Principal IAM/PAM Security Architect
$160k - $190kjobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal IAM/PAM Security Architect based in the United States.
The Principal IAM/PAM Security Architect will shape enterprise security architecture across a complex, multi-domain identity environment.
You’ll define standards spanning Active Directory, Microsoft Entra ID, Okta, and major cloud platforms including AWS, Azure, GCP, and OCI.
The role combines strategic architecture with hands-on technical leadership across identity, privileged access, and secrets governance.
You’ll lead enterprise PAM initiatives, establish secure controls for privileged accounts, and strengthen the protection of sensitive credentials and secrets.
A key focus will be defining emerging standards for AI agents and other non-human identities as enterprise adoption of agentic technologies evolves.
You’ll collaborate with identity, cloud, application, security, and engineering teams to create controls that are scalable, consistent, and audit-ready.
This is a high-impact remote opportunity for an experienced security architect who can turn complex identity challenges into practical enterprise standards.
Accountabilities
- Define and maintain enterprise security architecture and standards across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity environments, covering authentication, authorization, and identity lifecycle controls.
- Serve as the architectural authority for identity security decisions, aligning platform, cloud, and application teams with enterprise standards.
- Lead architecture reviews and risk assessments for new identity integrations, platform migrations, and mergers and acquisitions.
- Establish enterprise standards for Agentic Identity , including governance, lifecycle management, authentication, authorization, provisioning, scoped entitlements, and deprovisioning for AI agents and other non-human identities.
- Monitor developments in agentic AI and non-human identity technologies and advise leadership on emerging security risks, standards, and vendor capabilities.
- Define security requirements and lead the enterprise implementation of the Delinea PAM platform, including Secret Server and Privilege Manager.
- Design privileged access controls based on least privilege, just-in-time and just-enough administration, session monitoring, and credential rotation across on-premises and cloud environments.
- Oversee onboarding of privileged accounts and systems and ensure PAM controls produce audit-ready evidence aligned with frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001.
- Establish and maintain enterprise secrets governance covering API keys, OAuth/OATH tokens, service account credentials, certificates, vaulting, rotation, and secure distribution.
- Drive the identification and remediation of hardcoded, unmanaged, or exposed secrets across source code, configuration environments, and CI/CD pipelines.
- Develop metrics and reporting that measure secrets governance maturity, compliance, and remediation progress.
- Participate in and help lead architecture review boards, governance forums, and risk committees focused on identity and privileged access.
- Maintain reference architectures, security standards, roadmaps, and supporting documentation for identity, PAM, and secrets governance.
- Advise technical and business stakeholders on identity risk and control design for new initiatives while mentoring engineers responsible for implementing identity, PAM, and secrets solutions.
- Support strategic initiatives and special projects related to enterprise security architecture as required.
Requirements
- Bachelor’s degree in a technology-related discipline or equivalent professional experience.
- 8+ years of experience in identity and access management, privileged access management, security architecture, or related security roles within large and complex enterprise environments.
- Demonstrated experience designing and implementing security standards across hybrid identity environments involving Active Directory, cloud IAM, and SaaS identity providers.
- Hands-on experience with an enterprise PAM platform at an architecture or lead engineering level; Delinea experience is strongly preferred.
- Strong expertise with Active Directory, including multi-domain and multi-forest architectures, as well as Microsoft Entra ID and Okta, including federation, conditional access, and hybrid identity synchronization.
- Strong understanding of cloud IAM across AWS, Azure, GCP, and OCI, including IAM roles and policies, workload identity, federation, and cross-cloud access patterns.
- Experience with AI agent architectures, service identities, workload identities, and emerging approaches to non-human identity governance.
- Hands-on experience with Delinea Secret Server and Privilege Manager, along with broader secrets-management technologies such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager.
- Strong knowledge of authentication and authorization protocols, including Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA.
- Experience applying security and compliance frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001 to identity, privileged access, and secrets controls.
- Experience using PowerShell, Python, and REST APIs to automate identity, PAM, and secrets lifecycle processes.
- Familiarity with CI/CD pipelines and infrastructure-as-code technologies such as Terraform, ARM, and CloudFormation.
- Exceptional analytical and architectural problem-solving abilities, with the capacity to translate complex multi-domain identity environments into clear, scalable standards.
- Strong communication and stakeholder-management skills, with the ability to explain architecture, risk, and security decisions to both technical and business audiences.
- Ability to work independently, maintain focus, interpret complex information, assess risks, and make timely decisions.
- Relevant security certifications such as CISSP, CISM, SABSA, or CCSP are preferred.
- Ability to maintain a dedicated, secure remote workspace with reliable high-speed internet connectivity.
Benefits
- Base salary ranging from $160,000 to $190,000 per year , depending on experience, education, skills, certifications, and business needs.
