Principal IAM/PAM Security Architect
$160k - $190kCotiviti
Overview The Principal IAM/PAM Security Architect defines and evolves security architecture for identity and privileged access across a large, complex, multi-domain environment spanning Active Directory, Microsoft Entra ID, and Okta, as well as cloud-native identities across AWS, Azure, GCP, and OCI. This role sets security standards for each identity environment, leads the definition of emerging Agentic Identity standards for AI agents and other non-human identities, defines requirements for and drives implementation of the Delinea PAM platform, and owns secrets governance enterprise-wide — including API keys, OAuth/OATH tokens, service account credentials, and certificates. The architect partners closely with identity, cloud, and application teams to keep controls consistent, auditable, and scalable. Responsibilities Identity Architecture & Standards: Define and maintain security architecture and standards across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity (AWS, Azure, GCP, OCI), covering authentication, authorization, and lifecycle controls. Serve as the architectural authority for identity security decisions, aligning platform and cloud teams to enterprise standards across a large, complex identity environment. Lead architecture reviews and risk assessments for new identity integrations, platform migrations, and M&A activity. Agentic Identity Standards: Define enterprise standards for Agentic Identity — governance, lifecycle, authentication, and authorization for AI agents and other non-human identities, including provisioning, scoped entitlements, and deprovisioning. Track the evolving agentic AI and non-human identity landscape and advise leadership on emerging risks, standards, and vendor capabilities. Privileged Access Management (Delinea): Define security requirements for and lead enterprise-wide implementation of the Delinea PAM platform (Secret Server, Privilege Manager). Design privileged access controls — least privilege, JIT/JEA, session monitoring, credential rotation — across on-premises and cloud environments, and oversee onboarding of privileged accounts and systems. Produce audit-ready evidence of PAM controls aligned to frameworks such as SOX, HIPAA, PCI, and ISO 27001. Secrets Governance: Own enterprise policy and lifecycle standards for all secrets — API keys, OAuth/OATH tokens, service account credentials, and certificates — including vaulting, rotation, and secure distribution. Drive detection and remediation of hardcoded, unmanaged, or leaked secrets across source code, configuration, and CI/CD pipelines. Establish metrics and reporting to track secrets governance maturity and compliance across the organization. Governance & Collaboration: Participate in and help lead architecture review boards, governance forums, and risk committees for identity and privileged access. Maintain reference architectures, standards documentation, and roadmaps for identity, PAM, and secrets governance. Advise stakeholders on identity risk and control design for new initiatives, and mentor engineers implementing identity, PAM, and secrets solutions. Complete all responsibilities as outlined in the annual performance review and/or goal setting . Complete all special projects and other duties as assigned. Must be able to perform duties with or without reasonable accommodation. This job description is intended to describe the general nature and level of work being performed and is not to be construed as an exhaustive list of responsibilities, duties and skills required. This job description does not constitute an employment agreement and is subject to change as the needs of Cotiviti and requirements of the job change. Qualifications Bachelor’s degree in a technology discipline or equivalent professional experience. 8+ years of experience in identity and access management, privileged access management, or security architecture roles, including experience across large, complex enterprise environments. Demonstrated experience designing security standards across hybrid identity environments (Active Directory, cloud IAM, and SaaS identity providers). Hands-on experience with a PAM platform (Delinea preferred) at an architecture or lead engineering level. Enterprise Identity Platforms: Active Directory (multi-domain/forest architectures), Microsoft Entra ID, and Okta, including federation, conditional access, and hybrid identity synchronization. Cloud IAM: Identity and access models across AWS, Azure, GCP, and OCI, including IAM roles/policies, workload identity, federation, and cross-cloud access patterns. Agentic & Non-Human Identity: AI agent architectures, service/workload identities, and emerging standards for non-human identity governance. Delinea PAM & Secrets Management: Hands-on experience with Secret Server and Privilege Manager, plus broader vaulting technologies (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager) and secrets-detection tooling. Authentication & Authorization Protocols: Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA. Security & Compliance Frameworks: SOX, HIPAA, PCI DSS, and ISO 27001 as applied to identity, privileged access, and secrets controls. Automation & DevOps Integration: PowerShell, Python, and REST APIs for identity/PAM/secrets lifecycle automation; experience embedding these controls into CI/CD pipelines and infrastructure-as-code (Terraform, ARM, CloudFormation). Strong analytical and architectural problem-solving skills, with the ability to translate complex, multi-domain identity environments into clear standards and communicate architecture and risk decisions to technical and business stakeholders. Relevant security certifications preferred (e.g., CISSP, CISM, SABSA, CCSP). Cognitive /Mental Requirements: Communicating with others to exchange information. Assessing the