IAM Architect
Openkyber
Position : IAM Security Engineer Location : Onsite 4 days a week in Lutz FL Duration : 6-month contract to hire The goal is not to hire administrators or analysts performing day-to-day operational work. OpenKyber already provides Tier 1/Tier 2 support and routine administration. The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. MUST HAVES: CyberArk / Idira Need an SME, not an administrator. Someone who can provide strategic direction, mature the organization's use of the platform, and guide future CyberArk/PAM capabilities. Performing day-to-day operational work. Privileged Access Management (PAM) The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. Roughly 5+ years preferred Automate manual processes where possible Develop roadmaps and execution plans Partner with OpenKyber rather than perform outsourced operational tasks Have engineering/problem-solving mindsets rather than ticket-processing backgrounds POSITION CONCEPT The IAM Security Engineer is responsible for operating the company's information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides expert level support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on SAP and Non-SAP Corps applications, NERC Applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across Tampa Electric (TEC), Peoples Gas (PGS), New Mexico Gas (NMG), and Emera. PRIMARY DUTIES AND RESPONSIBILITIES Lead, develop and maintain a strategic roadmap for Identity and Access Management (IAM) aligned with both business and technological objectives. Collaborate closely with teams including Cyber Security, Human Resources, RPA, and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions. (20%) Lead, design, and implement access control policies and authorization mechanisms to govern user access to systems, applications, and data. Enforce the principle of least privilege to minimize security risks. (20%) Design, Implement and maintain IGA processes, including role-based access control (RBAC), certification, and compliance monitoring. Conduct regular access reviews and audits to ensure compliance with policies and regulations. (20%) Enforce security policies related to authentication, password management, and session management. Monitor, respond to security incidents related to unauthorized access attempts and troubleshoot the incidents. (10%) Serve as Subject Matter Expert (SME) for audit, compliance, and regulatory efforts pertaining to IAM, SOX, and PII through investigating, documenting, and reporting to management. (10%) Deploy and manage SSO solutions to enhance user convenience while maintaining security. Integrate applications to enable seamless and secure authentication across multiple systems. (10%) Effectively collaborate with both Technical and Non-technical business owners, highlighting strong interpersonal skills. Actively seek opportunities to optimize the use of IAM toolsets and processes in support of business goals and provide innovative ideas. (10%) Knowledge/Skills/Abilities (KSA) Proficient understanding of RBAC roles, including their assignment, coupled with a practical grasp of authorization object concepts. Advanced/Expert knowledge of the identity lifecycle management by designing workflows for user onboarding, offboarding and changes. Advanced/Expert understanding of Developing scripts, connectors, or custom code to enhance IAM functionality and address specific requirements. Advanced Knowledge of position based security and how roles are assigned to positions on the org structure. This includes advanced troubleshooting of access issues related to position-based security Advanced knowledge of how structural authorization is used via the org structure to restrict access to HR data. Authorizations are based on a user's position within the org structure. Should also have advanced knowledge of the other configuration, organizational structure, and structural profile considerations, which govern what users, can do & on what HR data they can operate Advanced/Expert knowledge of the use of reporting tools and privileges concepts Advance knowledge of Customizing IAM solutions to align with specific business needs and processes and Integrate IAM systems with other applications, directories, and platforms. Advanced knowledge of Reporting tool security as it relates to securing access to various reports, applications, connections, WEBI's, performing certain functions within certain related objects along with creating users. Advanced knowledge of the SAP portal architecture and user administration and how it handled through portal frontend along with troubleshooting knowledge of said architecture. Perform SAP security and authorizations duties, including Portal Roles, Single-Sign-On, Directory services, and securing Internet Transaction Server / web services Advanced knowledge of established system security control policies as it relates to GRC. Ability to analyze application authorization/privileges assignments and segregation of duties (SOD) conflicts, works with internal audit and compliance teams to resolved identified violations. Functional knowledge and implementation experience of GRC Access Control Working knowledge of the processes that ensure compliance with NERC, CIP, SOX, NIST and PCI; Preferred: General knowledge of Active Directory (AD) or other LDAP Directory Services, especially querying/updating through scripts/programs Multi-Factor Authentication (MFA) technology skills deploying and supporting MFA technology for internal and internet-facing application requirements. Single Sign-On (SSO) technology skills deploying and supporting Single Sign-on (SSO) applications within an organization. Must include support skills such as tracing, logging, and real-time troubleshooting. Federated SSO - Security Assertion Markup Language (SAML) and/or OpenID Connect (OIDC) skills required to support both internal and vendor authentication. Knowledge of Privilege Management and Muti factor Authentication (MFA) tools. Knowledge and support of Azure AD groups Key Direction from Manager The goal is not to hire administrators or analysts performing day-to-day operational work. OpenKyber already provides Tier 1/Tier 2 support and routine administration. The organization needs senior-level IAM and Data Security professionals who drive maturity, innovation, and strategic execution. Core Hiring Philosophy Target candidates who: Challenge the status quo Identify gaps and opportunities proactively Drive program maturity and modernization IAM Role Expectations These individuals should spend approximately: 90%+ Program maturity Engineering Roadmap execution Integration planning Process improvement Partner governance Automation Audit readiness improvements Less than 10% Routine operational work Manual certifications Administrative tasks Examples: Expanding integrated applications from 7 to 14 Building IAM roadmap execution plans Identifying non-human identity gaps Developing PKI/certificate management strategies Improving audit evidence collection through automation Desired IAM Candidate Profile Experience Strong candidates with less experience may be considered if they demonstrate significant accomplishments Preferred Background Experience with: CyberArk / Palo Alto PAM IGA platforms Microsoft Identity SSO Access Management Authentication systems Nice-to-have certifications : CyberArk certifications IGA certifications Microsoft identity certifications Ideal Traits Engineering mindset Problem solver Process improvement focus Ability to build programs from the ground up Strong analytical skills Self-directed
