Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Identity and Data Security Architect

Aqueduct Technologies Inc.

Job Description

Job Description

Aqueduct Technologies is seeking an Identity and Data Security Architect to serve as a senior, customer-facing technical architect responsible for designing, enforcing, and operationalizing identity- and data-centric security controls that govern access to sensitive data across hybrid and cloud environments. This is an architect-level, player/coach role with a strong hands-on bias.

 

Operating above the infrastructure and network layers, you will focus on how human and non-human identities interact with data, applications, APIs, and AI systems. You will translate business risk, regulatory requirements, and governance policy into enforceable technical controls which you design, deploy, and optimize. In short, you will make who can access what enforceable everywhere.

Core Responsibilities:
  • Data Visibility & Posture Management
  • Lead DSPM-led data discovery and posture management deployments across cloud, SaaS, and data platforms
  • Lead discovery engagements to identify where sensitive data resides, how it is accessed, and where controls break down
  • Translate findings into prioritized technical roadmaps aligned to business impact and cyber risk

Identity & Access Architecture

  • Own the data access control plane and operate alongside secure access and network security architectures
  • Design controls that govern who can access sensitive data independent of how or where users connect, including SaaS, APIs, and AI workloads
  • Define access models for human users, service accounts, and application and API workloads
  • Implement conditional access, lifecycle governance, and identity controls tied directly to data sensitivity

IAM / IGA Platform Architecture & Configuration

  • Architect and configure IAM and IGA platforms such as Microsoft Entra ID and Okta
  • Personally architect, configure, and validate identity and data security platforms

Enforcement & Data Controls

  • Translate DSPM findings into enforcement actions, including entitlement reduction, access governance changes, DLP and browser-based control updates, and API access restrictions
  • Design and enforce DLP strategies for data at rest and data in transit, aligned to classification and identity context
  • Implement browser- and endpoint-based data controls using secure access technologies as appropriate
  • Architect API and non-human identity security models using identity-based authentication and authorization
  • Reduce risk from token misuse, over-privileged APIs, long-lived secrets, and lateral data movement

Data Platform Security

  • Secure data lakes, warehouses, and lakehouses using identity-aware access, classification, and policy enforcement

AI / ML & LLM Workload Security

  • Design controls governing access to data used in analytics, AI/ML, and LLM-enabled workloads
  • Address AI-specific risks including data leakage, unauthorized access, and model abuse

Delivery Leadership & Solution Quality

  • Act as a player and coach on larger engagements, providing design leadership while contributing directly to execution
  • Ensure solutions are functional, testable, and enforceable

Resilience, Incident Readiness & Recovery

  • Design identity and data access controls that function during incidents, recovery events, and degraded operating states
  • Align architectures with incident response, cyber recovery, and BC/DR plans

Internal Standards & Presales Support

  • Develop internal reference architectures, patterns, and delivery standards for identity and data access security
  • Support presales and solution shaping by articulating clear, outcome-based security approaches
Required Skills & Qualifications:
  • 6+ years of progressive experience in identity, data security, or access governance roles, ideally within consulting, professional services, or complex enterprise environments
  • Demonstrated ability to own outcomes end-to-end, from strategy through hands-on implementation
  • Hands-on experience deploying and operationalizing DSPM platforms (Cyera, Laminar) as a core security control
  • Strong experience with IAM and IGA platforms such as Entra ID, and Okta including access governance and enforcement
  • Practical experience using tools such as Cyera, Laminar, BigID and Varonis to perform data discovery, classification, masking, DSPM, and DLP
  • Solid understanding of identity-based API authentication and authorization
  • Understanding of modern cloud, data platforms, and identity-aware application architectures
  • Working knowledge of incident response, business impact analysis, and BC/DR concepts as they relate to identity and data access
  • Strong customer-facing communication skills, comfortable with engineers and executive stakeholders
  • Note: Experience focused primarily on network security or secure service edge platforms without meaningful exposure to data discovery and access governance is unlikely to be sufficient for this role.
Preferred Certifications:
  • CISSP or CCSP
  • Microsoft SC-100 (Cybersecurity Architect Expert)
  • Okta Consultant or Administrator certification, or equivalent IAM certification

