Taking People, Process and Technology to the Next Level
Identity & Access Management (IAM) Architect
Location
California
Posted
45 days ago
Salary
0
Seniority
Mid Level
Job Description
Identity & Access Management (IAM) Architect
Apogee Global RMS
Apogee Global RMS is seeking for a client a seasoned "Identity & Access Management (IAM) Architect" to design, implement, and optimize enterprise‑wide IAM strategies across a complex, multi‑cloud environment. This role is ideal for a security leader who thrives at the intersection of architecture, governance, and hands‑on engineering — and who can drive scalable, secure identity frameworks that support business growth. Key Responsibilities: - Architect and implement IAM solutions across cloud and on‑prem environments (Azure AD, Okta, AWS IAM, etc.) - Lead the design of identity lifecycle management, authentication, authorization, and privileged access frameworks - Develop and enforce IAM governance, policies, and standards - Partner with Security, Infrastructure, DevOps, and Application teams to integrate IAM into enterprise systems - Evaluate and implement modern identity technologies (SSO, MFA, PAM, Zero Trust) - Conduct risk assessments, gap analyses, and remediation planning - Oversee IAM roadmap, scalability planning, and continuous improvement initiatives - Provide technical leadership, mentoring, and best‑practice guidance to engineering teams
Job Requirements
- 7+ years of experience in IAM architecture, engineering, or security architecture
- Deep expertise with Azure AD / Entra, Okta, AWS IAM, or similar identity platforms
- Strong understanding of Zero Trust, RBAC/ABAC, SAML/OAuth/OIDC, and modern authentication protocols
- Experience implementing PAM solutions (CyberArk, BeyondTrust, Delinea, etc.)
- Proven ability to design scalable IAM architectures in enterprise environments
- Strong knowledge of regulatory and compliance frameworks (SOX, NIST, ISO, HIPAA, etc.)
- Excellent communication skills with the ability to influence technical and executive stakeholders
- Preferred Skills:
- Experience with CI/CD integration for identity automation
- Background in cloud security architecture
- Scripting or automation experience (PowerShell, Python, Terraform)
- Certifications such as CISSP, CCSP, Azure Security Engineer, Okta Certified Professional, or similar
Benefits
- Why work for Apogee:
- This is an opportunity to shape the identity security posture of a high‑growth organization backed by Apogee’s trusted advisory and talent ecosystem. You’ll lead mission‑critical initiatives, influence enterprise security strategy, and work alongside forward‑thinking technology leaders.
- How to Apply
- To apply or for any questions, please contact our Talent Team at- careers@apogeeglobalrms.com.
Related Guides
Related Categories
Related Job Pages
More Architect Jobs
Technology Consultant – Mainframe Modernization Architect
EnsonoEnsono delivers complete Hybrid IT solutions, from mainframe to cloud, tailored to each client’s journey.
• Collaborate with their counterparts in the Sales and Consulting organizations to create Pursuit, Solution, and Sales strategies for large existing global clients • Conduct discovery and assessment workshops (often in collaboration with resources from consulting, operations and product teams) to help drive further penetration of the client account • Develop and document solutions that meet client’s (technical and business) requirements and allow them to adapt to changing industry needs with a focus on transformation and re-platform efforts • Conduct solution development sessions and present technical solutions and business cases to a wide variety of audience • Gain executives buy in for complex solutions by engaging in executive and senior-level technology discussions • Gain clients’ confidence as a trusted advisor by offering consultation and recommendations drawing from technology know-how and past experiences • Align and partner with Product Management to help drive appropriate product enhancements and changes to technology roadmap • Aid in driving stability and innovation within the client’s current and future state and create solutions based on client requirements and available product offerings
Purpose: The Senior Architect position requires a high degree of technical architecture expertise in design, development, and implementation of architecture strategy across multiple projects. Contributes to executive strategic leadership planning and leads feasibility analysis on potential future projects to management. The Senior Architect oversees the development, maturation and integration of enterprise architectures based on customer provided requirements to meet customer needs. They are responsible for the design, development, execution and deployment of an enterprise architecture program. Job Location: Work from Home Opportunity! Must be able to work eastern standard. Responsibilities: - Complexity of Work - Establishes the strategic technical direction of the sub-function. Drives the design, development, enhancement and implementation of all technology domains within a given sub-function. Evaluates new technologies for use in support of sub-functions goals. - Strategy & Innovation - Establishes current and long-range direction of technology within the sub-function aimed at keeping the organization on the forefront of change. Collaborating