Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal IAM/PAM Security Architect

$160k - $190k
Full-time

jobgether

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal IAM/PAM Security Architect based in the United States.

The Principal IAM/PAM Security Architect will shape enterprise security architecture across a complex, multi-domain identity environment.
You’ll define standards spanning Active Directory, Microsoft Entra ID, Okta, and major cloud platforms including AWS, Azure, GCP, and OCI.
The role combines strategic architecture with hands-on technical leadership across identity, privileged access, and secrets governance.
You’ll lead enterprise PAM initiatives, establish secure controls for privileged accounts, and strengthen the protection of sensitive credentials and secrets.
A key focus will be defining emerging standards for AI agents and other non-human identities as enterprise adoption of agentic technologies evolves.
You’ll collaborate with identity, cloud, application, security, and engineering teams to create controls that are scalable, consistent, and audit-ready.
This is a high-impact remote opportunity for an experienced security architect who can turn complex identity challenges into practical enterprise standards.

Accountabilities

  • Define and maintain enterprise security architecture and standards across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity environments, covering authentication, authorization, and identity lifecycle controls.
  • Serve as the architectural authority for identity security decisions, aligning platform, cloud, and application teams with enterprise standards.
  • Lead architecture reviews and risk assessments for new identity integrations, platform migrations, and mergers and acquisitions.
  • Establish enterprise standards for  Agentic Identity , including governance, lifecycle management, authentication, authorization, provisioning, scoped entitlements, and deprovisioning for AI agents and other non-human identities.
  • Monitor developments in agentic AI and non-human identity technologies and advise leadership on emerging security risks, standards, and vendor capabilities.
  • Define security requirements and lead the enterprise implementation of the Delinea PAM platform, including Secret Server and Privilege Manager.
  • Design privileged access controls based on least privilege, just-in-time and just-enough administration, session monitoring, and credential rotation across on-premises and cloud environments.
  • Oversee onboarding of privileged accounts and systems and ensure PAM controls produce audit-ready evidence aligned with frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001.
  • Establish and maintain enterprise secrets governance covering API keys, OAuth/OATH tokens, service account credentials, certificates, vaulting, rotation, and secure distribution.
  • Drive the identification and remediation of hardcoded, unmanaged, or exposed secrets across source code, configuration environments, and CI/CD pipelines.
  • Develop metrics and reporting that measure secrets governance maturity, compliance, and remediation progress.
  • Participate in and help lead architecture review boards, governance forums, and risk committees focused on identity and privileged access.
  • Maintain reference architectures, security standards, roadmaps, and supporting documentation for identity, PAM, and secrets governance.
  • Advise technical and business stakeholders on identity risk and control design for new initiatives while mentoring engineers responsible for implementing identity, PAM, and secrets solutions.
  • Support strategic initiatives and special projects related to enterprise security architecture as required.

Requirements

  • Bachelor’s degree in a technology-related discipline or equivalent professional experience.
  • 8+ years of experience in identity and access management, privileged access management, security architecture, or related security roles within large and complex enterprise environments.
  • Demonstrated experience designing and implementing security standards across hybrid identity environments involving Active Directory, cloud IAM, and SaaS identity providers.
  • Hands-on experience with an enterprise PAM platform at an architecture or lead engineering level; Delinea experience is strongly preferred.
  • Strong expertise with Active Directory, including multi-domain and multi-forest architectures, as well as Microsoft Entra ID and Okta, including federation, conditional access, and hybrid identity synchronization.
  • Strong understanding of cloud IAM across AWS, Azure, GCP, and OCI, including IAM roles and policies, workload identity, federation, and cross-cloud access patterns.
  • Experience with AI agent architectures, service identities, workload identities, and emerging approaches to non-human identity governance.
  • Hands-on experience with Delinea Secret Server and Privilege Manager, along with broader secrets-management technologies such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager.
  • Strong knowledge of authentication and authorization protocols, including Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA.
  • Experience applying security and compliance frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001 to identity, privileged access, and secrets controls.
  • Experience using PowerShell, Python, and REST APIs to automate identity, PAM, and secrets lifecycle processes.
  • Familiarity with CI/CD pipelines and infrastructure-as-code technologies such as Terraform, ARM, and CloudFormation.
  • Exceptional analytical and architectural problem-solving abilities, with the capacity to translate complex multi-domain identity environments into clear, scalable standards.
  • Strong communication and stakeholder-management skills, with the ability to explain architecture, risk, and security decisions to both technical and business audiences.
  • Ability to work independently, maintain focus, interpret complex information, assess risks, and make timely decisions.
  • Relevant security certifications such as CISSP, CISM, SABSA, or CCSP are preferred.
  • Ability to maintain a dedicated, secure remote workspace with reliable high-speed internet connectivity.