Aqueduct Technologies is committed to developing a diverse and talented team. We celebrate and support diversity and are committed to making an inclusive environment for all employees and applicants including women, minorities, individuals with disabilities, members of the LGBTQIA community, veterans, and any other legally protected group. We are an Equal Opportunity Employer and do not discriminate against any employee or applicant on the basis of any status protected by federal, state, or local laws.

 

Aqueduct Technologies is one of the largest IT solutions providers in the US, recognized for our relentless pursuit of customer satisfaction, our corporate culture, technology leadership, and our commitment to the local community. We pride ourselves on our world-class engineering, the investments we make in our employees and our systems, and on our loyal base of customers and manufacturers. Recognized as one of the fastest-growing, private companies in Massachusetts—and awarded the Best Place to Work in Boston for six, consecutive years—there is no better time to join Aqueduct than now!

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 19 days ago
Similar jobs that could be interesting for youBased on the Identity and Data Security Architect in Canton, MA vacancy
  • $120k - $175k

     ...Technology Cyber Security Architect Cooley is seeking a Cyber Security Architect to join the...  ...engineering, infrastructure, DevOps, and data teams to embed security, privacy, and governance...  ...Strong knowledge of network security, identity and access management (IAM), encryption... 
    Suggested
    Full time
    Temporary work
    Work at office
    Flexible hours
    Weekend work

    Cooley

    Boston, MA
    13 days ago
  • $116k - $190k

     ...Application Security Architect NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want...  ..., API gateways, Privileged access management platforms, identity access management platforms, LDAP and identity access... 
    Suggested
    Contract work
    Temporary work
    Work experience placement
    Flexible hours

    NTT DATA

    Boston, MA
    3 days ago
  •  ...candidates working under OPT . The Data Program Architect is responsible for defining and...  ...warehouses, ETL and integration platforms, and secure data access patterns. This role...  ...related medical conditions), gender, gender identity, gender expression, national origin,... 
    Suggested
    Second job
    Local area
    Remote work

    Ascensus

    Boston, MA
    4 days ago
  •  ...Data Architect (Data Platform) As a Data Architect for healthcare applications, you are responsible...  ..., designing, and managing scalable, secure, and interoperable data systems that...  ..., sex, sexual orientation, gender identity, national origin, veteran or disability... 
    Suggested

    Kyruus

    Boston, MA
    4 days ago
  • $116.44k - $163.02k

     ...or Portsmouth, NH Job Summary: The Data Architect will design, govern, and lead the implementation...  ...delivery leadership, and enablement of secure, scalable AI-ready data capabilities....  ...retrieval patterns. # Master Data & Identity Strategy Define approach for... 
    Suggested
    Full time
    Temporary work
    Part time
    Work at office
    Flexible hours

    Needham Bank

    Needham, MA
    2 days ago
  • $180k - $200k

     ...results through a rigorous, bottom-up security selection process and strives to provide...  ...employee engagement. Open Position: VP, Data Architect, Data Service and Governance...  .../or GitHub Azure Key Vault, managed identities, and RBAC for secure data access Platform... 
    Full time
    Temporary work
    Casual work
    Work visa

    Income Research Management

    Boston, MA
    22 days ago
  • $144k - $329.1k

     ...possesses a robust background in Data Architecture, Data...  ...responsibilities will include: As Data Architect – Senior Manager, you will...  ...practices, including data security, quality, and lifecycle...  ..., sexual orientation, gender identity/expression, pregnancy, genetic... 
    Summer holiday
    Flexible hours

    EY

    Boston, MA
    2 days ago
  • $120k - $202.5k

    Senior Data Lakehouse Architect (Databricks), Vice PresidentCorporate Functions TechnologyWho We Are...  ...engineering, and governance of scalable, secure, and compliant data capabilities...  ...IAM teams to integrate with enterprise identity providers (e.g., Entra ID / Azure AD)4... 
    Contract work
    Temporary work
    Flexible hours

    STATE STREET CORPORATION

    Quincy, MA
    16 hours ago
  •  ...: - Establish and maintain enterprise data warehouse (EDW) architecture environments...  ...development frameworks, including architecting elegant technical solutions that meet the...  ...guidance, researching, and responding to security vulnerability findings, and working with... 
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    Remote work

    MAXIMUS

    Boston, MA
    1 day ago
  • $81.98k - $178.09k

     ...Enterprise Architect We currently have a career opportunity for...  ...architecture domains — Business, Data, Application, and Technology...  ...for integration, data, security, cloud, and platform engineering...  ...architecture, and modern security and identity frameworks ~ Working... 
    Work at office
    Local area

    Perficient

    Boston, MA
    4 days ago
  •  ...Data Infrastructure Architect Rootshell Enterprise Technologies Inc. is a recognized provider of professional IT Consulting services in the...  ...Platform. Ensure high availability, performance, and security of cloud-based services and solutions. Data Warehousing... 

    Rootshell Inc

    Boston, MA
    4 days ago
  • $149k - $181k

     ...Cloud Security Architect A cloud security architect must be conversant with a breadth of technologies used to protect data, workloads, and systems within cloud platforms. Responsibilities...  ...security architect include: Identity Access Management and Identity... 
    Temporary work
    Worldwide

    InterSystems

    Boston, MA
    2 days ago
  • $184k - $230k

     ...Datavant is the data collaboration platform trusted for healthcare...  ...make the world's health data secure, accessible and actionable,...  ...As a Sr Product Security Architect at Datavant, you will play a...  ..., sexual orientation, gender identity, religion, national origin, disability... 
    Remote work

    Datavant

    Boston, MA
    7 days ago
  •  ...development and software implementation to data analytics and machine learning/AI...  ...This role is critical to supporting robust, secure, and high‑performance data infrastructure...  ...origin, sex, sexual orientation, gender identity, age, pregnancy, status as a qualified individual... 
    Full time
    Local area
    Remote work
    Shift work

    Big Resourcing

    Boston, MA
    16 hours ago
  • $122k - $180k

     ...Multi Database and AI Ready Data Platforms Locations & Work...  ...primary technical owner and architect for Oracle Exadata environments...  ...including tuning, backup, recovery, security, and lifecycle management •...  ..., ethnicity, gender, gender identity or expression, genetic... 
    Contract work
    Local area
    Remote work
    Flexible hours
    1 day per week

    Citizens

    Boston, MA
    1 day ago
  • $125k - $145k

     ...major database technologies to join our data team. The ideal candidate will be responsible...  .... Ensure data integrity, accuracy, security, and compliance across database platforms...  ...sex (including sexual orientation, gender identity or expression, and pregnancy), marital... 
    Work at office
    Local area
    Remote work
    Flexible hours
    2 days per week

    Broadridge Financial Solutions , Inc.

    Boston, MA
    16 hours ago
  • Check Point Software is seeking an experienced Information Security Architect in Boston, MA. The role involves providing architectural design and leading projects to enhance technology adoption among clients. Candidates should have over 10 years of experience in information... 

    Check Point Software

    Boston, MA
    2 days ago
  • $109.3k - $133k

     ...About the Team/Role Wex, Inc. is looking for an Application Security Architect with broad software development and application security experience. This individual would be responsible for designing, guiding, and assessing security solutions in software projects... 
    Flexible hours
    Shift work

    WEX

    Boston, MA
    1 day ago
  • $186k - $255k

     .... Job Summary Your Career We are seeking a Network Security Architect to manage and lead various initiatives to assist our Solutions...  ...of SOC security best practices. Knowledge of Identity and Access Management (IAM) principles. Experience with Generative... 
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Boston, MA
    7 days ago
  • $170.6k - $390k

     ...grow your career in information security! The opportunity The Senior Network Security Architect is a strategic and hands‑on...  ...solutions. Protect sensitive data against a myriad of threats while...  ..., sexual orientation, gender identity/expression, pregnancy, genetic... 
    Summer holiday
    Remote work
    Flexible hours

    EY

    Boston, MA
    4 days ago
  •  ...seeking an experienced Cloud Native AWS Data Architect to lead the design and implementation...  ...teams, and ensure delivery of secure, scalable, cost-optimized, and high-performance...  ...origin, citizenship, sex, gender identity and/or expression, sexual orientation,... 

    Verisk Analytics

    Boston, MA
    4 days ago
  • $116k - $190k

     ...Req ID: 366650 NTT DATA strives to hire exceptional, innovative and passionate individuals...  ...We are currently seeking a Application Security Architect to join our team in Boston,...  ...Privileged access management platforms , identity access management platforms , LDAP and... 
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Boston, MA
    24 days ago
  •  ...Database Architect Developer Boston, MA Asset Management JO-1707-475 Do you...  ...architecture and process improvements for data architecture and data management, balancing...  ...functionality (e.g. scalability, security, performance, data recovery, data backup,... 
    Temporary work

    The Ceres Group

    Boston, MA
    16 hours ago
  • $125k - $205k

     ...platform and more than a decade of proprietary data—including billions of social interactions...  ...[ ABOUT THIS POSITION: As a Senior Security Engineer at Later, you will play a...  ...engineering, with a particular focus on identity and access management, authentication systems... 
    Permanent employment
    Local area
    Remote work

    Later

    Boston, MA
    16 hours ago
  • $170k - $225k

     ...Data Architect Atlanta; Boston; Charlotte; Chicago; Dallas; Los Angeles; New York; San Francisco This position is not eligible for...  ...pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected... 
    Work at office
    Local area
    Remote work
    2 days per week

    Accordion USA

    Boston, MA
    4 days ago
  •  ...We develop bespoke solutions powered by data and technology for several Fortune 100 companies...  ...workforce. We are seeking a Data Architect – Patient Services to join our Life...  ...religion, age, sex, sexual orientation, gender identity/expression, pregnancy, national origin,... 
    Local area
    Remote work

    Tiger Analytics

    Boston, MA
    9 days ago
  • $129k - $180k

    Ensono is looking for a Security Senior Solution Architect to work remotely. This role involves leveraging security architecture knowledge to direct technology roadmaps, engaging with clients, and ensuring solutions align with business goals. The ideal candidate has 8-... 
    Remote job

    Ensono

    Boston, MA
    2 days ago
  •  ...We develop bespoke solutions powered by data and technology for several Fortune 100 companies...  ...Replace # Collaborate with Enterprise Architects, Cloud Architects, Data Engineers, and...  ..., age, sex, sexual orientation, gender identity/expression, pregnancy, national... 
    Local area
    Remote work
    Shift work

    Tiger Analytics Inc.

    Boston, MA
    1 day ago
  •  ...are looking for an experienced Enterprise Architect to support one of the most innovative...  ...Support compliance with regulatory and security requirements including HIPAA Collaborate with cross-functional teams — DevOps, Data, Engineering, Security — to guide architecture... 
    Full time
    Contract work
    Remote work

    IT Labs

    Boston, MA
    11 days ago
  •  ...Job Description Enterprise Architect Employment Type: Full-Time...  ...BlackBerry, Apple iOS, information security, wireless technologies,...  ..., sexual orientation, gender identity, national origin, disability,...  ...more information about how your data is processed, please contact... 
    Full time
    For subcontractor
    Remote work
    Flexible hours

    Contact Government Services, LLC

    Boston, MA
    9 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Identity and Data Security Architect. Be the first to apply!