This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal IAM/PAM Security Architect based in the United States.
The Principal IAM/PAM Security Architect will shape enterprise security architecture across a complex, multi-domain identity environment.
You’ll define standards spanning Active Directory, Microsoft Entra ID, Okta, and major cloud platforms including AWS, Azure, GCP, and OCI.
The role combines strategic architecture with hands-on technical leadership across identity, privileged access, and secrets governance.
You’ll lead enterprise PAM initiatives, establish secure controls for privileged accounts, and strengthen the protection of sensitive credentials and secrets.
A key focus will be defining emerging standards for AI agents and other non-human identities as enterprise adoption of agentic technologies evolves.
You’ll collaborate with identity, cloud, application, security, and engineering teams to create controls that are scalable, consistent, and audit-ready.
This is a high-impact remote opportunity for an experienced security architect who can turn complex identity challenges into practical enterprise standards.
Accountabilities- Define and maintain enterprise security architecture and standards across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity environments, covering authentication, authorization, and identity lifecycle controls.
- Serve as the architectural authority for identity security decisions, aligning platform, cloud, and application teams with enterprise standards.
- Lead architecture reviews and risk assessments for new identity integrations, platform migrations, and mergers and acquisitions.
- Establish enterprise standards for Agentic Identity, including governance, lifecycle management, authentication, authorization, provisioning, scoped entitlements, and deprovisioning for AI agents and other non-human identities.
- Monitor developments in agentic AI and non-human identity technologies and advise leadership on emerging security risks, standards, and vendor capabilities.
- Define security requirements and lead the enterprise implementation of the Delinea PAM platform, including Secret Server and Privilege Manager.
- Design privileged access controls based on least privilege, just-in-time and just-enough administration, session monitoring, and credential rotation across on-premises and cloud environments.
- Oversee onboarding of privileged accounts and systems and ensure PAM controls produce audit-ready evidence aligned with frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001.
- Establish and maintain enterprise secrets governance covering API keys, OAuth/OATH tokens, service account credentials, certificates, vaulting, rotation, and secure distribution.
- Drive the identification and remediation of hardcoded, unmanaged, or exposed secrets across source code, configuration environments, and CI/CD pipelines.
- Develop metrics and reporting that measure secrets governance maturity, compliance, and remediation progress.
- Participate in and help lead architecture review boards, governance forums, and risk committees focused on identity and privileged access.
- Maintain reference architectures, security standards, roadmaps, and supporting documentation for identity, PAM, and secrets governance.
- Advise technical and business stakeholders on identity risk and control design for new initiatives while mentoring engineers responsible for implementing identity, PAM, and secrets solutions.
- Support strategic initiatives and special projects related to enterprise security architecture as required.
Requirements
- Bachelor’s degree in a technology-related discipline or equivalent professional experience.
- 8+ years of experience in identity and access management, privileged access management, security architecture, or related security roles within large and complex enterprise environments.
- Demonstrated experience designing and implementing security standards across hybrid identity environments involving Active Directory, cloud IAM, and SaaS identity providers.
- Hands-on experience with an enterprise PAM platform at an architecture or lead engineering level; Delinea experience is strongly preferred.
- Strong expertise with Active Directory, including multi-domain and multi-forest architectures, as well as Microsoft Entra ID and Okta, including federation, conditional access, and hybrid identity synchronization.
- Strong understanding of cloud IAM across AWS, Azure, GCP, and OCI, including IAM roles and policies, workload identity, federation, and cross-cloud access patterns.
- Experience with AI agent architectures, service identities, workload identities, and emerging approaches to non-human identity governance.
- Hands-on experience with Delinea Secret Server and Privilege Manager, along with broader secrets-management technologies such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager.
- Strong knowledge of authentication and authorization protocols, including Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA.
- Experience applying security and compliance frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001 to identity, privileged access, and secrets controls.
- Experience using PowerShell, Python, and REST APIs to automate identity, PAM, and secrets lifecycle processes.
- Familiarity with CI/CD pipelines and infrastructure-as-code technologies such as Terraform, ARM, and CloudFormation.
- Exceptional analytical and architectural problem-solving abilities, with the capacity to translate complex multi-domain identity environments into clear, scalable standards.
- Strong communication and stakeholder-management skills, with the ability to explain architecture, risk, and security decisions to both technical and business audiences.
- Ability to work independently, maintain focus, interpret complex information, assess risks, and make timely decisions.
- Relevant security certifications such as CISSP, CISM, SABSA, or CCSP are preferred.
- Ability to maintain a dedicated, secure remote workspace with reliable high-speed internet connectivity.
Benefits
- Base salary ranging from $160,000 to $190,000 per year, depending on experience, education, skills, certifications, and business needs.
- Eligibility for a discretionary bonus.
- Remote work opportunity within the United States.
- Medical, dental, and vision insurance.
- Disability and life insurance coverage.
- 401(k) savings plan.
- Paid family leave.
- 9 paid holidays per year.
- 17–27 days of paid time off (PTO), depending on level and length of service.
- Comprehensive benefits designed to support a wide range of personal and family needs.
- Opportunity to work on enterprise-scale identity, privileged access, secrets governance, and emerging AI identity challenges.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1