IAM Architect
Openkyber
Position : IAM Security Engineer Location : Onsite 4 days a week in Lutz FL Duration : 6-month contract to hire The goal is not to hire administrators or analysts performing day-to-day operational work. OpenKyber already provides Tier 1/Tier 2 support and routine administration. The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. MUST HAVES: CyberArk / Idira Need an SME, not an administrator. Someone who can provide strategic direction, mature the organization's use of the platform, and guide future CyberArk/PAM capabilities. Performing day-to-day operational work. Privileged Access Management (PAM) The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. Roughly 5+ years preferred Automate manual processes where possible Develop roadmaps and execution plans Partner with OpenKyber rather than perform outsourced operational tasks Have engineering/problem-solving mindsets rather than ticket-processing backgrounds POSITION CONCEPT The IAM Security Engineer is responsible for operating the company's information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides expert level support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on SAP and Non-SAP Corps applications, NERC Applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across Tampa Electric (TEC), Peoples Gas (PGS), New Mexico Gas (NMG), and Emera. PRIMARY DUTIES AND RESPONSIBILITIES Lead, develop and maintain a strategic roadmap for Identity and Access Management (IAM) aligned with both business and technological objectives. Collaborate closely with teams including Cyber Security, Human Resources, RPA, and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions. (20%) Lead, design, and implement access control policies and authorization mechanisms to govern user access to systems, applications, and data. Enforce the principle of least privilege to minimize security risks. (20%) Design, Implement and maintain IGA processes, including role-based access control (RBAC), certification, and compliance monitoring. Conduct regular access reviews and audits to ensure compliance with policies and regulations. (20%) Enforce security policies related to authentication, password management, and session management. Monitor, respond to security incidents related to unauthorized access attempts and troubleshoot the incidents. (10%) Serve as Subject Matter Expert (SME) for audit, compliance, and regulatory efforts pertaining to IAM, SOX, and PII through investigating, documenting, and reporting to management. (10%) Deploy and manage SSO solutions to enhance user convenience while maintaining security. Integrate applications to enable seamless and secure authentication across multiple systems. (10%) Effectively collaborate with both Technical and Non-technical business owners, highlighting strong interpersonal skills. Actively seek opportunities to optimize the use of IAM toolsets and processes in support of business goals and provide innovative ideas. (10%) Knowledge/Skills/Abilities (KSA) Proficient understanding of RBAC roles, including their assignment, coupled with a practical grasp of authorization object concepts. Advanced/Expert knowledge of the identity lifecycle management by designing workflows for user onboarding, offboarding and changes. Advanced/Expert understanding of Developing scripts, connectors, or custom code to enhance IAM functionality and address specific requirements. Advanced Knowledge of position based security and how roles are assigned to positions on the org structure. This includes advanced troubleshooting of access issues related to position-based security Advanced knowledge of how structural authorization is used via the org structure to restrict access to HR data. Authorizations are based on a user's position within the org structure. Should also have advanced knowledge of the other configuration, organizational structure, and structural profile considerations, which govern what users, can do & on what HR data they can operate Advanced/Expert knowledge of the use of reporting tools and privileges concepts Advance knowledge of Customizing IAM solutions to align with specific business needs and processes and Integrate IAM systems with other applications, directories, and platforms. Advanced knowledge of Reporting tool security as it relates to securing access to various reports, applications, connections, WEBI's, performing certain functions within certain related objects along with creating users. Advanced knowledge of the SAP portal architecture and user administration and how it handled through portal frontend along with troubleshooting knowledge of said architecture. Perform SAP security and authorizations duties, including Portal Roles, Single-Sign-On, Directory services, and securing Internet Transaction Server / web services Advanced knowledge of established system security control policies as it relates to GRC. Ability to analyze application authorization/privileges assignments and segregation of duties (SOD) conflicts, works with internal audit and compliance teams to resolved identified violations. Functional knowledge and implementation experience of GRC Access Control Working knowledge of the processes that ensure compliance with NERC, CIP, SOX, NIST and PCI; Preferred: General knowledge of Active Directory (AD) or other LDAP Directory Services, especially querying/updating through scripts/programs Multi-Factor Authentication (MFA) technology skills deploying and supporting MFA technology for internal and internet-facing application requirements. Single Sign-On (SSO) technology skills deploying and supporting Single Sign-on (SSO) applications within an organization. Must include support skills such as tracing, logging, and real-time troubleshooting. Federated SSO - Security Assertion Markup Language (SAML) and/or OpenID Connect (OIDC) skills required to