accuracy, neatness, and thoroughness of the work assigned. Problem-solving and thinking critically. Completing tasks independently. Interpreting data. Making timely decisions in the context of a workflow. Maintaining focus. Physical Requirements and Working Conditions: Must be able to provide high-speed internet access / connectivity and office setup and maintenance. Must be able to provide a dedicated, secure work area. Remaining in a stationary position, often standing or sitting for prolonged periods. Repeating motions that may include the wrists, hands, and/or fingers. No adverse environmental conditions expected. Base compensation ranges from $160,000 to $190,000 per year. Specific offers are determined by various factors, such as experience, education, skills, certifications, and other business needs. This role is eligible for discretionary bonus consideration. Cotiviti offers team members a competitive benefits package to address a wide range of personal and family needs, including medical, dental, vision, disability, and life insurance coverage, 401(k) savings plans, paid family leave, 9 paid holidays per year, and 17-27 days of Paid Time Off (PTO) per year, depending on specific level and length of service with Cotiviti. For information about our benefits package, please refer to ourCareers page. Date of Posting: 9/04/2026 We anticipate that the application window will close on 11/04/2026, but the application window may change depending on the volume of applications received or close immediately if a qualified candidate is selected. #LI-Remote
#LI-MC1
- senior
- J-18808-Ljbffr Cotiviti
$161.9k - $272.93k
...SailPoint's Cybersecurity organization is seeking a Principal Security Architect with a passion for cybersecurity and protecting the organization. As an integral member of SailPoint's Security Architecture and Engineering team, you will take on a challenging and highly...PrincipalTemporary workLocal areaRemote workFlexible hours- ...brand at makpar.com/careers. Position Overview The Enterprise Security Architect III will design, develop, and maintain security... ...Risk Management Framework activities. Experience with ICAM, IAM, PIV, PKI, PAM, SSO, OAuth, OIDC, or access-control systems. Experience with...SuggestedStart working todayImmediate startFlexible hours
- PagerDuty, Inc. is seeking a Principal Product Manager, Platform Security to own the strategy and execution of securing our Operations Cloud platform. This senior IC role sits in Product Development and reports to the Sr Director of Product, Platform & Partners. You will...Principal
- ...About the Department The Identity and Access Management (IAM) team is dedicated to ensuring the secure and efficient management of user identities, access... ...platform Build and manage a Privileged Access Management (PAM) platform Provide operational support of IAM systems...SuggestedLocal area
- ...About the Role: We are looking for a Principal Enterprise Technology Architect to own the technical vision for how... ...Identity Lead retains ownership of IAM/PAM and access governance, and the AI &... ..., data model flexibility, and security compliance — not just features Identify...Principal
$214.51k
...difference and change the world. Job Description The Senior Security Architect role is responsible for leading the architecture of public,... ..., NIST, etc.) Design security for monitoring, logging, IAM, encryption, data protection, detection and preventive controls...H1b- ...Technology, Computer Science, Software Engineering or Information Security related field; 8+ years of relevant experience may be... ...Bash, REST APIs, JSON, YAML and vendor SDKs Experience supporting IAM, DSPM, ASM, vulnerability management, email security, endpoint security...
$150k - $155k
...flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Requisition #: pending Job Title: Senior Security Architect Location: Washington, DC - Hybrid 2-3 days Clearance Level: Public Trust, Must Have Ability to Obtain a Clearance...Monday to Friday- ...matter. About the Role We’re growing our security team and looking for an engineer who can... ...Familiarity with enterprise IAM systems and SSO: configuration, integration... ...Experience with privileged access management (PAM) tooling and the operational patterns around...Remote work
- ...will have a part in shaping it. We're seeking an exceptional Senior Cybersecurity Architect to serve as a technical leader and subject matter expert driving enterprise-wide security architecture initiatives. This role combines deep hands‑on architecture work with technical...Local area
$143.25k - $179.04k
...trust, teamwork, and opportunity at OD. As the Cybersecurity Architect at Old Dominion Freight Line, you will play a critical role in... ...cybersecurity strategies, provide expert guidance on technical security solutions, and ensure the effective implementation of security...Full timeTemporary workWork experience placementLocal areaImmediate startShift workDay shift- ...Description: The SailPoint Senior Architect / Identity Governance and... ...will work closely with ICAM, PAM/CyberArk, cybersecurity, cloud... ...the SailPoint environment is secure, scalable, highly available, auditable... ...related field; 10+ years of IAM/ICAM experience with 7+ years...PrincipalWork at officeLocal area
$218.4k - $365.2k
...endpoint and workload protection, such as Enterprise Endpoint Security, Endpoint Detection and Response (EDR) and Extended Detection... ...Management (CSPM) and SaaS Security Posture Management (SSPM) Architect messaging and gateway defense, including email security tools...- Nova Southwestern University seeks a senior security architect to lead security architecture, detection engineering, and cloud/AI security initiatives. You will establish architectural standards, guide risk assessments, and work across university systems to ensure robust...