Benefits

  • Base salary ranging from $160,000 to $190,000 per year , depending on experience, education, skills, certifications, and business needs.
  • Eligibility for a discretionary bonus.
  • Remote work opportunity within the United States.
  • Medical, dental, and vision insurance.
  • Disability and life insurance coverage.
  • 401(k) savings plan.
  • Paid family leave.
  • 9 paid holidays per year.
  • 17–27 days of paid time off (PTO), depending on level and length of service.
  • Comprehensive benefits designed to support a wide range of personal and family needs.
  • Opportunity to work on enterprise-scale identity, privileged access, secrets governance, and emerging AI identity challenges.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Principal IAM/PAM Security Architect in United States vacancy
  • $220k

     ...Direct Hire • Posted: 1 day agoPrincipal Security Architect - Enterprise SecurityOur client is seeking a highly experienced Principal Security Architect to define and advance enterprise...  ...will bring deep expertise in Zero Trust, IAM/PAM, network security, cloud architecture, and... 
    Principal
    Local area
    Remote work
    Visa sponsorship

    Irvine Technology

    Dallas, TX
    3 days ago
  •  ...they're doing!Job Description: The Sr. Principal Information Security Architect is a strategic technical leader...  ...Establish and enforce security patterns for IAM, network security, data protection,...  ...& Access Management (federation, PAM, least privilege) Cloud network... 
    Principal
    Full time

    Ingram Micro

    Santa Ana, CA
    1 day ago
  • $109k

     ...scientific discovery? Waters is seeking a Security Lead—an expert in application, and operational...  ...management, and rule optimization.Align IAM configs & controls to meet compliance, and...  ...(RBAC), and privileged access management (PAM).Enforce strong authentication mechanisms,... 
    Principal
    Local area
    Worldwide

    Waters

    Milford, MA
    1 day ago
  • $127.05k - $235.95k

     ...operating units. The company focuses on secure, modern, and scalable technology...  ...employer. Responsibilities The ZTNA Principal Architect & Program Lead is responsible for defining...  ...ecosystem (SIEM, SOAR, EDR, DLP, IAM).• Design and implement automated remediation... 
    Principal
    Full time

    Berkley Technology Services

    Wilmington, DE
    3 days ago
  • $140k - $175k

    IAM Security ArchitectHybrid (In office 3 days/week) within Oregon, Washington, Idaho or UtahBuild a career with purpose. Join our Cause...  ...Looking For: Every day, Cambia’s dedicated team of Security Architects are living our mission to make health care easier and lives better... 
    Suggested
    Full time
    For contractors
    Work at office
    Immediate start
    Work from home
    Flexible hours
    3 days per week

    Cambia Health Solutions

    Lewiston, ID
    2 days ago
  • $180k - $220k

     ...the flexibility for meaningful work-life balance. Being a Principal Security Architect at iManage Means… You will drive enterprise security strategy...  ...and patterns throughout many critical domains such as IAM, AI, cloud infrastructure, and secret management to be leveraged... 
    Principal
    Work at office
    Local area
    Worldwide
    Flexible hours

    Imanage

    Chicago, IL
    3 days ago
  • $326.06k - $385.05k

     ...shared experiences for everyone.As a Principal Security Software Engineer on the Production IAM team, you will set the technical...  ...privilege access for engineers. Architect just-in-time, least-privilege,...  ...privileged access management (PAM).Proficiency in at least one... 
    Principal
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    3 days ago
  • $120k - $190k

     ...Will JoinAs part of MetLife’s Global Security team, you’ll work alongside world-class...  ...initiatives across MetLife.The OpportunityThe Principal Security Architect will lead risk-based security...  ...broad security domain knowledge across IAM, network, devices, applications, data,... 
    Principal
    Full time
    Temporary work
    Work at office
    Local area
    Relocation package
    3 days per week

    Metropolitan Life Insurance Company

    New York, NY
    4 days ago
  • $153.47k - $255.75k

     ...their financial goals.Job Overview:LPL's Information Security team is seeking an exceptional Principal Security Architect to engage on API project efforts in Cloud, On-...  ...of AWS and its core services, including EC2, S3, IAM, VPC, and security-related services like security... 
    Principal
    Full time
    Work from home
    Flexible hours

    LPL Financial

    Austin, TX
    1 day ago
  • $164.6k - $288k

     ...service. Position SummaryThe Senior Principal, Identity & Access Management (IAM) Strategy & Product Management, is...  ...strategic advisor, partnering with cyber security leadership, technology teams,...  ...IGA), Privileged Access Management (PAM), Access Controls, Authentication,... 
    Principal
    Full time
    H1b
    Worldwide
    Flexible hours

    Northern Trust

    Tempe, AZ
    3 days ago
  • $77 - $83 per hour

     ...Principal Security Architect (Remote US) We are seeking an experienced Principal Security Architect for a global high tech company. In this...  ...technologies. ~ Strong working knowledge of Azure, AWS, IAM, Zero Trust architectures, application security, and threat... 
    Principal
    Contract work
    Remote work

    Stage 4 Solutions Inc

    Maryland, MD
    2 days ago
  •  ...Required skills: ~5-8 years as Business Analyst in IAM/PAM or cybersecurity domains. ~ Experience with process mapping, workshops, and documentation. ~ Strong analytical and stakeholder engagement skills. Preferred Skills: Experience with CyberArk... 

    Strategic Resources International USA

    Dallas, TX
    29 days ago
  • $155k - $230k

     ...remote position. Position Title: Principal Architect, Technology – Enterprise Security   Base Salary: $155,000 to...  ...identity and access management (IAM) architecture: MFA enforcement standards...  ..., privileged access management (PAM) design, SSO and federation... 
    Principal
    Local area
    Remote work
    Flexible hours

    Ziply Fiber

    Kirkland, WA
    13 days ago
  •  ...Expert will work for the Identity Security Program within a multi-disciplinary team of engineers, architects, program managers and will have...  ...Privilege Access Management (PAM) solution(s). Success for this...  ...colleagues. Coordinate with other IAM components and IAM team members... 
    Full time
    Contract work
    Traineeship
    Work experience placement
    Internship

    Equinix

    Dallas, TX
    20 days ago
  • InterSources Inc in New York is seeking an IAM /Privileged Access Management Architect for a 12-month hybrid contract. The...  ...of Azure and Active Directory security groups, and leading onboarding/...  ...over 7 years of experience in IAM /PAM and is familiar with tools like SailPoint... 
    Contract work

    InterSources Inc

    New York, NY
    2 days ago
  •  ...Design Identity-centric Workforce Security solutions for secure authentication, authorization...  ...in: Identity & Access Management (IAM) Authentication & Authorization...  ...Authentication Identity Federation Architect solutions for: Entra ID Azure... 

    Purple Drive

    Chicago, IL
    a month ago
  •  ...Roblox Corporation in California is seeking a Principal Security Software Engineer for the Production IAM team. You will set the technical direction for identity and access across Roblox's hybrid on-prem and cloud infrastructure, covering machine, workload, human, and... 
    Principal

    Jobleads-US

    San Mateo, CA
    1 day ago
  • Civil Recruit is seeking a Senior Business Analyst with strong IAM/PAM or cybersecurity experience to support a CyberArk PAM discovery and expansion program in Dallas. The role centers on understanding current processes, identifying gaps, and developing an implementation... 