- Eligibility for a discretionary bonus.
- Remote work opportunity within the United States.
- Medical, dental, and vision insurance.
- Disability and life insurance coverage.
- 401(k) savings plan.
- Paid family leave.
- 9 paid holidays per year.
- 17–27 days of paid time off (PTO), depending on level and length of service.
- Comprehensive benefits designed to support a wide range of personal and family needs.
- Opportunity to work on enterprise-scale identity, privileged access, secrets governance, and emerging AI identity challenges.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$220k
...Direct Hire • Posted: 1 day agoPrincipal Security Architect - Enterprise SecurityOur client is seeking a highly experienced Principal Security Architect to define and advance enterprise... ...will bring deep expertise in Zero Trust, IAM/PAM, network security, cloud architecture, and...PrincipalLocal areaRemote workVisa sponsorship- ...they're doing!Job Description: The Sr. Principal Information Security Architect is a strategic technical leader... ...Establish and enforce security patterns for IAM, network security, data protection,... ...& Access Management (federation, PAM, least privilege) Cloud network...PrincipalFull time
$109k
...scientific discovery? Waters is seeking a Security Lead—an expert in application, and operational... ...management, and rule optimization.Align IAM configs & controls to meet compliance, and... ...(RBAC), and privileged access management (PAM).Enforce strong authentication mechanisms,...PrincipalLocal areaWorldwide$127.05k - $235.95k
...operating units. The company focuses on secure, modern, and scalable technology... ...employer. Responsibilities The ZTNA Principal Architect & Program Lead is responsible for defining... ...ecosystem (SIEM, SOAR, EDR, DLP, IAM).• Design and implement automated remediation...PrincipalFull time$140k - $175k
IAM Security ArchitectHybrid (In office 3 days/week) within Oregon, Washington, Idaho or UtahBuild a career with purpose. Join our Cause... ...Looking For: Every day, Cambia’s dedicated team of Security Architects are living our mission to make health care easier and lives better...SuggestedFull timeFor contractorsWork at officeImmediate startWork from homeFlexible hours3 days per week$180k - $220k
...the flexibility for meaningful work-life balance. Being a Principal Security Architect at iManage Means… You will drive enterprise security strategy... ...and patterns throughout many critical domains such as IAM, AI, cloud infrastructure, and secret management to be leveraged...PrincipalWork at officeLocal areaWorldwideFlexible hours$326.06k - $385.05k
...shared experiences for everyone.As a Principal Security Software Engineer on the Production IAM team, you will set the technical... ...privilege access for engineers. Architect just-in-time, least-privilege,... ...privileged access management (PAM).Proficiency in at least one...PrincipalFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$120k - $190k
...Will JoinAs part of MetLife’s Global Security team, you’ll work alongside world-class... ...initiatives across MetLife.The OpportunityThe Principal Security Architect will lead risk-based security... ...broad security domain knowledge across IAM, network, devices, applications, data,...PrincipalFull timeTemporary workWork at officeLocal areaRelocation package3 days per week$153.47k - $255.75k
...their financial goals.Job Overview:LPL's Information Security team is seeking an exceptional Principal Security Architect to engage on API project efforts in Cloud, On-... ...of AWS and its core services, including EC2, S3, IAM, VPC, and security-related services like security...PrincipalFull timeWork from homeFlexible hours$164.6k - $288k
...service. Position SummaryThe Senior Principal, Identity & Access Management (IAM) Strategy & Product Management, is... ...strategic advisor, partnering with cyber security leadership, technology teams,... ...IGA), Privileged Access Management (PAM), Access Controls, Authentication,...PrincipalFull timeH1bWorldwideFlexible hours$77 - $83 per hour
...Principal Security Architect (Remote US) We are seeking an experienced Principal Security Architect for a global high tech company. In this... ...technologies. ~ Strong working knowledge of Azure, AWS, IAM, Zero Trust architectures, application security, and threat...PrincipalContract workRemote work- ...Required skills: ~5-8 years as Business Analyst in IAM/PAM or cybersecurity domains. ~ Experience with process mapping, workshops, and documentation. ~ Strong analytical and stakeholder engagement skills. Preferred Skills: Experience with CyberArk...