and orchestrating across sub-functions. - Knowledge & Skill - Typically possesses 10 years of relevant work experience. Requires a technical mastery and business knowledge in multiple technology domains and has an operational understanding of supporting technology domains. - Scope of Influence - Design and integration of all technology domains related to a sub-function. - Community Presence/Eminence - Has a presence in multiple job-related communities demonstrated through presentations at user groups, trade shows, and/or academic conferences as well as publication of written manuscripts and/or whitepapers in trade magazines and/or academic journals. Initiates contacts with key technologists and other subject matter experts and is a contact point for others to initiate communications with. - Bachelor's Degree in a related field with 10 years of relevant work experience OR 14 years total relevant work experience.Holds deep technical mastery and business knowledge across multiple technology domains.Strategic thinking and analytical skills with demonstrated ability to combine broad technical, business, clinical and political factors. - Has a broad background implementing different architectures to meet differing needs. Strong written and verbal communication skills and possesses good presentation skills. - Demonstrated ability to direct the implementation of diverse technologies in a complex organization. - Diplomacy and interpersonal skills to lead others to provide inputs for the purpose of sharing with customers, partners, and higher management on vision and need for key technologies. - Demonstrated experiences innovating beyond the state of the art.Maximizing technical efficiency and setting technical direction. Licensure, Certifications, and Clearances: N/A UPMC is an Equal Opportunity Employer/Disability/Veteran
Fairmarkit is the #1 autonomous sourcing platform revolutionizing the way all organizations buy & sell. Fairmarkit equips procurement teams with automation, AI, and GenAI so they can source more competitively at scale. Our solutions for tail spend and strategic sourcing help innovative procurement teams reduce cycle times, drive out costs, meet ESG/Diversity targets, and provide a better stakeholder experience to internal partners and suppliers. Fairmarkit has been recognized with awards by organizations such as Gartner and IDC, and is backed by strategic investors like Notable Capital, Insight Partners, 1984.VC, and Newfund. We are hiring a Software Architect to serve as a senior technical design partner to Fairmarkit’s engineering leadership as we build new product capabilities and strengthen the foundation of our existing platform. This role reports directly to the SVP of Engineering and will be central to how we make architectural decisions across the company. We’re looking for someone with deep engineering expertise, strong product instincts, and the ability to make decisions confidently - a person who naturally brings clarity to complexity and aligns teams on the best path forward. This is not an ivory-tower role: the Architect will be hands-on when needed, especially for MVPs, prototypes, and proof-of-concepts, while spending most of their time shaping architecture, driving technical direction, and ensuring we build scalable, resilient systems. Our platform is built with Python on the backend, Angular on the frontend, and runs in a multi-cloud environment (AWS + Azure). This is the foundation you’ll help us evolve. Why does this role matter? Fairmarkit is scaling — not just in customers and usage, but in product complexity and technical expectations. The decisions we make now will define our speed, stability, and ability to deliver for years. This role ensures we build with intention: aligned architecture, strong design, high engineering quality, and clear technical direction that keeps teams moving fast without sacrificing durability. What You’ll Do - Serve as a technical design partner to the SVP of Engineering and Engineering Leadership, shaping architectural direction and technical strategy. - Drive and own key architecture decisions across our platform — making decisions is a central requirement of this role. - Lead system-level design across: - backend services (Python) - frontend architecture (Angular) - APIs and integrations - data workflows and system boundaries - multi-cloud deployment and infrastructure patterns (AWS + Azure) - Establish and evolve architectural standards including: - scalable service design - performance and reliability best practices - system modularity and domain modeling - security and compliance patterns - observability and operational excellence - Partner with Engineering Managers and Tech Leads to ensure architectural intent is reflected in execution. - Guide teams through technical tradeoffs and design reviews — ensuring clarity, alignment, and high quality. - Identify high-leverage cross-cutting improvements and lead initiatives that accelerate engineering velocity and stability. - Be hands-on when needed: - prototype new services or workflows - build PoCs to validate architecture choices - support teams through hard technical problems - contribute meaningful production-quality code when required - Improve reliability and scale by shaping architecture for: - incident prevention - monitoring and alerting - deployment safety - performance tuning - Collaborate