Principal IAM/PAM Security Architect

Talanto

Northern (KY)

Hybrid

USD 160,000 - 190,000

Full time

14 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Talanto is seeking a Principal IAM/PAM Security Architect to define and evolve security architecture for identity and privileged access across AD, Entra ID, Okta, and multi-cloud identities (AWS, Azure, GCP, OCI). You will lead standards for Agentic Identity and Delinea PAM, owning secrets governance enterprise-wide.

You will collaborate with identity, cloud, and application teams to ensure controls are auditable, scalable, and aligned with SOX, HIPAA, PCI, and ISO 27001.

Qualifications

  • Bachelors degree in technology discipline or equivalent professional experience.
  • 8+ years of experience in identity and access management, privileged access management, or security architecture roles, including experience across large, complex enterprise environments.
  • Demonstrated experience designing security standards across hybrid identity environments (Active Directory, cloud IAM, and SaaS identity providers).
  • Hands-on experience with a PAM platform (Delinea preferred) at an architecture or lead engineering level.
  • Enterprise Identity Platforms: Active Directory (multi-domain/forest architectures), Microsoft Entra ID, and Okta, including federation, conditional access, and hybrid identity synchronization.
  • Cloud IAM: Identity and access models across AWS, Azure, GCP, and OCI, including IAM roles/policies, workload identity, federation, and cross-cloud access patterns.
  • Agentic & Non-Human Identity: AI agent architectures, service/workload identities, and emerging standards for non-human identity governance.
  • Delinea PAM & Secrets Management: Hands-on experience with Secret Server and Privilege Manager, plus broader vaulting technologies (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager) and secrets-detection tooling.
  • Authentication & Authorization Protocols: Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA.
  • Security & Compliance Frameworks: SOX, HIPAA, PCI DSS, and ISO 27001 as applied to identity, privileged access, and secrets controls.
  • Automation & DevOps Integration: PowerShell, Python, and REST APIs for identity/PAM/secrets lifecycle automation; experience embedding these controls into CI/CD pipelines and infrastructure-as-code (Terraform, ARM, CloudFormation).
  • Strong analytical and architectural problem-solving skills, with the ability to translate complex, multi-domain identity environments into clear standards and communicate architecture and risk decisions to technical and business stakeholders.
  • Relevant security certifications preferred (e.g., CISSP, CISM, SABSA, CCSP).

Responsibilities

  • Identity Architecture & Standards: Define and maintain security architecture and standards across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity (AWS, Azure, GCP, OCI), covering authentication, authorization, and lifecycle controls.
  • Serve as the architectural authority for identity security decisions, aligning platform and cloud teams to enterprise standards across a large, complex identity environment.
  • Lead architecture reviews and risk assessments for new identity integrations, platform migrations, and M&A activity.
  • Agentic Identity Standards: Define enterprise standards for Agentic Identity — governance, lifecycle, authentication, and authorization for AI agents and other non-human identities, including provisioning, scoped entitlements, and deprovisioning.
  • Track the evolving agentic AI and non-human identity landscape and advise leadership on emerging risks, standards, and vendor capabilities.
  • Delinea PAM & Secrets Management: Define security requirements for and lead enterprise-wide implementation of the Delinea PAM platform (Secret Server, Privilege Manager).
  • Design privileged access controls - least privilege, JIT/JEA, session monitoring, credential rotation - across on-premises and cloud environments, and oversee onboarding of privileged accounts and systems.
  • Produce audit-ready evidence of PAM controls aligned to frameworks such as SOX, HIPAA, PCI, and ISO 27001.
  • Secrets Governance: Own enterprise policy and lifecycle standards for all secrets - API keys, OAuth/OATH tokens, service account credentials, and certificates - including vaulting, rotation, and secure distribution.
  • Drive detection and remediation of hardcoded, unmanaged, or leaked secrets across source code, configuration, and CI/CD pipelines.
  • Establish metrics and reporting to track secrets governance maturity and compliance across the organization.
  • Governance & Collaboration: Participate in and help lead architecture review boards, governance forums, and risk committees for identity and privileged access.
  • Maintain reference architectures, standards documentation, and roadmaps for identity, PAM, and secrets governance.
  • Advise stakeholders on identity risk and control design for new initiatives, and mentor engineers implementing identity, PAM, and secrets solutions.
  • Complete all responsibilities as outlined in the annual performance review and/or goal setting.
  • Complete all special projects and other duties as assigned.
  • Must be able to perform duties with or without reasonable accommodation.

