Full Job Description
Interview integrity requirement
*Candidates must personally complete all interviews and technical assessments. The use of proxies or third-party representatives during any stage of the hiring process is prohibited and will result in disqualification. Final candidates will be required to participate in at least one in-person interview. Some travel for this role is expected. Reasonable accommodations will be provided in accordance with applicable laws.*
Help us build secure, seamless access across a modern enterprise. As our Senior IAM Architect, you'll design and evolve identity platforms that keep the right people connected to the right resources-securely, reliably, and without friction-across on-prem, hybrid, and cloud environments. You'll partner closely with security, infrastructure, cloud, application, HR, and compliance teams to deliver solutions that balance strong controls with great user experience.
What You'll Do
- Design and support hybrid identity architectures using Active Directory, Microsoft Entra ID, and Okta
- Architect authentication, authorization, and federation patterns for workforce, partner, and service identities
- Apply least-privilege models (RBAC, ABAC) and role lifecycle management
- Design MFA, passwordless, conditional access, and adaptive authentication policies
- Automate joiner/mover/leaver (JML) workflows and identity lifecycle processes
- Integrate IAM platforms with HR systems, directories, and SaaS applications
- Support identity incident response-investigating access misuse, auth failures, and compromise
- Monitor identity signals and logs to strengthen detection capabilities
- Produce architecture diagrams, standards, runbooks, and documentation
- Provide design reviews and best-practice guidance to application and infrastructure teams
What You Bring
- 7+ years in security or identity architecture with hands-on enterprise IAM expertise
- Advanced skills in Active Directory (domains, forests, trusts, GPOs), Microsoft Entra ID (Conditional Access, MFA, Identity Protection, PIM), and Okta (Workforce Identity, SSO, Lifecycle Management, Workflows)
- Proven experience with hybrid AD/Entra ID architectures and directory synchronization
- Strong background in identity lifecycle automation, role modeling, federation, Zero Trust design, PIM/PAM, access governance/certification, and large-scale directory transformations
- Knowledge of Kerberos, LDAP, SAML, OAuth 2.0, and OpenID Connect
- Excellent communication skills across technical and non-technical audiences
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience)
Work Style: Remote/hybrid with occasional in-person collaboration; camera-on virtual meetings.
What We Offer:
- Full benefits starting Day 1: Medical, Dental, and Vision
- 401(k) with company match
- Unlimited Flex Time Off plus 10 company-paid holidays
- Remote-first role with monthly communication stipend
- Professional development programs and tuition assistance
- Home office equipment stipend
- Employee resource groups and exclusive employee discounts