IAM Architect

Ernst & Young   •  

Baltimore, MD

Industry: Financial Services


11 - 15 years

Posted 422 days ago

This job is no longer available.

Join our Core Business Services (CBS) team and you will help support the important business enablement functions that keep our organization running strong. As a CBS professional, you will work across teams to provide the knowledge, resources and tools that help EY deliver exceptional quality service to our clients, win in the marketplace and support EY’s growth and profitability. Major teams within CBS include Finance, Information Technology, Human Resources, Enterprise Support Services, Brand Marketing and Communications, Business Development, Knowledge and Risk Management. With so many offerings, you have the opportunity to develop your career through a broad scope of engagements, mentoring and formal learning. That’s how we develop outstanding leaders who team to deliver on our promises to all of our stakeholders, and in so doing, play a critical role in building a better working world for our people, for our clients and for our communities. Sound interesting? Well this is just the beginning. Because whenever you join, however long you stay, theexceptional EY experience lasts a lifetime.  

Job Summary:


The Identity & Access Management (IAM) ILM Architect reports to the Global IAM Architecture Lead in a hands-on role focused on the security architecture in the identity lifecycle management and provisioning space.  The architect works directly with Lead Development, Engineering and Operational resources through collaboration and mentoring to shape the IAM capabilities for the firm.


The Identity and Access Management (IAM) ILM Architect is accountable and responsible for the alignment of business, operational and security requirements and translation of those requirements into technical IAM capabilities. IAM services include, but not limited to, Identity Lifecycle Management, authentication and authorization, session management, access requests, access provisioning, access reauthorization, remote access, IAM services API, role and entitlement models, and directory technologies. The IAM ILM Architect will work with other Architects and Service Owners to create a roadmap that meets strategic and current requirements.


Key responsibilities (analytical/decision making/supervisory):

  • Develop security architectures and engineering system specifications implementing identity management and security controls in development and operational systems.
  • Provide professional knowledge and experience of information systems security identity policies and large enterprise scale practices.
  •  Act as trusted security architecture advisor with extensive evidence of ability to provide strategic direction in leading activities in support of Identity Lifecycle management tools & technologies and enterprise security objectives.
  •  Manage end-user identity, end-user application access, application resource access, and directory maintenance solution architectures, to include the user and application security lifecycle from provisioning to de-provisioning of access rights.
  •  Deliver technical security configuration architecture expertise in implementing cross-organizational information sharing.
  •  Develop solutions and recommendations for issues caused by process challenges, emerging threats and technology changes.

Analytical/Decision Making Responsibilities:

The individual in this role must be able to understand and interpret identity and access management strategies and direction.  Further, the person must be able to bring together key tenets of Information Security to the IAM strategies and develop technical security solutions that properly align.  The IAM Security Architect will contribute to the overall effort of the IAMdirection of the firm.


Knowledge, skills and experience requirements:

The individual in this role must be well educated in general aspects of Information Security, namely:

  • Extensive experience working with IAM technologies:
    •  SME knowledge of Oracle Identity Manager (OIM), and Active Directory
    • Strong knowledge of Microsoft Identity Management products (e.g., FIM/MIM, Azure AD connect).
    • Knowledge of Active Role Server and Imanami GroupID.
  • Proven experience in providing architecture guidance and advisory services to clients for various environments and systems, including application/technology blueprints, roadmaps, optimization, and migration strategies.
  •  Solid understanding of application and systems security architecture and best practices.
  •  Strong knowledge of Exchange and PowerShell, SQL Server, Microsoft SQL Server Integration Services (SSIS).
  •  Strong network and host security background in Windows.
  •  6+ years’ experience in hands-on Identity Management positions.
  •  Must have an experience of implementing an enterprise level IAM (ILM) infrastructure.
  •  Ability to secure solution architecture solutions
  •  Ability to effectively communicate and advocate key security requirements and control implementation to thedevelopment team

Further, the individual must be well versed in the practices and methods within IT Services, specifically:

  • IT Strategy
  • Enterprise Architecture

Desired skills include:

  • Experience in IDM integration across domains
  •  Significant experience in ADDS, Azure AD
  •  Ability to communicate effectively with all levels of management, both verbally and in writing
  •  Significant experience in Oracle DB & Microsoft SQL Server
  •  Experience with ABAC, RBAC
  •  Security architecture and engineering experience

Other Requirements:

  • Frequent travel is not required for this position.  However, it is anticipated that some travel may be required toparticipate in vendor briefings, project meetings, and/or education opportunities.

Qualifications, certifications and education requirements:


  • Bachelor’s or Master’s degree in Information Assurance, Computer Science, Information Systems or related field ofstudy.


  • 12+ years of practical experience in the field of IT is required.  8+ years of direct Information Security experience.

Certification Requirements:

  • A security industry certification is required including but not limited to CISSP, SSCP, CISM, SANS GSEC, ECSA, ECSP, and Security+.