Identity and Access Management Architect – Manager
Salary Range: $104,500 – $213,800 per year.
At Crowe, you will partner with client stakeholders and Crowe leadership to define and drive identity and access management (IAM) strategy, architecture, and roadmaps across complex environments. This role combines strategic leadership with hands‑on solution design, engineering, and client engagement, enabling organizations to secure identities, support business objectives, and enhance user experience.
Key Responsibilities
- Lead IAM strategy development, roadmap creation, and reference architecture design aligned to client business objectives.
- Define and deliver enterprise IAM architecture, including authentication, authorization, identity lifecycle management, and privileged access management.
- Advise clients on Zero Trust principles and identity‑centric security strategies.
- Present IAM strategies, architectures, and findings to technical and executive stakeholders, including C‑suite leadership.
- Design and implement IAM solutions across cloud (Azure, AWS, GCP), on‑premises, and hybrid environments.
- Architect and integrate IAM platforms with enterprise applications, directories, APIs, and DevOps pipelines.
- Provide guidance on modern authentication and authorization approaches (SSO, MFA, passwordless, RBAC, ABAC).
- Lead or support implementation of modern identity and authorization platforms, including fine‑grained authorization and entitlement visibility solutions.
- Design and guide API‑driven integrations between IAM platforms and enterprise systems, leveraging REST‑based services and identity data flows.
- Lead or support implementation efforts, including identity governance, provisioning, access reviews, and privileged access controls.
- Partner with clients to accelerate onboarding and adoption of IAM and authorization capabilities, including requirements gathering, solution design, and enablement.
- Conduct IAM risk assessments, threat modeling, and control evaluations; support remediation and continuous improvement.
- Support regulatory compliance and alignment with frameworks such as NIST, ISO, CIS, and industry‑specific requirements.
- Apply IAM expertise within enterprise cybersecurity programs, collaborating across domains such as GRC, cloud security, and data protection.
- Collaborate with cross‑functional teams including security, cloud, application development, and risk/compliance.
Qualifications
Required Experience
- Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, Engineering, or related field.
- 7+ years of experience in IAM, cybersecurity architecture, or related roles (consulting or industry).
- Proven experience designing and implementing enterprise IAM solutions across cloud and hybrid environments.
- Strong knowledge of authentication and federation standards (OAuth2, OIDC, SAML, SCIM, LDAP).
- Experience with identity governance, privileged access management, and identity lifecycle processes.
- Hands‑on experience with leading IAM tools such as Entra ID (Azure AD), SailPoint, Saviynt, CyberArk, Ping Identity, Okta, or similar.
- Broad understanding of cybersecurity domains (risk management, IT controls, cloud security, compliance frameworks).
- Familiarity with Zero Trust principles and modern identity security approaches (MFA, passwordless, RBAC/ABAC).
- Experience with API‑based integrations and identity data flows (REST APIs, JSON, or similar patterns).
- Familiarity with scripting or automation (Python, SQL, or similar) to support identity integrations or data analysis.
- Experience supporting or leading IAM implementations, transformations, or program development efforts.
- Understanding of non‑human identities (service accounts, APIs, workloads, AI agents) and emerging identity considerations for AI/automation.
- Strong analytical, problem‑solving, and stakeholder management skills.
- Strong communication skills with the ability to translate technical concepts into business terms and engage with senior stakeholders.
- Professional certifications such as CISSP, CISM, CRISC, or IAM/vendor‑specific certifications.
Preferred Qualifications
- Experience in regulated industries (financial services, healthcare, government).
- Familiarity with AI/automation in cybersecurity or identity governance.
- Familiarity with workflow and governance platforms (ServiceNow), including support for identity‑related processes such as access requests, approvals, and risk/compliance workflows.
We expect the candidate to uphold Crowe's values of Care, Trust, Courage, and Stewardship. All individuals act with ethics and integrity at all times.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. Crowe is not sponsoring for work authorization at this time.
Crowe LLP provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, sexual orientation, gender identity or expression, genetics, national origin, disability or protected veteran status, or any other characteristic protected by federal, state or local laws.