closely with Product and stakeholders to align technology decisions with business outcomes. What Success Looks Like - Architecture decisions are made faster and with stronger alignment — fewer stalls, fewer reversals, fewer costly rewrites. - Engineering teams ship with greater confidence because system design is clear, scalable, and consistent. - Our multi-cloud platform becomes more resilient and operationally mature. - The backend and frontend architecture becomes more modular, maintainable, and extensible. - New product initiatives move quickly from idea → MVP → durable production implementation. - Technical debt decreases over time because architectural improvements are integrated into delivery, not postponed. - Engineering feels more empowered: teams have strong guidance, clear patterns, and decisive leadership. What You Bring - 15+ years of software engineering experience, including responsibility for system architecture and platform design. - Deep expertise in Python backend development, including modern frameworks and best practices for scalable service design. - Strong understanding of frontend architecture principles, ideally with Angular (or transferable expertise designing frontends at scale). - Strong experience building and evolving cloud-native SaaS platforms. - Experience working in environments that require high reliability, scalability, and strong security posture. - Demonstrated success making difficult technical decisions and guiding teams through tradeoffs. - Strong architecture fundamentals, including: - distributed system design - API and integration patterns - data modeling and performance optimization - authentication / authorization and platform security fundamentals - observability and incident-driven improvement - Strong engineering craftsmanship — you care deeply about long-term maintainability, clarity, and correctness. - Ability to communicate architecture clearly to both technical and non-technical stakeholders. - Leadership through influence: you can align groups, create momentum, and raise the bar without relying on hierarchy. - A builder’s mindset — you genuinely love engineering, programming, and designing software. Nice to Have - Experience building multi-cloud systems (AWS + Azure) and designing for portability, cost-awareness, and resilience. - Experience with enterprise workflow systems (procurement, supply chain, ERP integrations, etc.). - Experience scaling architecture through growth stages (startup → enterprise maturity). - Experience leading modernization efforts: - monolith modularization - service boundaries - performance scaling - moving from legacy patterns to modern architecture - Strong background in platform engineering, developer experience, or reliability/SRE practices. Working Style / Traits We Value - Decisive: you don’t avoid hard calls; you gather input, make decisions, and move forward with accountability. - Pragmatic: you balance “ideal architecture” with practical delivery constraints. - Collaborative: you bring people along and build alignment through clarity and respect. - Hands-on: you can still code and prototype when needed, especially for MVPs/PoCs. High standards: you care deeply about engineering quality, both technical and cultural. #Poland Headquartered in Boston, and backed by a $35.6M Series C co-led by OMERS, Highland, Notable Capital, Insight Partners, and ServiceNow. We are looking for exceptional candidates who want to help grow our company into a global enterprise and make their mark on the B2B tech industry. Come soar to new heights with us! Fairmarkit is an equal opportunity employer, and selects individuals best matched for the job based upon job-related qualifications regardless of race, religion, color, creed, sex, sexual orientation, age, ancestry, national origin, gender identity, genetic information, disability, pregnancy, veteran or military status or any other status or characteristic protected by law.
Active Directory, Azure AD Senior Identity & Access Management (IAM) Architect
NTT GroupA global IT innovator founded in 1965, NTT DATA specializes in system integration and networking system services for more than a dozen industries. As an employer, NTT DATA offers a
Title: Active Directory/Azure AD Senior Identity & Access Management (IAM) Architect Location: Plano TX United States Job Description: Req ID: 366994 NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. We are currently seeking a Active Directory/Azure AD Senior Identity & Access Management (IAM) Architect - to join our team in Plano, Texas (US-TX), United States (US). Systems Eng. Sr. Specialist Advisor- Active Directory/Entra ID Role Overview The NTT DATA Services Security organization is looking for talented security-oriented Systems SR. Engineering with strong Active Directory, DNS, DHCP, GPO, ADFS/Entra ID, MFA, SSO and related Identity skills. This role will be part of a larger dedicated security team dedicated to supporting, troubleshooting, upgrading Active Directory, Entra ID and related Identity technologies. Role Responsibilities: - Active Directory designing, Architecture Solutions, Integration with platforms & Applications - Develop an architecture of directory solutions for Windows, Unix, and related platforms - Experience in consolidations of multiple forest and domains and demonstrated understanding on User accounts, machine accounts, GPOs - Understand the requirement and create a migration plan for any services i.e. DNS, DHCP, and Certificate Services (PKI) etc. - Analyzing the requirement and design a solution to fulfil the requirement with zero impact to other platforms - Develop a power shell scripting with AD modules or VB .Net based on the requirements - Manage Azure active directory design, Architect Solutions, Integration with platforms & Applications and AD connector to Entra - Auditing the security logs and integrating with SIEM - Conducting POC with multiple vendors for AD solutions and prepare detailed test cases. Create a clear recommendation document with pros and cons for senior management - Vulnerability Assessment and Management related to Active Directory, DNS & Windows platforms - Active Directory consolidations including application integration working with application teams - Recommend security best practices to achieve stated business objectives, advises on risk assumptions for any variances granted, and provides alternatives to achieve desired end results Required Qualifications: - Minimum 8 years relevant experience in Architecture and designing, solutions & Migrating Active Directory, Entra ID ,Windows & End points - Strong Demonstrated experience with Active Directory migration tool or equivalent and consolidation of Global Forest and Domains. Hands on experience in successful consolidation of AD Forests and Domains - Must have strong hands-on experience working on Entra ID (Azure Active Directory) - Extensive Experience working as Entra IDmin for enterprise Active Directory setup and maintenance - Strong experience in AD Trusts, two-way Trusts and one-way Trusts and deep knowledge of Active Directory Schemas and meta data - Strong Knowledge on Entra ID Identity Management & Integration with on premise - Strong knowledge of Entra ID technologies, including authentication models, federation, Multifactor Authentication (MFA), conditional access policies and other relevant capabilities. - Knowledge of best practices in AD/Azure Privileged access management and modern AD/Azure Secured Administration practices - Strong hands-on experience in coding in PowerShell scripting - Strong Knowledge on IAM disciplines like PIM and Privilege Administrative Accounts PAM solutions such as CyberArk - Good knowledge on ADFS and Entra ID sync connectors - Strong familiarity with DNS Active Directory integrated, partitions and Infoblox & DHCP systems and Migration of services from Active Directory any platform - Demonstrated knowledge and experience in AD assessment in terms of OU delegation, GPOs, permission etc., - Expertise in Active Directory versions 2003, 2008R2, 2012R2 & 2016, 2019 and Azure Active Directory - Good knowledge and hands on experience in setting up lab based on the solution requirements - Demonstrated working knowledge and hands on experience in AD disaster recovery, Replication issues and resolution using tools such as repadmin - Demonstrated experience in writing and applying GPOs, especially related to domain consolidations - Good Knowledge on Active Directory & windows audit logs and levels and SIEM integration - Good knowledge on Networking, firewalls, including host firewalls, DNS, DHCP, DFS & Network load balancers and Secure Global Directory or Secure LDAP - Good knowledge on Cryptography, certificates, PKI, symmetric, asymmetric keys, Encryption & hash algorithms - Good knowledge on AD authentication protocols Kerberos, NTLM, LDAP, LDAPS & LDAP-Start TLS - Good knowledge on Network log capturing & analyzing the network packet captures through the tools Wireshark, Tshark, Microsoft NM etc., - Good knowledge on application integration with LDAP & Kerberos i.e. Keytab, krb5 etc., - Good knowledge on AD migration tools like ADMT, Quest etc., knowledge on AD trusts, forest, domain tree structures, sites, DNS, GPOs, OU, FRS, DFSR. - Good knowledge on any Identity & Access Management tools like FIM, MIM, OIM, Quest etc., - Exposure to SAML, OAuth, OpenID and other security/IAM related standards - Strong hands-on familiarity with host-based security solutions, Forensic & Investigation agents, and Compliance scanning and reporting, Hardening Active Directory - Knowledge of single sign-on, federation, active directory/LDAP, Kerberos/NTLM authentication & integrated Windows authentication - Good knowledge on Identity management and Role based access control, attribute-based access control & entitlement management - Good knowledge on power shell scripting with AD modules or VB .Net and ability to write scripts based on the requirement - Excellent communication skills, especially verbal and written - Good documentation skills to write a design & configuration documents version controls - Excellent Interpersonal skill and ability to work as part of a team - Home office for remote work - Ability to work some weekends and late nights performing approved changes - ITIL V3 or later experience, experience in writing change request and attending Change Advisory Boards (CAB) meeting - Experience with Security Controls and compliance About NTT DATA NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D. Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client's needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us. NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here. For Pay Transparency information, please click here.