$155k - $230k
...remote position. Position Title: Principal Architect, Technology – Enterprise Security Base Salary: $155,000 to... ...identity and access management (IAM) architecture: MFA enforcement standards... ..., privileged access management (PAM) design, SSO and federation...PrincipalLocal areaRemote workFlexible hours- ...Expert will work for the Identity Security Program within a multi-disciplinary team of engineers, architects, program managers and will have... ...Privilege Access Management (PAM) solution(s). Success for this... ...colleagues. Coordinate with other IAM components and IAM team members...Full timeContract workTraineeshipWork experience placementInternship
- InterSources Inc in New York is seeking an IAM /Privileged Access Management Architect for a 12-month hybrid contract. The... ...of Azure and Active Directory security groups, and leading onboarding/... ...over 7 years of experience in IAM /PAM and is familiar with tools like SailPoint...Contract work
- ...Design Identity-centric Workforce Security solutions for secure authentication, authorization... ...in: Identity & Access Management (IAM) Authentication & Authorization... ...Authentication Identity Federation Architect solutions for: Entra ID Azure...
- ...Roblox Corporation in California is seeking a Principal Security Software Engineer for the Production IAM team. You will set the technical direction for identity and access across Roblox's hybrid on-prem and cloud infrastructure, covering machine, workload, human, and...Principal
- Civil Recruit is seeking a Senior Business Analyst with strong IAM/PAM or cybersecurity experience to support a CyberArk PAM discovery and expansion program in Dallas. The role centers on understanding current processes, identifying gaps, and developing an implementation...
- A leading data and AI company based in Mountain View, CA, is seeking a Senior Staff Software Engineer - IAM to enhance customer data security, build distributed systems, and engage with senior leaders. The ideal candidate has extensive experience in Data Security, leadership...Full time
- Tier4 Group in Houston is seeking an experienced Cybersecurity Project Manager to lead enterprise IAM initiatives, including PAM and Secrets Management. You will coordinate cross-functional teams, manage risks, and drive on-time delivery across multiple workstreams. The...Contract work
- ...Care System is seeking a Lead Analyst to support Identity and Access Management initiatives within the IAM team. You will analyze and develop solutions for IGA, PAM, SSO, Epic workflows, and MFA, while ensuring appropriate controls are in place and operational. Collaborate...Remote job
- Interclypse in Maryland is seeking an experienced IAM Architect to design, implement, and maintain enterprise IAM solutions, enforcing least... ...authorization, and identity lifecycle, including MFA, SSO, and PAM for state agency projects. Required are a Bachelor's degree in...
- ...Technologies is seeking a Senior Business Analyst with strong IAM/PAM and cybersecurity experience to support a CyberArk PAM discovery... ...implementation-ready roadmap and SoW. You will collaborate with Security, Infrastructure, DBA, SOC, and Audit teams to map processes,...
- Caesars Entertainment is seeking a Principal Cloud Security Architect to drive secure cloud architecture across AWS and GCP, ensuring security is integrated... ...in AWS and GCP security best practices, including IAM, VPC security, WAF, SIEM, CNAPP, and workload protection....PrincipalWork experience placementShift workEarly shift
- ...Roles, Unit Admin Role, PAM, granular admin... ...senior, cross-cutting Principal PM role. Rather than owning... ...identity, access management, security, policy, or a closely... ...related domain (bonus for IAM, IdP/SCIM,... ...of senior engineers and architects and reason about foundational...PrincipalWork at officeLocal area
$100k - $135k
...our planet. About the RoleThe Enterprise Security Architect (Cyber Security) is responsible for... ...including SIEM, IDS/IPS, DLP, EDR/XDR, IAM, and vulnerability management platforms.... ...)OAuthSAMLPrivileged Access Management (PAM)Security OperationsSIEM Platforms (Elastic...Full timeWork at office- Job DescriptionADP is Hiring a Principal Cloud Security Architect - Google Cloud Platform (GCP)Position Summary:The Cyber Security Architecture (CSA)... ...knowledge of GCP security architecture and services, including IAM, organization/resource hierarchy, VPC security,...PrincipalWorldwide
- ...adoption a top company priority. This Principal IAM Engineer is a senior level, individual-... ...at Lantern. In an organization where the security perimeter is effectively identity, you... ...access to PHI. Hands-on Saviynt with PAM, Azure PIM, and Keeper, or transferable...PrincipalTemporary workFlexible hours
$220k - $250k
...Position Overview We are seeking a highly skilledPrincipal Cloud Security Architect with deep experience designing and securing distributed... ...zero-trust architectures, identity management (OAuth2, JWT, IAM), and secure OTA updates. Background in industrial IoT, energy...PrincipalFull timeWorldwide- ...Cyber is a leading platform-enabled unified security operations company providing a... ...seeking a technical Senior Security Solutions Architect to support the DHS OCIO Security Tools program... ...the security stack, including SIEM, EDR, PAM, network detection, and vulnerability...PrincipalTemporary work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal IAM/PAM Security Architect. Be the first to apply!
- lead security architect United States
- cloud security architect United States
- application security architect United States
- security architect United States
- security solutions architect United States
- aws security architect United States
- cyber security architect United States
- principal software architect United States
- senior principal cloud computing engineer United States
- principal data scientist United States