    Civil Recruit

    Dallas, TX
    4 days ago
  • A leading data and AI company based in Mountain View, CA, is seeking a Senior Staff Software Engineer - IAM to enhance customer data security, build distributed systems, and engage with senior leaders. The ideal candidate has extensive experience in Data Security, leadership... 
    Full time

    Databricks

    Mountain View, CA
    3 days ago
  • Tier4 Group in Houston is seeking an experienced Cybersecurity Project Manager to lead enterprise IAM initiatives, including PAM and Secrets Management. You will coordinate cross-functional teams, manage risks, and drive on-time delivery across multiple workstreams. The... 
    Contract work

    TIER4 GROUP

    Houston, TX
    2 days ago
  •  ...Care System is seeking a Lead Analyst to support Identity and Access Management initiatives within the IAM team. You will analyze and develop solutions for IGA, PAM, SSO, Epic workflows, and MFA, while ensuring appropriate controls are in place and operational. Collaborate... 
    Remote job

    Cook Children's Health Care System

    Fort Worth, TX
    2 days ago
  • Interclypse in Maryland is seeking an experienced IAM Architect to design, implement, and maintain enterprise IAM solutions, enforcing least...  ...authorization, and identity lifecycle, including MFA, SSO, and PAM for state agency projects. Required are a Bachelor's degree in... 

    Socket.dev

    Annapolis, MD
    3 days ago
  •  ...Technologies is seeking a Senior Business Analyst with strong IAM/PAM and cybersecurity experience to support a CyberArk PAM discovery...  ...implementation-ready roadmap and SoW. You will collaborate with Security, Infrastructure, DBA, SOC, and Audit teams to map processes,... 

    USK Technologies

    Dallas, TX
    4 days ago
  • Caesars Entertainment is seeking a Principal Cloud Security Architect to drive secure cloud architecture across AWS and GCP, ensuring security is integrated...  ...in AWS and GCP security best practices, including IAM, VPC security, WAF, SIEM, CNAPP, and workload protection.... 
    Principal
    Work experience placement
    Shift work
    Early shift

    Caesers Entertainment

    Las Vegas, NV
    1 day ago
  •  ...Roles, Unit Admin Role, PAM, granular admin...  ...senior, cross-cutting Principal PM role. Rather than owning...  ...identity, access management, security, policy, or a closely...  ...related domain (bonus for IAM, IdP/SCIM,...  ...of senior engineers and architects and reason about foundational... 
    Principal
    Work at office
    Local area

    Atlassian

    San Francisco, CA
    8 hours ago
  • $100k - $135k

     ...our planet. About the RoleThe Enterprise Security Architect (Cyber Security) is responsible for...  ...including SIEM, IDS/IPS, DLP, EDR/XDR, IAM, and vulnerability management platforms....  ...)OAuthSAMLPrivileged Access Management (PAM)Security OperationsSIEM Platforms (Elastic... 
    Full time
    Work at office

    Apex Technology

    Los Angeles, CA
    4 days ago
  • Job DescriptionADP is Hiring a Principal Cloud Security Architect - Google Cloud Platform (GCP)Position Summary:The Cyber Security Architecture (CSA)...  ...knowledge of GCP security architecture and services, including IAM, organization/resource hierarchy, VPC security,... 
    Principal
    Worldwide

    ADP - Automatic Data Processing

    Roseland, NJ
    2 days ago
  •  ...adoption a top company priority. This Principal IAM Engineer is a senior level, individual-...  ...at Lantern. In an organization where the security perimeter is effectively identity, you...  ...access to PHI. Hands-on Saviynt with PAM, Azure PIM, and Keeper, or transferable... 
    Principal
    Temporary work
    Flexible hours

    Lantern

    Dallas, TX
    15 days ago
  • $220k - $250k

     ...Position Overview We are seeking a highly skilledPrincipal Cloud Security Architect with deep experience designing and securing distributed...  ...zero-trust architectures, identity management (OAuth2, JWT, IAM), and secure OTA updates. Background in industrial IoT, energy... 
    Principal
    Full time
    Worldwide

    Nextracker

    Fremont, CA
    4 days ago
  •  ...Cyber is a leading platform-enabled unified security operations company providing a...  ...seeking a technical Senior Security Solutions Architect to support the DHS OCIO Security Tools program...  ...the security stack, including SIEM, EDR, PAM, network detection, and vulnerability... 
    Principal
    Temporary work
    3 days per week

    UltraViolet Cyber

    National Harbor, MD
    15 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal IAM/PAM Security Architect. Be the first to apply!