NTT DATA  Services

IAM Architect (Entra ID-Focused) Hybrid in Plano

NTT DATA Services$116K — $164K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in IAM architecture, engineering, and senior technical delivery roles.
  • Proven hands-on experience with SailPoint and CyberArk implementations.
  • Deep expertise in Entra ID/Azure AD, identity federation, and conditional access.
  • Strong knowledge of PKI design and certificate lifecycle automation.
  • Proficiency with identity protocols (SCIM, SAML, OAuth/OIDC) and automation tools (PowerShell, Python, Terraform).
  • Experience with ITSM (ServiceNow), CI/CD integration, and audit evidence delivery.

Responsibilities

  • Define IAM target state, roadmaps, and governance models.
  • Design role models, entitlement mappings, and certification campaigns for SailPoint IGA.
  • Architect CyberArk PAM including vault topology and credential rotation.
  • Design identity flows, conditional access, and sync patterns for Entra ID/Azure AD.
  • Define PKI trust model and automate certificate issuance and renewal.
  • Drive automation for connector integration and identity infrastructure.
  • Ensure audit readiness and lead access review programs.
  • Lead technical teams and mentor engineers to enhance operational maturity.

Benefits

  • Medical, dental, and vision insurance with employer contribution.
  • Flexible spending or health savings account.
  • Life and AD&D insurance.
  • Short and long term disability coverage.
  • Paid time off and employee assistance programs.
  • Participation in a 401k program with company match.
Full Job Description
Req ID: 385475

We are currently seeking a IAM Architect (Entra ID-Focused) Hybrid in Plano to join our team in Plano, Texas (US-TX), United States (US).

Role Summary:

The Senior IAM Architect will define and deliver enterprise identity strategy and architecture, lead SailPoint IGA and CyberArk PAM design and integrations, architect Entra ID identity and conditional access models, and own PKI and certificate lifecycle strategy. This role partners with Security, Cloud, DevOps, and Application teams to ensure identity-centric, auditable, and automated controls across the organization.

**Must be willing to work in a hybrid setting (2-3 days in the office) in Dallas, TX.

Key Responsibilities:

  • Architectural Leadership -Define IAM target state, roadmaps, and standards covering IGA, PAM, Access Management, and PKI; produce architecture artifacts and governance models.
  • SailPoint IGA Ownership - Design role models, entitlement mappings, connector strategy, reconciliation, and certification campaigns; guide complex integrations with HR and business applications.
  • CyberArk PAM Strategy - Architect vault topology, privileged session controls, credential rotation, and onboarding patterns for service and privileged accounts.
  • Entra ID and Cloud Identity - Design Entra ID/Azure AD identity flows, conditional access, B2B/B2C scenarios, and hybrid sync patterns; align cloud IAM across Azure, AWS, and GCP.
  • PKI and Certificate Automation - Define PKI trust model, certificate issuance/renewal automation, and integration with DevOps pipelines and service identities.
  • Automation and Iac- Drive SCIM/SAML/OIDC connector automation, Terraform/IaC for identity infrastructure, and scripting to reduce manual provisioning.
  • Risk, Compliance, and Audit- Ensure audit readiness, lead access review programs, and translate regulatory requirements into technical controls.
  • Mentorship and Delivery - Lead technical teams, review designs, and mentor L1-L3 engineers to raise operational maturity.


Required Qualifications:
  • 10+ years in IAM architecture, engineering, and/or senior technical delivery roles.
  • Proven hands-on experience with SailPoint and CyberArk implementations.
  • Deep expertise in Entra ID / Azure AD, Identity federation, conditional access, and hybrid identity patterns.
  • Strong knowledge of PKI design and certificate lifecycle automation.
  • Proficiency with identity protocols (SCIM, SAML, OAuth/OIDC), and automation tools (PowerShell, Python, Terraform).
  • Experience with ITSM (ServiceNow), CI/CD integration, and audit evidence delivery.


Preferred Qualifications:

  • Certifications: **SailPoint**, **CyberArk**, **Microsoft Identity/Entra**, **CISSP**
  • Experience integrating HR systems (Workday) and securing cloud native workloads (Kubernetes RBAC, secrets management).


Ideal Soft Skills and Logistics:
- Strong communicator able to influence senior stakeholders and translate business needs into secure identity designs.
- Analytical leader -with a track record of driving automation, reducing risk, and improving audit posture.

NTT DATA provides a reasonable range of compensation for U.S.-based positions. The starting pay range for this remote role is $116,000-$164,000 . This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors, including the candidate's actual work location, relevant experience, technical skills, and other qualifications.

This position may also be eligible for incentive compensation based on individual and/or company performance. If the position offered in temporary, the position will not be eligible for incentive compensation.

This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client's needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use [redacted].com, [redacted].com and [redacted].nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us.

About NTT DATA Services

NTT DATA Corporation is a Japanese multinational information technology service and consulting company headquartered in Tokyo, Japan. It is partially-owned subsidiary of Nippon Telegraph and Telephone. Japan Telegraph and Telephone Public Corporation, a predecessor of NTT, started Data Communications business in 1967. NTT, following its privatization in 1985, spun off the Data Communications division as NTT DATA in 1988, which has now become the largest of the IT Services companies headquartered in Japan.
Learn more about NTT DATA Services
Size
151,991 employees
Industry
Founded
1988
NASDAQ

Similar Jobs

More Jobs at NTT DATA Services

More Information Technology Jobs

Find similar IAM Architect (Entra ID-Focused) Hybrid in Plano jobs: