In this Lead Identity Security Architect role, you will direct enterprise Identity Security efforts across IGA, ITDR, PAM, and Policy-Based Access Control (PBAC). The position emphasizes architecture, integration, and operationalization of identity risk detection and response capabilities using leading identity security platforms.
Location
New York, NY (onsite)
Responsibilities
- Lead enterprise Identity Security initiatives spanning IGA, ITDR, PAM, and PBAC capabilities.
- Define and execute the Identity Security strategy, roadmap, architecture, and implementation approach in alignment with business and security objectives.
- Provide architectural oversight and technical leadership for SailPoint Identity Security Cloud (ISC), CrowdStrike Identity Protection, and related Identity Security platforms.
- Design and implement identity risk signal integrations across SailPoint ISC, CrowdStrike Identity Protection, Active Directory, Microsoft Entra ID, PAM solutions, and existing security platforms.
- Develop and operationalize identity threat detection and response to surface account compromise, privilege escalation, lateral movement, insider threats, and credential abuse.
- Lead detection engineering, including use case design, correlation logic, monitoring content development, alert tuning, and optimization.
- Drive SIEM integrations to improve identity-centric threat analytics, monitoring, dashboards, and threat-hunting capabilities.
- Establish workflow automation, orchestration, and response mechanisms to accelerate identity-related incident remediation.
- Support PBAC model implementation, including access governance frameworks, entitlement management, and risk-based access controls.
- Lead PAM onboarding, integration, governance, monitoring, and operational processes for enterprise privileged accounts.
- Partner with executive stakeholders and governance forums to deliver program updates, risk visibility, and strategic guidance.
- Create and maintain operational runbooks, playbooks, architecture documentation, testing plans, and transition-to-support deliverables.
Requirements
- 8+ years of experience in Identity & Access Management (IAM), Identity Governance, Cybersecurity Architecture, or Identity Security Engineering.
- Deep expertise in SailPoint Identity Security Cloud (ISC) implementation, integration, governance, and access lifecycle management.
- Hands-on experience with CrowdStrike Identity Protection and ITDR capabilities, including identity risk monitoring.
- Strong understanding of Privileged Access Management solutions such as CyberArk, BeyondTrust, Delinea, or equivalent.
- Experience implementing identity security controls using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, and modern federation protocols.
- Expertise in identity threat detection, incident response, threat hunting, and security monitoring use case development.
- Experience integrating IAM, IGA, PAM, Active Directory, Entra ID, and SIEM platforms in enterprise environments.
- Strong knowledge of policy-based access control, role management, identity governance, and compliance requirements.
- Experience delivering in Agile environments and leading cross-functional security transformation initiatives.
- Excellent stakeholder management, executive communication, technical leadership, and governance experience.
- Relevant certifications in SailPoint, CyberArk, SC-300, CISSP, CISM, or equivalent identity and security technologies are highly desirable.
Technologies
- SailPoint Identity Security Cloud (ISC)
- CrowdStrike Identity Protection
- Privileged Access Management (CyberArk)
- BeyondTrust
- Delinea
- SAML
- OAuth 2.0
- OpenID Connect (OIDC)
- SCIM
- Active Directory
- Microsoft Entra ID
- SIEM
- CyberArk
- SC-300
- CISSP
- CISM
Compensation
The annual salary for this position is USD 114,500 - 134,000, depending on experience and other qualifications. This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.
Benefits
- Medical/Dental/Vision/Life Insurance
- Paid holidays plus Paid Time Off
- 401(k) plan and contributions
- Long-term/Short-term Disability
- Paid Parental Leave
- Employee Stock Purchase Plan
Application Deadline
Applications will be accepted until 30 Sep 2026.