Collaborate with product, engineering, and business leaders to prioritize the roadmap and measure outcomes.
  • Ensure compliance with applicable standards and regulations.

Skills

IAM Architecture
Leadership
Stakeholder Management
Zero Trust
Identity Governance
Cloud/On-Prem
RBAC/ABAC
MFA/SSO
OAuth2/OIDC
SAML

Education

Advanced degree (MS)
CISSP/CISM/SABSA

Tools

Entra ID/Azure AD
Microsoft AD
CyberArk
SailPoint
Ping Identity

Job description

Work you'll do

We are seeking a Senior Manager-level IAM Architect to partner with Senior IAM leadership team to define and drive the technical strategy and architecture for Identity and Access Management (IAM) across the organization. This role combines strategic leadership, hands‑on solution design with product owners, and senior level stakeholder engagement, to secure identities, enable business objectives, and improve user experience across digital channels. This individual must have a pulse on the emerging identity technology trends and best practices to coordinate with Product Owners for integrated IAM architectures and roadmaps.

Core Responsibilities
  • Partner with Senior IAM leadership team to define and own the enterprise IAM architecture, strategy, reference patterns, and roadmaps across authentication, authorization, identity lifecycle, privileged access, and account protection.

  • Engage in executive level leadership conversations, translate business goals into IAM requirements, coordinate with IAM product owners on technical feasibility to ensure solutions scale and interoperate across on‑premises, cloud, and hybrid environments.

  • Partner with IAM product technical leads to assist with technical design and implementation for authentication (e.g. MFA, SSO, etc), authorization models (e.g. RBAC, ABAC, etc), identity provisioning, lifecycle management, and privileged access controls.

  • Champion innovation with Identity and Access Management tools, evaluate and provide recommendations to product owners for consideration and integration with the existing platform, while balancing security, privacy, and usability.

  • Architect secure integrations between IAM platforms and applications, directories, cloud services, and CI/CD pipelines, set standards and reusable patterns for developers.

  • Partner with IAM Sr. Leadership team and IAM product technical leads to address IAM risk assessments, threat modeling, and remediation strategies, partner with security, risk, and compliance teams to implement controls and measure risk reduction.

  • Partner with IAM product technical leads to oversee incident response activities as they relate to identity compromise, and lead post‑incident root‑cause analysis and remediation.

  • Drive adoption: create technical guidance, architecture diagrams, and executive‑level briefings, mentor architects and senior engineers on IAM best practices.

  • Collaborate with product, engineering, and business leaders to prioritize roadmap items, measure outcomes (security posture, access‑related incidents, time‑to‑provision), and demonstrate business value.

  • Ensure compliance

The team

Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in what is but rather what can be to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

Qualifications

Do you possess the following?:

  • 10+ years of IAM experience with progressive technical leadership, experience in a consulting or large enterprise environment preferred.

  • Proven track record designing, delivering, and operating enterprise‑scale IAM solutions across cloud and on‑prem environments.

  • Deep technical knowledge of authentication/authorization protocols and standards (OAuth2/OIDC, SAML, SCIM, LDAP) and modern IAM architectures.

  • Hands‑on experience with at least two major IAM technologies (e.g., Entra ID/Azure AD, Microsoft AD, CyberArk, SailPoint, Ping Identity).

  • Strong stakeholder management and communication skills, able to present technical concepts to executive audiences and translate business needs into technical requirements.

  • Experience leading vendors, technical teams, and cross‑functional workstreams to successful outcomes.

  • Advanced degree (MS) or certifications (e.g., CISSP, CISM, SABSA, TOGAF, vendor‑specific IAM certs).

  • Experience with zero‑trust identity models, identity governance, privileged access management, and modern authentication modalities (passwordless, biometrics, adaptive MFA).

  • Prior experience building IAM programs or working in high‑regulation industries (finance, healthcare, government).

  • Balance strategic thinking with the ability to roll up sleeves and deliver technically where needed.

  • Identity Providers / Directories: Entra ID/Azure AD, Microsoft AD

  • Identity Governance and PAM: SailPoint, CyberArk

  • Authentication & Federation: Ping Identity, OAuth2/OIDC, SAML, SCIM

  • Cloud & DevOps integration: AWS/Azure/GCP identity services, CI/CD tooling

Limited immigration sponsorship may be available.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity and Access Management Architect
Identity and Access Management Architect

Deloitte France • Jacksonville (FL)

On-site
USD 140,000 - 190,000
IAM Architect
IAM Architect

KTek Resourcing • Dallas (TX)

On-site
USD 120,000 - 150,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Sr. Identity & Access Management (IAM) Engineer
Sr. Identity & Access Management (IAM) Engineer

NKC Health • Kansas City (MO)

On-site
USD 100,000 - 130,000
Enterprise Identity & Access Management Architect
Enterprise Identity & Access Management Architect

State Street • Clifton (NJ)

Hybrid
USD 120,000 - 203,000
401K with company match
Insurance coverage including medical,
Paid time off
IAM Architect
IAM Architect

Compunnel, Inc. • Chicago (IL)

On-site
USD 150,000 - 180,000
Enterprise Identity & Access Management Architect
Enterprise Identity & Access Management Architect

State Street • Quincy (MA)

On-site
USD 120,000 - 203,000
IAM Architect
IAM Architect

Conexess Group • Farmington Hills (MI)

On-site
USD 130,000 - 170,000
Manager – Identity & Access Management (IAM)
Manager – Identity & Access Management (IAM)

Fynetra • Boston (MA)

On-site
USD 120,000 - 150,000
Enterprise Identity & Access Management Architect
Enterprise Identity & Access Management Architect

State Street • Berwyn (PA)

Hybrid
USD 120,000 - 203,000
Hybrid work model