- AEGIS Insurance Services, Inc. is seeking a Senior Security Architect to define, design, implement, and maintain the enterprise security architecture across multiple domains including cloud, identity, data protection, and security operations. You will partner with CISO...
- Celigo seeks a Principal Enterprise Architect to build and lead Celigo’s enterprise architecture from the ground up, governing the portfolio and driving rationalization and cost control across SaaS tools. You will apply AI to portfolio analysis, set standards, and tie...PrincipalRemote work
- .... Position Summary: The CyberArk Principal Architect / Privileged Access Management (PAM) SME will serve as the senior technical... ..., implementation, integration, security, and operation of an enterprise... ...; 10+ years of cybersecurity/IAM experience with 7+ years of deep...PrincipalWork at officeLocal area
- ...seeking a Senior Identity & Access Management (IAM) Engineer to support and enhance enterprise access management platforms that secure critical applications and digital services... ...(IGA), Privileged Access Management (PAM), adaptive authentication, multi-factor authentication...Contract workWork experience placementWork at officeWork from homeWork visa
$140k - $150k
Description Contingent Upon Contract Award Remote with occasional on-site support Connected Logistics is seeking a Senior Security Architect to support the Cybersecurity Architecture and Engineering Services supporting the Department of Veterans Affairs (VA) Office...Contract workWork at officeRemote work$122.4k - $228k
...enthusiastic and passionate professional for a Senior Cloud, AI & Data Security Engineer role who wants to design and implement security... ...and approve code and changes with security implications (e.g., IAM Roles and Policies, Security Groups, etc.) Be the cloud security...PrincipalPart timeLocal area$122k - $253k
## Senior Principal Cloud ArchitectApplylocations: Annapolis Junction... ...commercial markets.**Cloud Architect – AWS GovCloud Development Environment... ...on designing scalable, secure, and high-performance cloud... ...services including EC2, S3, VPC, IAM, Lambda, and CloudFormation*...Principal- ...company, is seeking an experienced Security Engineer to support enterprise... ...Architecture principles. Principal responsibilities will include... ...Privileged Access Management (PAM) solutions, Web Application... ...identity and access management (IAM), network security groups,...Local areaRemote workFlexible hours
- ...Sr. Principal Engineer, Mechanical Architect for PC Notebooks From applied research to advanced engineering, the Engineering Technologist team has the expertise to shape ground-breaking products, material and processes. It’s a fascinating field of work. We’re involved...Principal
- Clorox is seeking an Enterprise IAM Product Owner to lead strategy, governance, and delivery of identity security across the enterprise. You will drive IAM roadmap for workforce, privileged, machine, application, and AI identities, aligning with zero trust, MFA, and passwordless...
$180k - $190k
...‑based solutions Key Responsibilities: ~1. Design and architect scalable, secure, and high‑performance AWS and Databricks solutions, leveraging... ...workspaces, clusters, jobs, storage (ADLS/S3), networking, IAM roles and permissions, and related resources on Azure and...PrincipalWork at office3 days per week$175.5k - $263.8k
Cupertino, California, United States Software and Services We are seeking an AI Security Architect with deep expertise across security architecture, AI/ML systems, and threat modeling to join the Apple Information Security (AIS) Assurance ARC team. You will own security...Relocation- ...Strategic Analysis, Inc. is seeking an experienced Principal Cyber Security Engineer to join our team. Experience with prior Department of Defense Science and Technology (S&T) and Research and Development (R&D) platform integration experience teams is what we are looking...Principal
- CVS Health seeks a Distinguished Engineer to act as a technical authority for AI security and related infrastructure security. The role emphasizes hands-on engineering, building reusable security patterns, reference architectures, and proof-of-concept implementations for...
- Myriad360 in the United States is seeking a Senior Security Solution Architect (Presales) to design and present advanced cybersecurity architectures for complex client environments. You will translate security requirements into concrete solutions, lead technical conversations...Remote job
- Salesforce, Inc. is seeking a Solution Engineer with a strong security and compliance background to support defense and national security customers. You will engage with CISOs, CIOs, and RMF Officials, translating complex requirements into actionable security designs and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal IAM/PAM Security Architect. Be the first to apply!
- principal cloud computing engineer Eastern, KY
- principal scientist Eastern, KY
- senior principal cloud computing engineer Eastern, KY
- principal architect Eastern, KY
- principal applied scientist Eastern, KY
- principal Eastern, KY
- principal data scientist Eastern, KY
- senior principal scientist Eastern, KY
- aws security architect
- cyber security architect

