IAM Architect
Openkyber
Position : IAM Security Engineer Location : Onsite 4 days a week in Lutz FL Duration : 6-month contract to hire The goal is not to hire administrators or analysts performing day-to-day operational work. OpenKyber already provides Tier 1/Tier 2 support and routine administration. The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. MUST HAVES: CyberArk / Idira Need an SME, not an administrator. Someone who can provide strategic direction, mature the organization's use of the platform, and guide future CyberArk/PAM capabilities. Performing day-to-day operational work. Privileged Access Management (PAM) The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. Roughly 5+ years preferred Automate manual processes where possible Develop roadmaps and execution plans Partner with OpenKyber rather than perform outsourced operational tasks Have engineering/problem-solving mindsets rather than ticket-processing backgrounds POSITION CONCEPT The IAM Security Engineer is responsible for operating the company's information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides expert level support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on SAP and Non-SAP Corps applications, NERC Applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across Tampa Electric (TEC), Peoples Gas (PGS), New Mexico Gas (NMG), and Emera. PRIMARY DUTIES AND RESPONSIBILITIES Lead, develop and maintain a strategic roadmap for Identity and Access Management (IAM) aligned with both business and technological objectives. Collaborate closely with teams including Cyber Security, Human Resources, RPA, and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions. (20%) Lead, design, and implement access control policies and authorization mechanisms to govern user access to systems, applications, and data. Enforce the principle of least privilege to minimize security risks. (20%) Design, Implement and maintain IGA processes, including role-based access control (RBAC), certification, and compliance monitoring. Conduct regular access reviews and audits to ensure compliance with policies and regulations. (20%) Enforce security policies related to authentication, password management, and session management. Monitor, respond to security incidents related to unauthorized access attempts and troubleshoot the incidents. (10%) Serve as Subject Matter Expert (SME) for audit, compliance, and regulatory efforts pertaining to IAM, SOX, and PII through investigating, documenting, and reporting to management. (10%) Deploy and manage SSO solutions to enhance user convenience while maintaining security. Integrate applications to enable seamless and secure authentication across multiple systems. (10%) Effectively collaborate with both Technical and Non-technical business owners, highlighting strong interpersonal skills. Actively seek opportunities to optimize the use of IAM toolsets and processes in support of business goals and provide innovative ideas. (10%) Knowledge/Skills/Abilities (KSA) Proficient understanding of RBAC roles, including their assignment, coupled with a practical grasp of authorization object concepts. Advanced/Expert knowledge of the identity lifecycle management by designing workflows for user onboarding, offboarding and changes. Advanced/Expert understanding of Developing scripts, connectors, or custom code to enhance IAM functionality and address specific requirements. Advanced Knowledge of position based security and how roles are assigned to positions on the org structure. This includes advanced troubleshooting of access issues related to position-based security Advanced knowledge of how structural authorization is used via the org structure to restrict access to HR data. Authorizations are based on a user's position within the org structure. Should also have advanced knowledge of the other configuration, organizational structure, and structural profile considerations, which govern what users, can do & on what HR data they can operate Advanced/Expert knowledge of the use of reporting tools and privileges concepts Advance knowledge of Customizing IAM solutions to align with specific business needs and processes and Integrate IAM systems with other applications, directories, and platforms. Advanced knowledge of Reporting tool security as it relates to securing access to various reports, applications, connections, WEBI's, performing certain functions within certain related objects along with creating users. Advanced knowledge of the SAP portal architecture and user administration and how it handled through portal frontend along with troubleshooting knowledge of said architecture. Perform SAP security and authorizations duties, including Portal Roles, Single-Sign-On, Directory services, and securing Internet Transaction Server / web services Advanced knowledge of established system security control policies as it relates to GRC. Ability to analyze application authorization/privileges assignments and segregation of duties (SOD) conflicts, works with internal audit and compliance teams to resolved identified violations. Functional knowledge and implementation experience of GRC Access Control Working knowledge of the processes that ensure compliance with NERC, CIP, SOX, NIST and PCI; Preferred: General knowledge of Active Directory (AD) or other LDAP Directory Services, especially querying/updating through scripts/programs Multi-Factor Authentication (MFA) technology skills deploying and supporting MFA technology for internal and internet-facing application requirements. Single Sign-On (SSO) technology skills deploying and supporting Single Sign-on (SSO) applications within an organization. Must include support skills such as tracing, logging, and real-time troubleshooting. Federated SSO - Security Assertion Markup Language (SAML) and/or OpenID Connect (OIDC) skills required to support both internal and vendor authentication. Knowledge of Privilege Management and Muti factor Authentication (MFA) tools. Knowledge and support of Azure AD groups Key Direction from Manager The goal is not to hire administrators or analysts performing day-to-day operational work. OpenKyber already provides Tier 1/Tier 2 support and routine administration. The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. Core Hiring Philosophy Target candidates who: Challenge the status quo Identify gaps and opportunities proactively Drive program maturity and modernization IAM Role Expectations These individuals should spend approximately: 90%+ Program maturity Engineering Roadmap execution Integration planning Process improvement Partner governance Automation Audit readiness improvements Less than 10% Routine operational work Manual certifications Administrative tasks Examples: Expanding integrated applications from 7 to 14 Building IAM roadmap execution plans Identifying non-human identity gaps Developing PKI/certificate management strategies Improving audit evidence collection through automation Desired IAM Candidate Profile Experience Strong candidates with less experience may be considered if they demonstrate significant accomplishments Preferred Background Experience with: CyberArk / Palo Alto PAM IGA platforms Microsoft Identity SSO Access Management Authentication systems Nice-to-have certifications : CyberArk certifications IGA certifications Microsoft identity certifications Ideal Traits Engineering mindset Problem solver Process improvement focus Ability to build programs from the ground up Strong analytical skills Self-directed
For applications and inquiries, contact:View email address on us.fitly.work
- ...Job Summary: We are seeking a Cloud & IAM DevOps Engineer with strong expertise in AWS cloud deployments, CI/CD automation, and Identity & Access Management (IAM). The ideal candidate will have hands-on experience with AWS, Harness, HashiCorp Vault, Kafka, ForgeRock,...Suggested
- ...Science, Information Systems, or related field 5+ years' experience in Identity and Access Management engineering Expertise with IAM platforms including cloud (Azure, AWS, Google Cloud Platform). In-depth knowledge of authentication, authorization, and...Suggested
- ...IAM Consultant Location: Palo Alto, CA OR Irvine, CA (Hybrid - 3 days a week onsite) Duration: 6 months CTH Description: 7+ years... ...enterprise migration from Entra ID / Azure AD to Okta as architect or technical lead Deep expertise in SAML, OIDC, OAuth 2.0,...Suggested3 days per week
- Position Overview Role: SAP Functional Manager / SAP S/4HANA & ECC OTC Consultant Client / Partner: OpenKyber Location: Milpitas, CA (Hybrid 3 Days Onsite per week) Employment Type: Contract (C2C) Max Rate: Up to $80/hr C2C Key Responsibilities...SuggestedContract work3 days per week
- Data Analyst Banking (2-3 Years Experience) Company: OpenKyber About the Role OpenKyber is seeking a Data Analyst Banking to support reporting and analytics for banking and payments platforms. This role involves analyzing transaction data, building dashboards, and supporting...Suggested
- Job Description: ***Only W2 resumes are accepted Work Location: Role is Hybrid - 4 Days Remote and 1 Day Onsite Per Week. Candidate location: Candidate must be a CURRENT SC resident. No relocation allowed. Due to the large number of systems, interconnected services, cloud...Work at officeRemote workRelocationFlexible hours1 day per week
- ...Job Description Job Description Architect I/II Position Summary - Location: St. Thomas, U.S. Virgin Islands Join our partner firm, INVISION Architecture as an Architect Level I / II and contribute to the planning, design, and coordination of impactful projects across...Local areaRelocationRelocation package
$100.1 - $105.1 per hour
...security, availability, and cost-efficiency requirements. Architect and implement cloud networking, compute, storage, and identity constructs... ...). Background in cloud security architecture including IAM design and secrets management. Skills: Microsoft Azure....Contract work- ...Title: Azure B2C Architect Tax Term: W2 / 1099 Employment Type: Contract Duration: 12+ Months Work Schedule... ...B2C. Strong knowledge of Microsoft Entra ID / Azure AD and IAM concepts. Experience with Azure AD B2C Custom Policies and...Contract workLocal areaRemote workWorldwide
$90 - $95 per hour
Staff Cloud Engineer (Contract-to-Hire) Location: Scottsdale, AZ (preferred) | San Francisco, CA | Chicago, IL Work Model: Hybrid (3 days onsite) Contract Length: 12 months (strong conversion potential) Compensation: $90 $95/hour Work Authorization: Must be authorized ...Full timeContract work- ...Multimodal AI MLOps Databricks Kubernetes MCP ecosystem Certifications (Preferred) Azure AI Engineer Associate Azure Solutions Architect Databricks ML Professional AWS ML Specialty 12. Prior Experience with Agentic AI, LLMs & Production Deployments Mandatory...
- ...Lead Platform Engineer / Architect Location: Charlotte, NC (Hybrid) Position Overview We are seeking a highly experienced Lead Platform Engineer / Architect to design, build, and lead scalable enterprise platforms and services. The ideal candidate will have...
- ...Azure AI Engineer/Architect(End to End Engineering Lead): Location-Fremont, CA (Remote PST Hours/Local Candidates given 1st preference for Onsite/Hybrid work) Job Type-Long Term Contract 12-15 Years Experience Hands on Person. We are looking for a highly skilled...Long term contractLocal areaRemote work
- Network Engineer | Enterprise Infrastructure & Security Join a growing technology team focused on modernizing and securing a complex enterprise network environment. This role offers the opportunity to work across on-premise data centers, cloud platforms, network automation...
$97.5k - $130k
Azure Data Engineer Salary: $97,500-$130,000 Job Summary We are seeking an experienced Azure Data Engineer with strong Databricks expertise to design, develop, and support scalable cloud-based data solutions. This role is responsible for building and maintaining modern...- Hands on Experience in Azure Synapse Analytics, Azure Data Factory and Data Bricks, Azure Storage, Azure Key Vault, SQL Pools CI/CD Pipeline Designing and other Azure services like functions, logic apps - Linked services, Various Runtimes, Datasets, Pipelines, Activities...
- Hi Team, Need utmost focus and support on below role ASAP. Salesforce Developer Overall 12+yrs profiles only We need some really solid Salesforce Developer for Industry Telecommunications / Media experience preferred. Please share a few profiles soon. Position...Full timeImmediate startRemote work
- Job Title: Salesforce Developer | ONLY W2 Location: Chicago, IL Hybrid Duration: 12 Months Contract Must-Haves: ~7 10 years of ITSM/ServiceNow and Incident Management experience ~7+ years in Data Architecture & Data Migration ~ Strong Salesforce Configuration...Contract work
- Job Title: ServiceNow HRSD Consultant Location: Santa Clara, CA (Remote) Job Summary We are seeking an experienced Human Resource Business Process Consultant with deep knowledge of HR operations and ServiceNow HR Service Delivery (HRSD). In this role, you...Remote work
$50 - $55 per hour
Innova Solutions has a client that is immediately hiring for a ServiceNow Consultant Position Type: Full-time (Contract) Duration: 12+ Months Location: Irving, TX & Charlotte, NC As a ServiceNow Consultant, you will: Develop and customize solutions on the ...Hourly payFull timeContract workTemporary workWork experience placementImmediate startWorldwideFlexible hours- Job Title: ServiceNow Support Specialist / HRSD Business Process Consultant Location: Santa Clara, CA Remote Job Type: Contract W2 Work Authorization: Candidates must be able to work on W2 without requiring current or future visa sponsorship. We...Contract workRemote workVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IAM Architect. Be the first to apply!