Skills

Identity architecture
Security analytics
CI/CD integration

Education

Bachelor's degree in technology or equivalent experience
8+ years IAM/PAM/security architecture experience

Tools

Delinea PAM
Secret Server
Privilege Manager
HashiCorp Vault
AWS Secrets Manager
Azure Key Vault
GCP Secret Manager
Terraform

Job description

Important: if an employer asks you to log into their system via iCloud or Google, send a code, an SMS or Telegram password, run some code, or install software - refuse. These are signs of fraud.

Overview

The Principal IAM/PAM Security Architect defines and evolves security architecture for identity and privileged access across a large, complex, multi-domain environment spanning Active Directory, Microsoft Entra ID, and Okta, as well as cloud-native identities across AWS, Azure, GCP, and OCI.

This role sets security standards for each identity environment, leads the definition of emerging Agentic Identity standards for AI agents and other non-human identities, defines requirements for and drives implementation of the Delinea PAM platform, and owns secrets governance enterprise-wide - including API keys, OAuth/OATH tokens, service account credentials, and certificates. The architect partners closely with identity, cloud, and application teams to keep controls consistent, auditable, and scalable.

Responsibilities
  • Identity Architecture & Standards: Define and maintain security architecture and standards across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity (AWS, Azure, GCP, OCI), covering authentication, authorization, and lifecycle controls.
  • Serve as the architectural authority for identity security decisions, aligning platform and cloud teams to enterprise standards across a large, complex identity environment.
  • Lead architecture reviews and risk assessments for new identity integrations, platform migrations, and M&A activity.
  • Agentic Identity Standards: Define enterprise standards for Agentic Identity — governance, lifecycle, authentication, and authorization for AI agents and other non-human identities, including provisioning, scoped entitlements, and deprovisioning.
  • Track the evolving agentic AI and non-human identity landscape and advise leadership on emerging risks, standards, and vendor capabilities.
  • Privileged Access Management (Delinea): Define security requirements for and lead enterprise-wide implementation of the Delinea PAM platform (Secret Server, Privilege Manager).
  • Design privileged access controls - least privilege, JIT/JEA, session monitoring, credential rotation - across on-premises and cloud environments, and oversee onboarding of privileged accounts and systems.
  • Produce audit-ready evidence of PAM controls aligned to frameworks such as SOX, HIPAA, PCI, and ISO 27001.
  • Secrets Governance: Own enterprise policy and lifecycle standards for all secrets - API keys, OAuth/OATH tokens, service account credentials, and certificates - including vaulting, rotation, and secure distribution.
  • Drive detection and remediation of hardcoded, unmanaged, or leaked secrets across source code, configuration, and CI/CD pipelines.
  • Establish metrics and reporting to track secrets governance maturity and compliance across the organization.
  • Governance & Collaboration: Participate in and help lead architecture review boards, governance forums, and risk committees for identity and privileged access.
  • Maintain reference architectures, standards documentation, and roadmaps for identity, PAM, and secrets governance.
  • Advise stakeholders on identity risk and control design for new initiatives, and mentor engineers implementing identity, PAM, and secrets solutions.
  • Complete all responsibilities as outlined in the annual performance review and/or goal setting.
  • Complete all special projects and other duties as assigned.
  • Must be able to perform duties with or without reasonable accommodation.

This job description is intended to describe the general nature and level of work being performed and is not to be construed as an exhaustive list of responsibilities, duties and skills required. This job description does not constitute an employment agreement and is subject to change as the needs of •••••••• and requirements of the job change.

Qualifications
  • Bachelor's degree in a technology discipline or equivalent professional experience.
  • 8+ years of experience in identity and access management, privileged access management, or security architecture roles, including experience across large, complex enterprise environments.
  • Demonstrated experience designing security standards across hybrid identity environments (Active Directory, cloud IAM, and SaaS identity providers).
  • Hands‑on experience with a PAM platform (Delinea preferred) at an architecture or lead engineering level.
  • Enterprise Identity Platforms: Active Directory (multi-domain/forest architectures), Microsoft Entra ID, and Okta, including federation, conditional access, and hybrid identity synchronization.
  • Cloud IAM: Identity and access models across AWS, Azure, GCP, and OCI, including IAM roles/policies, workload identity, federation, and cross‑cloud access patterns.
  • Agentic & Non‑Human Identity: AI agent architectures, service/workload identities, and emerging standards for non‑human identity governance.
  • Delinea PAM & Secrets Management: Hands‑on experience with Secret Server and Privilege Manager, plus broader vaulting technologies (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager) and secrets‑detection tooling.
  • Authentication & Authorization Protocols: Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA.
  • Security & Compliance Frameworks: SOX, HIPAA, PCI DSS, and ISO 27001 as applied to identity, privileged access, and secrets controls.
  • Automation & DevOps Integration: PowerShell, Python, and REST APIs for identity/PAM/secrets lifecycle automation; experience embedding these controls into CI/CD pipelines and infrastructure‑as‑code (Terraform, ARM, CloudFormation).
  • Strong analytical and architectural problem‑solving skills, with the ability to translate complex, multi‑domain identity environments into clear standards and communicate architecture and risk decisions to technical and business stakeholders.
  • Relevant security certifications preferred (e.g., CISSP, CISM, SABSA, CCSP).
Cognitive /Mental Requirements:
  • Communicating with others to exchange information.
  • Assessing the accuracy, neatness, and thoroughness of the work assigned.
  • Problem‑solving and thinking critically.
  • Completing tasks independently.
  • Making timely decisions in the context of a workflow.
  • Maintaining focus.
Physical Requirements and Working Conditions:
  • Must be able to provide high‑speed internet access / connectivity and office setup and maintenance.
  • Must be able to provide a dedicated, secure work area.
  • Remaining in a stationary position, often standing or sitting for prolonged periods.
  • Repeating motions that may include the wrists, hands, and/or fingers.
  • No adverse environmental conditions expected.

Base compensation ranges from $160,000 to $190,000 per year. Specific offers are determined by various factors, such as experience, education, skills, certifications, and other business needs. This role is eligible for discretionary bonus consideration.

•••••••• offers team members a competitive benefits package to address a wide range of personal and family needs, including medical, dental, vision, disability, and life insurance coverage, 401(k) savings plans, paid family leave, 9 paid holidays per year, and 17-27 days of Paid Time Off (PTO) per year, depending on specific level and length of service with •••••••• . For information about our benefits package, please refer to our Careers page.

Date of Posting: 9/04/2026

We anticipate that the application window will close on 11/04/2026, but the application window may change depending on the volume of applications received or close immediately if a qualified candidate is selected.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal IAM/PAM Security Architect
Principal IAM/PAM Security Architect

Cotiviti • Northern (KY)

Hybrid
USD 160,000 - 190,000
Medical
Dental
Vision
+6
VP, Privileged Access Management (PAM) Engineer - Delinea Secret Server
VP, Privileged Access Management (PAM) Engineer - Delinea Secret Server

Synchrony • New York (NY)

On-site
USD 135,000 - 230,000
IAM/PAM Architect
IAM/PAM Architect

Tata Consultancy Services • New York (NY)

On-site
USD 120,000 - 130,000
Discretionary Annual Incentive
Medical Coverage
Parental Leaves
+3
Senior Identity Application Architect, CIAM/IAM
Senior Identity Application Architect, CIAM/IAM

AHEAD • Chicago (IL)

On-site
USD 140,000 - 200,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
PAM Security Architect
PAM Security Architect

Compunnel, Inc. • Westlake (OH)

On-site
USD 120,000 - 150,000
Information Technology Security Engineer
Information Technology Security Engineer

IZAR Associates, Inc. • United States

Hybrid
USD 100,000 - 130,000
Senior Product Manager - Vault & Secrets
Senior Product Manager - Vault & Secrets

Delinea • Northern (KY)

Hybrid
USD 120,000 - 160,000
Competitive salaries
Bonus program
Excellent benefits
+6
Principal Software Engineer (Identity Services)
Principal Software Engineer (Identity Services)

INSPYR Solutions • Beverly Hills (CA)

Hybrid
USD 180,000 - 240,000
Staff Identity Governance and Access Engineer
Staff Identity Governance and Access Engineer

United States Digital Space LLC • Washington

On-site
USD 180,000 - 230,000
Senior Privileged Access Management Specialist -IT (Hybrid)
Senior Privileged Access Management Specialist -IT (Hybrid)

Intact Insurance Group • Farmington (CT)

Hybrid
USD 111,000 - 148,000
Comprehensive medical, dental and vision insurance
401(k) savings with annual contributions
Mental health support and paid parental leave