Role Overview:We are seeking a highly skilled Identity, Authentication, and Authorization Architect (IAA) to design and guide secure and efficient authentication and access management solutions. This role focuses on ensuring secure and compliant implementation of hybrid and cloud solutions, aligned with industry frameworks and standards.
Key Responsibilities:- Design Identity-centric Workforce Security solutions for secure and efficient authentication and access management, adhering to industry frameworks such as NIST CSF, COBIT, SOC, and GDPR.
- Guide the architectural development of identity solutions, access patterns, and modern security protocols, practicing Zero Trust, least privilege, and defense-in-depth principles.
- Review and provide feedback on Identity, Authentication, and Access management related security solutions proposed by stakeholders, offering consultation to partners and IT Management.
- Act as a cybersecurity expert, participating in solutions from an IAA perspective across end-user computing, proxy solutions, MFA, SSO, conditional access, device-based authentication, VPN, Desktop virtualization, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, network segmentation, Secrets Management, Certificates Management, Automation, role-based access control, Privileged Identity Management, Just-in-Time access, and data protection.
- Thoroughly understand and provide solutions considering Security technology choices, including design, protocol support, secrets management, data security, client-server communication, token handling, session management, credential vaulting, OIDC OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, and cloud-native services.
- Possess a good understanding of Cloud Infrastructure Entitlement Management (CIEM) solutions to ensure continuous improvement in Security Posture by consulting application teams.
- Design target architectures and roadmaps, considering IAM security control frameworks and audit requirements.
- Demonstrate awareness of Cyber Security Risk management principles and frameworks, supply chain risk, and third-party risk assessment controls.
- Apply threat modeling concepts and methodologies.
- Display a balanced, cross-functional perspective under information security, liaising with other towers and business to help improve Security-centric designs.
Required Skills:- In-depth knowledge and experience with Entra ID, EPM, Sentinel, Azure, M365, and AWS Security.
- Knowledge of Okta, PingFederate, and Entitlement management solutions.
- In-depth knowledge of various cybersecurity frameworks, standards, and identity governance and administration.
- Strong knowledge of Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, Kerberos, LDAP, and Identity Federations.
- Experience in providing security solutions for Java-based Microservices, React-based frontends, and Android/iOS-based mobile applications on Azure.
- Deeper expertise in various security products, authentication, authorization, access management, governance, controls, regulatory requirements, and agentic identities.
Qualifications: