Senior Identity & Access Architect

OEC

United States

Hybrid

USD 140,000 - 190,000

Full time

4 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

OEC is seeking an experienced identity security architect to design, implement, and evolve enterprise IAM platforms supporting on-prem, hybrid, and cloud environments. You will ensure secure access with the right identities at the right time, collaborating with security engineering, infrastructure, cloud and HR teams.

You will lead the design of hybrid AD/Entra ID architectures, MFA, passwordless and Zero Trust strategies, while driving identity governance at scale.

Qualifications

  • 7+ years in security or identity architecture with enterprise IAM.
  • Experience designing hybrid AD/Entra ID architectures.
  • Strong knowledge of Zero Trust and risk-based access.

Responsibilities

  • Design and evolve enterprise IAM platforms for hybrid cloud on-prem.
  • Define secure authentication, authorization, and federation patterns.
  • Lead architecture reviews with security, infra, and application teams.
  • Implement MFA, passwordless, conditional access, and JML workflows.
  • Create runbooks and architecture diagrams.

Skills

IAM Architecture
Active Directory
Entra ID
Okta
RBAC/ABAC
Zero Trust
Identity governance
Hybrid AD/Entra

Education

Bachelor's degree in CS/IS/Cybersecurity

Tools

Active Directory
Entra ID
Okta
SAML/OAuth

Job description

*Candidates must personally complete all interviews and technical assessments. The use of proxies or third-party representatives during any stage of the hiring process is prohibited and will result in disqualification. Final candidates will be required to participate in at least one in-person interview. Some travel for this role is expected. Reasonable accommodations will be provided in accordance with applicable laws.*

Strong preference for those who live in Austin, TX, Atlanta, GA, or Cleveland, OH, or are willing to travel.

What You’ll Do

You’ll design, implement, and evolve enterprise-scale identity platforms that are secure, resilient, and intuitive to use. This role plays a critical part in enabling secure access across on-premises, hybrid, and cloud environments, ensuring the right identities have the right access to the right resources, at the right time.

You’ll collaborate closely with security engineering, infrastructure, cloud, application teams, HR, and compliance to deliver identity solutions that balance strong security controls with usability and operational efficiency.

How You’ll Make an Impact
  • Design, implement, and support hybrid identity architectures using Active Directory, Microsoft Entra ID, and Okta.
  • Architect secure authentication, authorization, and federation patterns for workforce, partner, and service identities.
  • Apply least-privilege access models using RBAC, ABAC, and role lifecycle management aligned to business functions.
  • Design and implement MFA, passwordless authentication, conditional access, and adaptive authentication policies that balance security and usability.
  • Enable and automate joiner/mover/leaver (JML) processes and identity lifecycle workflows.
  • Integrate IAM platforms with HR systems, directories, and SaaS applications.
  • Support identity-related incident response, including investigation and remediation of access misuse, authentication failures, and identity compromise.
  • Monitor identity signals, logs, and alerts to strengthen detection and response capabilities.
  • Create clear architecture diagrams, standards, runbooks, and implementation documentation.
  • Provide architectural guidance, design reviews, and best-practice recommendations to application and infrastructure teams.
What You Bring
  • 7+ years of experience in security or identity architecture with deep, hands-on expertise in enterprise IAM platforms.
  • Advanced experience with:
  • Active Directory (domains, forests, trusts, GPOs, authentication protocols)
  • Microsoft Entra ID (Conditional Access, MFA, Identity Protection, PIM)
  • Okta (Workforce Identity, SSO, MFA, Lifecycle Management, Workflows)
  • Proven experience designing and operating hybrid AD / Entra ID architectures, including directory synchronization.
  • Strong background in:
  • Identity lifecycle automation and role modeling
  • Okta application integrations, federation, and lifecycle rules
  • Risk-based access design and Zero Trust identity strategies
  • Privileged identity and access management (PIM, PAM, break-glass accounts)
  • Identity governance, access reviews, and certification at enterprise scale
  • Large-scale directory transformations and cloud migrations
  • Cloud-first and hybrid identity architecture design
Skills That Set You Apart
  • Deep understanding of identity and access protocols, including Kerberos, LDAP, SAML, OAuth 2.0, and OpenID Connect.
  • Strong knowledge of Zero Trust principles and identity-centric security models.
  • Ability to communicate complex technical concepts clearly to both technical and non-technical stakeholders.
  • Highly organized with strong prioritization and time-management skills.
  • Flexible, adaptable, and comfortable navigating shifting priorities.
  • Effective in a remote or hybrid environment with limited in-person interaction.
Education & Experience
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field required.
  • Equivalent, directly relevant professional experience may be considered in lieu of a degree.
What to Expect
  • Participation in virtual meetings with camera enabled.
  • Occasional travel to collaborate in person on key initiatives.
What We Offer:
  • Full benefits starting Day 1: Medical, Dental, and Vision
  • 401(k) with company match
  • Professional development programs and tuition assistance
  • Home office equipment stipend
  • Employee resource groups and exclusive employee discounts
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity & Access Architect- Remote within the US
Senior Identity & Access Architect- Remote within the US

Francisco Partners • United States

Hybrid
USD 140,000 - 190,000
Medical benefits
Dental benefits
Vision benefits
+7
Senior Identity Engineer
Senior Identity Engineer

Tyler-Technologies-29572f8 • Plano (TX)

On-site
USD 110,000 - 140,000
Identity and Security Engineer
Identity and Security Engineer

Ledgent Technology • Houston (TX)

On-site
USD 130,000 - 140,000
Principal Software Engineer (Identity Services)
Principal Software Engineer (Identity Services)

INSPYR Solutions • Beverly Hills (CA)

Hybrid
USD 180,000 - 240,000
Staff Identity Engineer
Staff Identity Engineer

United States Digital Space LLC • Washington

On-site
USD 161,000 - 221,000
Equity
Health insurance
Dental & Vision insurance
+1
Senior Identity & Access Architect- Remote within the US
Senior Identity & Access Architect- Remote within the US

OEConnection LLC • Northern (KY)

Hybrid
USD 140,000 - 200,000
Medical, Dental, Vision
401(k) with company match
Remote-first role with stipend
+3
Enterprise Architect
Enterprise Architect

Kerry Search Partners • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Staff Identity Engineer
Staff Identity Engineer

Socket.dev • Bellevue (WA)

On-site
USD 161,000 - 221,000
Equity
Bonus
Health insurance
+2
Staff Identity Engineer
Staff Identity Engineer

Triwill Group • Washington (IL), Northern (KY)

Hybrid
USD 161,000 - 221,000
Staff Identity Engineer
Staff Identity Engineer

Okta • Washington

On-site
USD 161,000 - 221,000