Must Have Technical/Functional Skills
Required Skills & Experience
Identity & Access Management
• Deep expertise in IAM architecture and identity security frameworks.
• Experience with:
Entra ID (Azure AD)
Single Sign-On (SSO)
Multi-Factor Authentication (MFA)
Identity Governance
Access Management
Privileged Access Management (PAM)
Federation and modern authentication protocols
Product Expertise
• Strong hands-on experience with:
Sgnl.ai
PlainID
CrowdStrike Identity Protection
Entra ID / Azure AD
• Proven ability to engineer, integrate, and operationalize enterprise security products.
Security Architecture
• Strong understanding of:
Zero Trust Architecture
Identity Threat Detection and Response (ITDR)
Attack Path Analysis
Authorization Frameworks
Policy-Based Access Control (PBAC)
Risk-Based Authentication
Engineering & Technical Skills
• Strong product engineering and solution delivery experience.
• Experience integrating security platforms with enterprise applications and infrastructure.
• Knowledge of APIs, identity protocols, automation, and cloud-native architectures.
• Ability to translate business requirements into secure, scalable technical solutions.
Preferred Qualifications
• 10+ years of experience in cybersecurity, IAM, identity architecture, or security engineering.
• Experience leading enterprise-scale identity transformation programs.
• Familiarity with NIST, Zero Trust, and modern cybersecurity frameworks.
• Experience within large, complex, highly regulated environments.
• Relevant certifications such as CISSP, CCSP, Azure Security Engineer, CIAM/IAM certifications, or equivalent.
Skillsets Required:
Strong product knowledge (PlainID, Sgnl.ai), strong product engineering skill sets, IAM architecture
Roles & Responsibilities
Position Summary
We are seeking a highly experienced Principal Identity Security Architect & Product Engineering Lead to drive the design, engineering, and
deployment of next-generation identity security capabilities across the enterprise. This role will lead initiatives focused on attack path analysis,
identity threat protection, behavioral analytics, authentication modernization, policy-based access control (PBAC), and identity-driven attack
containment.
The successful candidate will combine deep expertise in IAM architecture, Zero Trust security models, and identity security products,
including Sgnl.ai, PlainID, Entra ID (Azure AD), and CrowdStrike Identity Protection, to build and operationalize scalable identity-centric
security solutions that reduce risk, improve resilience, and enhance user access experiences.
This position will collaborate closely with cybersecurity, infrastructure, engineering, architecture, and product teams to advance
strategic identity security initiatives and support the organization's cyber defense transformation.
Key Responsibilities
Identity Security Strategy & Architecture
• Define and execute enterprise identity security roadmaps aligned with Zero Trust principles.
• Design scalable IAM architectures supporting modern workforce, privileged, and machine identities.
• Develop identity-centric security controls that reduce attack surfaces and prevent identity-based threats.
• Establish architectural standards for authentication, authorization, and access governance.
Product Engineering & Security Platforms
• Lead engineering and deployment activities for:
Sgnl.ai
PlainID
CrowdStrike Identity Protection
Entra ID (Azure AD)
Authentication and authorization platforms
• Partner with product vendors and internal engineering teams to deliver secure, scalable solutions.
• Drive integration of identity security capabilities into enterprise applications and infrastructure.
Identity Threat Protection & Attack Path Analysis
• Expand attack path mapping capabilities to identify and remediate exploitable identity-based attack vectors.
• Implement identity threat detection, risk scoring, and attack containment capabilities.
• Develop processes to proactively identify privilege escalation paths and lateral movement opportunities.
• Enhance visibility into identity relationships, entitlements, and access risks across the enterprise.
Authentication & Access Modernization
• Support enhancements to authentication services, including Citi Authenticator capabilities and user experience improvements.
• Accelerate adoption of strong authentication and adaptive access controls.
• Advance Policy-Based Access Control (PBAC) initiatives utilizing platforms such as PlainID.
• Drive identity-aware authorization models that improve security while reducing operational complexity.
Behavioral Analytics & Risk-Based Security
• Implement behavioral biometric and user behavior analytics capabilities.
• Design identity-risk models that enable adaptive authentication and access decisions.
• Leverage identity intelligence to support continuous verification and Zero Trust access controls.
Salary Range: $90,000 to $125,000 per year