support both internal and vendor authentication. Knowledge of Privilege Management and Muti factor Authentication (MFA) tools. Knowledge and support of Azure AD groups Key Direction from Manager The goal is not to hire administrators or analysts performing day-to-day operational work. OpenKyber already provides Tier 1/Tier 2 support and routine administration. The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. Core Hiring Philosophy Target candidates who: Challenge the status quo Identify gaps and opportunities proactively Drive program maturity and modernization IAM Role Expectations These individuals should spend approximately: 90%+ Program maturity Engineering Roadmap execution Integration planning Process improvement Partner governance Automation Audit readiness improvements Less than 10% Routine operational work Manual certifications Administrative tasks Examples: Expanding integrated applications from 7 to 14 Building IAM roadmap execution plans Identifying non-human identity gaps Developing PKI/certificate management strategies Improving audit evidence collection through automation Desired IAM Candidate Profile Experience Strong candidates with less experience may be considered if they demonstrate significant accomplishments Preferred Background Experience with: CyberArk / Palo Alto PAM IGA platforms Microsoft Identity SSO Access Management Authentication systems Nice-to-have certifications : CyberArk certifications IGA certifications Microsoft identity certifications Ideal Traits Engineering mindset Problem solver Process improvement focus Ability to build programs from the ground up Strong analytical skills Self-directed
For applications and inquiries, contact:View email address on us.fitly.work
- ...Job ID: TX-27R0001715 Hybrid/Local TX Govt SailPoint IAM Developer (15+) with governance, PowerShell/Python, RBAC, OIDC/SSO/MFA/SAML, SailPoint Identity Security Cloud/ISC, REST APIs experience Location: Austin, TX (DPS) Duration: 10 Months Skills: 8 Required IAM Platform...SuggestedContract workLocal area
- ...RESPONSIBILITIES: OpenKyber's client in Tampa, FL is seeking 2 IAM Engineers to take ownership of Identity Governance and Administration... .... Duties: Serve as the IGA Solutions Lead and Architect, owning design, implementation, and ongoing administration...SuggestedHourly payContract work
- ...Job Summary We are seeking an experienced IAM / OCI Identity Engineer to support an ongoing Oracle Fusion ERP implementation . The... ...Candidate The ideal candidate is an OCI IAM Engineer / Identity Architect with strong IDCS and Entra ID experience who understands how...SuggestedFull timeRemote workMonday to Friday
$42 - $47 per hour
...Talent Acquisition Specialist OpenKyber at email address ****@*****.*** . We have Contract role Entra External ID / IAM Application Architect-Hybrid for client at Long Island, NY. Please let me know if you or any of your friends would be interested in this...SuggestedContract work- ...Job Description : To lead the IAM Operations team in all day-to-day responsibilities fulfilling access requests, audit/compliance requests, troubleshooting incidents related to access, and providing strong customer service to end users and role owners. Subject matter expert...Suggested
- ...Job Title: IAM Operations / IAM Automation Engineer Location: Remote US Develops and maintains automation scripts and workflows using PowerShell, Python, Tines, and AI-enabled coding tools to streamline IAM Governance processes and reduce manual workload. Leverages...Remote work
$65.28 per hour
...65.28 Security Clearance: Ability to obtain and maintain Public Trust (or higher if required) Overview This role is for a senior IAM professional who can lead enterprise identity security and governance across Microsoft Entra ID and Microsoft ICAM environments. The...Contract workRemote work- ...Job Summary: We are seeking a Cloud & IAM DevOps Engineer with strong expertise in AWS cloud deployments, CI/CD automation, and Identity & Access Management (IAM). The ideal candidate will have hands-on experience with AWS, Harness, HashiCorp Vault, Kafka, ForgeRock,...
- ...For more information about OpenKyber, visit us at . This is a contract to perm role. Position Title: Principal Cybersecurity Architect Identity, IAM & Zero Trust Location Information Remote Position Responsibilities: As the Principal Cybersecurity Architect specializing...Permanent employmentContract workRemote work
- ...Title: Business Analyst/QA Analyst IAM (InfoSec) Location: Los Angeles Based Duration: 3-6 Months (possible extension... ...proactive liaison between product owners, developers, security architects, and operations teams. Surface risks early, propose...
- ...OpenKyber . I came across your profile and felt it could be a good match for a current opportunity we're working on. Google Cloud Platform IAM Engineer (Associate) | Google Cloud Platform IAM Lead / Manager (VP) Location: Plano, TX - Onsite Duration: 12 Months Important...Live inImmediate start
- ...Looking for a senior Identity & Access Management (IAM) leader to head an enterprise authentication modernization initiative. In this role, you will lead the migration from legacy ForgeRock OpenAM to PingOne Advanced Identity Cloud and Microsoft Entra ID . Position...Remote work
- ...Role: AWS Security & IAM Engineer Location: Dallas, TX(Hybrid)-3 days in a week Responsible for designing, implementing, and supporting secure AWS Identity and Access Management (IAM) solutions, including user lifecycle management, privileged access controls, and governance...3 days per week
- ...We are seeking an experienced Lead IAM Security Engineer with deep expertise in Saviynt Identity Governance & Administration (IGA) to help mature and modernize a large enterprise IAM program. This is an engineering-focused role designed for professionals who build, improve...
- ...Role: IAM Business Analyst, Process, Persona and Change Location: Onsite - Charlotte NC USA(Hybrid) Practice: Cloud Business Unit Role Purpose: Translate stakeholder needs and observed friction into measurable processes, persona requirements,...
- ...Title: IAM Analyst Location: Arlington, TX (Onsite) Contract Job Description: Design, build, and maintain Business Roles and access templates. Perform role mining, role analysis, and RBAC optimization activities. Partner with business leaders...Contract work
- ...Practical knowledge of Google Cloud Platform projects, networking, IAM, compute, containers, data services, logging and monitoring.... ...decisions. ~ Associate Cloud Engineer or Professional Cloud Architect certification is preferred. Success Measures Case records...Work at office3 days per week
- ...knowledge transfer Provide post-migration support Required Technical Skills: PingOne, Microsoft Entra ID, ForgeRock OpenAM, IAM, SSO, OAuth 2.0, OIDC, SAML, authentication architecture, security best practices. Preferred Qualifications: Government...Remote work
- ...practices. Required Experience Strong experience with Multi-Factor Authentication ( MFA ) and Identity & Access Management ( IAM ) technologies. Background in IT Security, authentication, and access control solutions. Experience troubleshooting complex...For contractorsRemote workWorldwide
- ...Role: Security Engineer Automation / IAM Location: 100% Remote U.S. Only | Core Hours: 8:30 AM 5:00 PM ET Duration: Contract | On-Call: Monthly 247 SOC rotation Seeking an experienced Security Engineer with strong hands-on expertise in security automation...Contract workRemote work
- "C2C or W2 Opportunities" Job Title : IAM Architect Work Location: Alpharetta, GA (Onsite) Need local only who can go for F2F interview JD An IAM Architect is responsible for designing, implementing, and governing identity and access management solutions that ensure secure...Local area
- ...Business Systems Analyst - Identity Access Management Location- Hybrid Chicago, IL downtown Duration- 4-6 Months Job Description: As a IAM business systems analyst you will work on the IAM delivery team on IAM projects. You will be responsible for analyzing business...
- ...Senior AWS Cognito Phoenix, AZ Hybrid Long Term Contract! Role Overview We are seeking a Senior AWS Cognito and Okta IAM Engineer to design, implement, and support secure identity and access management solutions for cloud-based web, mobile, and enterprise applications...Long term contractImmediate start
- ...The primary skills are Google Cloud Platform IAM, Terraform and Golang - Kubernetes - Golang --- Google Cloud Platform (Google Cloud Platform) expertise --- Python programming --- Terraform infrastructure-as-code --- Identity and Access Management (IAM) specific knowledge...
- ...OpenKyber is looking for IAM Audit & Compliance Analyst for one of its clients Remote Job Title: IAM Audit & Compliance Analyst Summary We are seeking an experienced IAM Audit & Compliance Analyst to support audit, compliance, risk, and governance activities within the...Immediate startRemote work
- ...Job Title: (IAM) Saviynt Administrator/Architect Location: Spring, TX - Hybrid (3-Days a week Onsite) Duration: 12+ Months Contract Job Description: Required Skills & Experience: ~5 - 10+ years in Identity & Access Management. ~3...Contract work3 days per week
- ...Cybersecurity IGA & SSO Architect :: Jersey City, NJ :: 5 Days Onsite :: W2 Role : Cybersecurity IGA & SSO Architect Location :- Jersey... ...Sign-On (SSO) solutions. Proven experience delivering large-scale IAM transformations across cloud, on-premises, and hybrid...Remote work
- ...Professional Summary: Seasoned Google Cloud Platform IAM Architect with 15+ years of experience in Identity & Access Management, Cloud Security, and Enterprise Architecture. Proven expertise in designing and implementing large-scale access governance solutions, persona...
- ...Technical Skills Strong expertise in: Identity & Access Management (IAM) Authentication & Authorization Identity Governance &... ...Conditional Access Passwordless Authentication Identity Federation Architect solutions for: Entra ID Azure AWS Microsoft 365 Okta PingFederate...
- ...Position Overview We are seeking an experienced Security Architect Agentic Identity & Access Management to design and govern the target-... ...Protocol (MCP) integrations. Key Responsibilities Agentic IAM Target-State Architecture: Define and lead the enterprise target...Work experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IAM Architect. Be the first to apply!

