Identity & Access Management (IAM) Architect

International Paper Company

$109K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Computer Science, Cybersecurity, or related field preferred.
  • 10+ years in cybersecurity, with at least 5 years as an IAM architect in a complex environment.
  • Experience in cloud-first environments, especially Microsoft Azure.
  • Knowledge of security frameworks like NIST, ISO 27001, and CIS.
  • Certifications such as CISSP, CISA, CIAM, or CISM preferred.

Responsibilities

  • Develop and maintain GCF's IAM strategy and reference architectures.
  • Lead IAM transformation initiatives, including large-scale modernization efforts.
  • Design identity solutions for cloud, hybrid, and on-premises environments.
  • Drive implementation of Zero Trust principles.
  • Establish IAM standards and governance processes.
  • Architect federation, SSO, MFA, and adaptive access solutions.
  • Lead implementation of Privileged Access Management capabilities.

Benefits

  • Hybrid work environment with remote options available in select states.
  • Collaboration with business leaders across various departments.
  • Opportunities for professional growth and mentorship.
  • Involvement in cutting-edge IAM technology and security practices.
Full Job Description
Identity & Access Management Architect

Memphis, TN

Pay Rate:

$109,100 - 145,400

Multiple factors, including Individual experience, skills and abilities will determine where an employee is placed in the pay range.

Category/Shift:

Salaried Full-Time

Location: Memphis (Hybrid) or Remote (For remote positions, Global Cellulose Fibers will consider residents of the following states: Alabama, Arizona, Georgia, Florida, Massachusetts, Mississippi, North Carolina, Ohio, Oklahoma, South Carolina, Tennessee, Texas, Vermont, Virginia and Washington.)

About The Role:

Global Cellulose Fibers (GCF) is seeking an experienced Identity & Access Management (IAM) Architect to lead the strategy, design, implementation, and governance of enterprise identity services. This role is responsible for developing modern identity architectures that enable secure, compliant, and user-friendly access to company resources across cloud, on-premises, and third-party environments.

The IAM Architect will serve as the technical authority for identity governance, access management, privileged access management, authentication, authorization, and zero-trust identity initiatives. This position partners closely with Infrastructure, Cloud, Application Development, HR, Compliance, and business leaders to ensure identity services support organizational objectives while reducing cybersecurity risk.

Key Responsibilities

IAM Strategy & Architecture
  • Develop and maintain GCF's IAM strategy, roadmap, and reference architectures.
  • Experience leading IAM transformation initiatives, including carve-outs, TSA exits, mergers, acquisitions, or large-scale identity modernization programs.
  • Design secure identity solutions supporting cloud, hybrid, and on-premises environments.
  • Drive implementation of Zero Trust principles through identity-centric security controls.
  • Lead modernization initiatives including passwordless authentication and adaptive access.
  • Establish IAM standards, patterns, and governance processes.

Identity Governance & Administration (IGA)
  • Design and oversee joiner, mover, and leaver processes.
  • Develop role-based and attribute-based access control models (RBAC/ABAC).
  • Define and maintain identity lifecycle governance controls.
  • Lead access certification and recertification programs.
  • Collaborate with HR and business stakeholders to improve identity governance processes.

Access Management
  • Architect federation, SSO, MFA, and adaptive access solutions.
  • Design secure authentication and authorization models for workforce, contractor, vendor, and machine identities.
  • Integrate enterprise applications with IAM platforms and identity providers.
  • Develop policies for privileged and elevated access.

Privileged Access Management (PAM)
  • Lead implementation and governance of PAM capabilities.
  • Define privileged account management standards.
  • Design governance and controls for administrative access, service accounts, machine identities, APIs, and workload identities
  • Implement just-in-time and least-privilege access methodologies.

Security Architecture & Risk Management
  • Perform IAM risk assessments and security reviews.
  • Ensure identity solutions align with NIST, ISO 27001, CIS Controls, and Zero Trust frameworks.
  • Support regulatory and audit requirements including SOX, PCI, GDPR, and other applicable standards.
  • Evaluate new IAM technologies and recommend strategic investments.

Leadership & Collaboration
  • Serve as the IAM subject matter expert across the organization.
  • Provide architectural guidance to project teams and application owners.
  • Mentor IAM engineers and security analysts.
  • Collaborate with managed service providers and third-party vendors.
  • Participate in security governance and architecture review boards.


About You: Knowledge, Skills, and Abilities
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field preferred.
  • 10+ years of professional experience in cybersecurity, with at least 5 years as an IAM architect in a complex enterprise environment.
  • Proven experience collaborating with third-party security vendors or MSPs
  • Experience designing and implementing enterprise IAM solutions.
  • Experience supporting cloud-first environments, particularly Microsoft Azure.
  • Proven knowledge of security frameworks and standards such as NIST, ISO 27001, CIS, ISA 62443 and MITRE ATT&CK
  • Experience and understanding of various regulatory requirements and laws, including but not limited to: Payment Card Industry (PCI), ISA 62443, Health Insurance Portability and Accountability Act (HIPAA), and General Data Protection Regulation (GDPR).
  • Certifications such as CISSP, CISA, CIAM, or CISM preferred.
  • Strong analytical, relationship management, and communication skills (both written and verbal).
  • Ability to collaborate across functions and influence stakeholders


Technical Expertise

Strong knowledge of:
  • Microsoft Entra ID (Azure AD)
  • SailPoint, Saviynt, or comparable IGA platforms
  • CyberArk, Delinea, BeyondTrust, or comparable PAM solutions
  • Active Directory and Hybrid Identity
  • SAML 2.0, OAuth 2.0, OIDC, SCIM, and LDAP
  • MFA and Passwordless Authentication
  • Identity Federation and SSO
  • RBAC and ABAC models
  • Zero Trust Architecture
  • Privileged Access Governance
  • Cloud Security Architecture


Physical Location of Position:

Memphis Corporate Office

6400 Poplar Ave.

Memphis, TN 38197

Similar Jobs

More Jobs at International Paper Company

More Information Technology Jobs

Find similar Identity & Access Management (IAM) Architect jobs: