Principal Cybersecurity Architect – Identity, IAM & Zero Trust

World Wide Technology, Inc.

Northern (KY)

Hybrid

USD 160,000 - 200,000

Full time

43 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health & Wellness benefits
Profit Sharing
401k with company matching
PTO & Holidays
Tuition Reimbursement

Job summary

World Wide Technology (WWT) seeks a Principal Cybersecurity Architect to own IAM, Zero Trust, and enterprise security across identity, access management, and data protection. You will influence architecture decisions, mentor engineers, and collaborate with stakeholders to reduce risk and improve security posture.

The role emphasizes design of trust models, SSO standards, and CIEM governance across cloud platforms, with a focus on leadership without formal authority.

Qualifications

  • 8+ years in information security, with 4+ years in an architecture or senior engineering role
  • Proven track record building trusted relationships with business and technical stakeholders
  • Demonstrated ability to influence outcomes and gain buy-in without formal authority
  • Experience facilitating workshops, requirements-gathering sessions, or architecture reviews
  • Excellent written and verbal communication skills
  • Deep expertise in Zero Trust frameworks and identity-centric security
  • Strong understanding of threat modeling methods
  • Hands-on experience with enterprise IAM platforms
  • Strong grasp of federation protocols: SAML 2.0, OIDC, OAuth 2.0
  • Experience with PAM platforms and secrets management
  • Familiarity with CIEM tooling and cloud IAM governance
  • Experience designing identity lifecycle and IGA processes
  • Certifications preferred: CISSP, SABSA, TOGAF, Microsoft SC-100, Okta Certified Architect

Responsibilities

  • Act as a trusted advisor to IT, infrastructure, and business stakeholders
  • Build and maintain relationships across engineering, business units, and executive leadership
  • Lead discovery sessions, workshops, and architecture reviews
  • Translate complex risk into business language and recommendations
  • Mentor security engineers on architecture standards and communications
  • Navigate competing priorities to build consensus on security decisions
  • Design and mature a Zero Trust architecture spanning identity, device trust, network access, and app security
  • Define reference architectures, security patterns, and guardrails
  • Lead threat modeling and security architecture reviews for major changes
  • Evaluate and select security tooling aligned to architecture strategy
  • Drive continuous improvement of Zero Trust posture through maturity modeling
  • Own the enterprise IAM architecture and lifecycle management
  • Define authentication assurance levels and roadmap toward phishing-resistant MFA
  • Lead the PAM architecture and secret management effort
  • Govern cloud entitlements through a CIEM framework
  • Establish non-human identity strategy and governance
  • Drive identity governance processes and joiner/mover/leaver automation
  • Define security architecture standards and governance artifacts
  • Contribute to security roadmap and budgeting

Skills

Zero Trust
IAM
NIST SP 800-207
BeyondCorp
SAML 2.0
OIDC
OAuth 2.0
STRIDE
PASTA
ATT&CK
Microsoft Entra ID
Okta
Ping Identity
SCIM
CISSP
SABSA
TOGAF
PAM
HashiCorp Vault
AWS Secrets Manager
Azure Key Vault

Tools

CyberArk
BeyondTrust
Delinea
HashiCorp Vault
AWS Secrets Manager
Azure Key Vault

Job description

Principal Cybersecurity Architect – Identity, IAM & Zero Trust

#26-2788

Remote - Nationwide, United States

Eligible Work Locations

Remote - Nationwide , United States

This is a full-time direct hire position. We are not able to offer visa sponsorship, 1099 status, or work with C2C for this role.

World Wide Technology (WWT) strives to make a new world happen. WWT's work benefits clients and partners as much as it does its people and community across the globe. Founded in 1990, WWT brings together strategy, deep technical expertise and world-class partnerships to help public and private sector organizations design, build and scale intelligent AI, digital, cybersecurity, cloud and infrastructure solutions. Through its Advanced Technology Center (ATC)—a collaborative ecosystem featuring state-of-the-art hardware and software—WWT enables clients and partners to conceptualize, test and validate innovative technology and then deploy solutions at scale using its global integration and distribution capabilities. With more than 14,000 team members and over 60 locations globally, WWT's culture—grounded in core values and leadership philosophies—has been recognized by Fortune® and Great Place to Work for its commitment to innovation, trust and creating a great place to work for all. WWT provides products and services to large enterprise, global service provider and public sector clients in up to 130 countries across six continents. Softchoice, a World Wide Technology company, supports commercial and SMB markets in the U.S. and Canada. Want to work with highly motivated individuals on high-performance teams? Join WWT today! What is the Internal WWT IT Team, and why join ? The Internal WWT IT team is the backbone of our company’s technological infrastructure, ensuring seamless operations and continuous innovation. Our team is dedicated to managing and supporting the company’s technology infrastructure, ensuring the smooth operation of hardware, software, networks, and data systems, while providing top-notch technical support to employees . By joining the Internal WWT IT team, you will play a crucial role in maintaining the efficiency and security of our IT environment, enabling the company to achieve its strategic goals. The Internal IT team offers the opportunity to work in a dynamic and collaborative environment, where your contributions will have a direct impact on the company's success. If you are passionate about technology and eager to take on new challenges, we encourage you to apply and join our team. WWT Information Security is looking for a Principal Cybersecurity Architect to own the enterprise security architecture across identity, access management, and Zero Trust. This is a senior individual contributor role with significant influence over how people, machines, and workloads authenticate, authorize, and access resources across our environment. This role requires strong people skills as well as architectural expertise . We seek someone with deep technical knowledge and a consultative mindset — someone who builds trust , listens before offering solutions, and guides IT, business, and executive stakeholders toward shared decisions on identity and Zero Trust strategy. Strong candidates will have a proven record as trusted advisors , not merely implementers .

Stakeholder Engagement & Consulting

  • Act as a trusted advisor to IT, infrastructure, and business stakeholders - understanding their goals and constraints, then shaping security architecture decisions around them rather than dictating from a purely technical standpoint
  • Build and maintain relationships across engineering, business units, and executive leadership to earn buy-in for Zero Trust and IAM initiatives, particularly where they require behavior change or short-term friction
  • Lead discovery sessions, workshops, and architecture reviews that bring together technical and non-technical stakeholders, and know how to adapt the conversation for each audience
  • Translate complex, technical risk into business language and actionable recommendations for executives and nontechnical decision-makers
  • Mentor and guide security engineers on both architecture standards and how to communicate design decisions persuasively to stakeholders
  • Navigate competing priorities and organizational politics to build consensus on security architecture decisions, relying on influence and credibility rather than authority

Zero Trust Architecture

  • Design and mature a Zero Trust architecture (ZTNA, MFA, PAM) spanning identity, device trust, network access, and application security - grounded in NIST SP 800-207 and BeyondCorp principles
  • Define reference architectures, security patterns, and guardrails consumed across engineering and infrastructure teams
  • Lead threat modeling and security architecture reviews for major platform changes and initiatives
  • Evaluate and select security tooling (SASE, SSE, ZTNA, NDR, EDR) aligned to the overall architecture strategy
  • Drive continuous improvement of Zero Trust posture through gap assessments and maturity modelling

Identity & Access Management (IAM)

  • Own the enterprise IAM architecture - covering workforce identity, B2B federation, machine identities, and cloud entitlements
  • Design and govern identity lifecycle management: provisioning, role assignment, access reviews, and deprovisioning - ensuring least privilege is enforced by default and not by exception
  • Architect federation and SSO standards across the enterprise: SAML 2.0, OIDC, OAuth 2.0 - including integrations with third-party SaaS, partner tenants, and customer-facing portals
  • Define authentication assurance levels by resource sensitivity, aligning MFA requirements to NIST AAL2/AAL3 - with a clear roadmap toward phishing-resistant MFA (FIDO2/ WebAuthn ) for privileged and high-risk access
  • Lead the PAM architecture - credential vaulting, just-in-time privilege, session recording, and endpoint privilege management - in partnership with the security operations team
  • Govern cloud entitlements across AWS, Azure, and GCP through a CIEM framework: identify over-permissioned roles, enforce least privilege for service principals and IAM roles, and manage cross-account trust relationships
  • Establish and maintain a non-human identity strategy: service accounts, API keys, application credentials, and pipeline secrets - eliminating hardcoded credentials and enforcing dynamic secrets via a secrets management platform
  • Drive identity governance processes: access certification campaigns, segregation of duties ( SoD ) controls, and role-based access control (RBAC) model design
  • Partner with HR, IT, and business application owners to ensure joiner/mover/leaver processes are automated and auditable

Governance & Architecture Standards

  • Define security architecture standards, policies, and exception management processes
  • Serve as the escalation point for complex identity and access design decisions
  • Produce architecture artefacts — threat models, data flow diagrams, trust zone maps — suitable for both technical and executive audiences
  • Contribute to the security roadmap and annual planning, translating risk priorities into architectural investments

Qualifications

  • 8+ years in information security, with 4+ years in an architecture or senior engineering role
  • Proven track record , building trusted relationships with business and technical stakeholders - including direct experience acting as a consultant or advisor, whether internally or with clients
  • Demonstrated ability to influence outcomes and gain buy-in without formal authority, navigating competing priorities across engineering, business, and leadership
  • Experience facilitating workshops, requirements-gathering sessions, or architecture reviews with mixed technical and non-technical audiences
  • Excellent written and verbal communication skills - able to translate complex architecture into clear guidance for engineers, business stakeholders, and executives alike
  • Deep expertise in Zero Trust frameworks (NIST SP 800-207, BeyondCorp ) and identity-centric security
  • Strong understanding of threat modeling methodologies (STRIDE, PASTA, ATT&CK) and their application to identity attack surfaces
  • Hands-on experience with enterprise IAM platforms - Microsoft Entra ID, Okta, Ping Identity, or equivalent
  • Strong grasp of federation protocols: SAML 2.0, OIDC, OAuth 2.0, SCIM
  • Experience with PAM platforms (CyberArk, BeyondTrust , Delinea ) and secrets management ( HashiCorp Vault, AWS Secrets Manager, Azure Key Vault)
  • Familiarity with CIEM tooling and cloud IAM governance across at least two major cloud platforms
  • Experience designing and governing identity lifecycle and IGA processes (SailPoint, Saviynt, or equivalent a plus)
  • Certifications (preferred) : CISSP, SABSA, TOGAF, Microsoft SC-100, Okta Certified Architect, or equivalent

Certain states and localities require employers to post a reasonable estimate of the salary range. A reasonable estimate of the current base pay range for this position is $1 59 , 6 00 to $1 99 , 5 00 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that are not included in the bas e pay.

The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:

  • Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
  • Financial Benefits : Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
  • Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring
  • Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program

Note: This is not an all-encompassing list and should not be used as a complete description of the plan’s benefits. For more information, see our US Benefits Website

We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for all!

If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process. World Wide Technology is an Equal Opportunity Employer.

WWT is an Equal Opportunity Employer

Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status or other characteristics protected by law. We are committed to working with and providing reasonable accommodations to individuals with disabilities. If you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application, please call 1-800-432-7008 and ask for Human Resources.

Applicants to and employees of most private employers, state and local governments, educational institutions, employment agencies and labor organizations are protected under Federal law from discrimination.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Solutions Architect (Data)
Solutions Architect (Data)

World Wide Technology, Inc. • Northern (KY)

Hybrid
USD 111,000 - 139,000
Health and Wellbeing
Financial Benefits
PTO & Holidays
+2
Senior Application Security Engineer
Senior Application Security Engineer

World Wide Technology • Maryland Heights (MO)

On-site
USD 116,000 - 145,000
Health insurance
401k with company matching
Paid time off
+3
Senior Application Security Engineer
Senior Application Security Engineer

World Wide Technology, Inc. • Northern (KY)

Hybrid
USD 116,000 - 145,000
Health and Wellbeing
401k with Company Matching
Paid Time Off
+2
Senior AI Security Engineer
Senior AI Security Engineer

World Wide Technology • Maryland Heights (MO)

On-site
USD 116,000 - 145,000
Health and Wellbeing
401k Plan with Company Matching
Paid Time Off
+1
Consulting Systems Engineer (Southern California) - Network
Consulting Systems Engineer (Southern California) - Network

World Wide Technology, Inc. • San Diego (CA), Northern (KY)

Hybrid
USD 150,000 - 200,000
Health and Wellbeing benefits
401k with company match
Paid time off
Consulting Systems Engineer - Web Services
Consulting Systems Engineer - Web Services

World-Wide-Technology • San Francisco (CA)

On-site
USD 150,000 - 210,000
Health and Wellness
Profit Sharing
401k Matching
+1
Solutions Architect (Data)
Solutions Architect (Data)

World Wide Technology • United States

On-site
USD 111,000 - 166,000
Health and Wellbeing
Profit Sharing
401k with Company Matching
+3
Cyber Sales Specialist-- Global Financials
Cyber Sales Specialist-- Global Financials

World-Wide-Technology • New York (NY)

Hybrid
USD 200,000 - 215,000
Health and Vision Care
401k with Company Matching
Paid Time Off
+1
Cyber Security Sales Specialist
Cyber Security Sales Specialist

World Wide Technology, Inc. • Northern (KY)

Hybrid
USD 130,000 - 160,000
Health & Dental
401k with company match
PTO & Holidays
+1
Sr Manager, Digital Architecture
Sr Manager, Digital Architecture

World Wide Technology, Inc. • Northern (KY)

Hybrid
USD 150,000 - 188,000
Health, dental & vision coverage
401(k) with company matching
Paid time off (PTO)
+2