For applications and inquiries, contact:View email address on us.fitly.work
- ...Responsibilities: Interpret and apply development skills to build IAM solutions to support globally dispersed businesses, personnel... ...during the lifecycle of solutions delivery, service owners, architects, project managers, global infrastructure teams, regional IT teams...SuggestedPermanent employmentFull timeH1b
- ...seeking a highly motivated and experienced candidate to serve as a Subject Matter Expert (SME) / Tech PM on Identity & Access Management (IAM) planning and implementation engagements supporting key clients. The ideal candidate must have extensive experience (7+ years)...SuggestedContract workRemote workFlexible hours
- ...Senior Identity Specialist to drive strategy, design, and improvement of its global Identity Services ecosystem. The role focuses on IAM solutions, security enhancements, and cross-team collaboration within Corporate IT, with a fully remote work setup. You will design and...SuggestedRemote work
- ...Responsibilities: Interpret and apply development skills to build IAM solutions to support globally dispersed businesses, personnel... ...during the lifecycle of solutions delivery, service owners, architects, project managers, global infrastructure teams, regional IT teams...SuggestedPermanent employmentFull time
- ...Brooklyn NY - 3 days onsite and 2 days remote Mandatory Skills 12 years in IAM architect, engineering, administration and operations with focus on directory services and PKI Deep expertise in Active Directory (on-prem and hybrid), Entra ID, and eDirectory Hands‑on experience...SuggestedContract workRemote work
- ...IAM Architect This is a high-level technical position that requires expertise in Identity and Access Management (IAM) systems. The ideal candidate will have extensive experience with ForgeRock solutions, including OpenAM, OpenDJ, OpenIG, and OpenIDM. Key Responsibilities...
- We are seeking an experienced IAM Architect to design, implement, and maintain robust identity and access management solutions. The ideal candidate will have a strong background in IAM technologies, security architecture, and compliance, with a proven ability to translate...Work experience placement
- Veriipro is seeking an experienced IAM Architect to design, implement, and maintain identity and access management solutions. The ideal candidate will possess a strong background in IAM technologies, security architecture, and compliance, and be adept at translating complex...
- ...management provider headquartered in Ann Arbor, Michigan that offers strategic talent solutions to our clients world-wide. Title: Architect IAM for AI / Platform (PAM-Focused) Location: NYC, NY Duration: 11 months Work Type: Onsite Job Type: Temporary...Temporary work
- InterSources Inc in New York is seeking an IAM /Privileged Access Management Architect for a 12-month hybrid contract. The role includes managing identity provisioning workflows, supporting governance of Azure and Active Directory security groups, and leading onboarding...Contract work
$153.47k - $255.75k
Overview We are seeking an experienced Identity and Access Management (IAM) Architect with a strong AI and agent-integration focus to lead the design, proof-of-concept (POC), and hands-on implementation of identity patterns for AI workloads, conversational agents, and...Work from home- ...federation, and API authorization models; identify gaps in delegation, token lifecycle, scopes, secrets, and auditability. Design enterprise IAM patterns (user context propagation, delegation chains, BFF sessions, least-privilege access) and OAuth/OIDC client models. Define...
- Jobtailor in New York is seeking a senior IAM architect to lead secure identity patterns across services, runtimes, tools, and APIs. You will evaluate SSO/MFA, token strategies, and auditability, and design scalable OAuth/OIDC client models with zero-trust alignment. You...
- ...Java and JavaScript, and a bachelor's degree or equivalent experience. This full-time permanent role is open to U.S. citizens and Green Card holders only, with a focus on delivering excellent IAM solutions within a global environment. #J-18808-Ljbffr Career Guidant Inc.Permanent employmentFull time
- LPL Financial is seeking an experienced Identity and Access Management (IAM) Architect to lead the architecture and implementation of identity solutions tailored for AI workloads. In this role, you will work closely with engineering teams to secure tools and access while...
- Point72 is seeking a senior IAM/Privileged Access Manager to lead and mature our privileged access program across enterprise systems. You will collaborate with infrastructure, security, cloud, and engineering teams to implement least privilege, lifecycle management, and...
- Guardian Life is seeking an Identity Governance & Administration Lead to provide hands‑on IGA leadership, manage vendors, and shape enterprise governance models. The role coordinates with HR, legal, digital, technology, cybersecurity, and compliance to deliver secure, ...
$135k - $230k
Role Summary / Purpose We are looking for a highly skilled PAM Engineer with proven experience in Delinea Secret Server, Server Suite, and Delinea Just Enough Privilege (JEP) to manage and enhance our privileged access management infrastructure. This role involves installing...Visa sponsorshipWork visa$70 - $85 per hour
This range is provided by BCforward. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Base pay range $70.00/hr - $85.00/hr Direct message the job poster from BCforward Seeking a highly motivated candidate who demonstrates...Contract workWork at officeFlexible hours- NTT DATA North America is seeking an IAM Architect with Saviynt expertise to lead enterprise security architecture across cloud and on-prem environments. The role emphasizes designing scalable IAM solutions, aligning with governance processes, and driving adoption of reference...Remote job
$175k - $205.9k
...impact?Overview West Monroe is excited to hire a Microsoft 365 Architect for our growing Enterprise Technology team! We’re looking for a... ...Microsoft 365 solutions, and advanced Identity and Access Management (IAM) capabilities. This role will play a key part in designing...Local areaImmediate startFlexible hours- Are you ready to make an impact?West Monroe is hiring a Senior Architect for our growing Enterprise Technology practice! This role will focus... ...Engine (GKE), Cloud Storage, Cloud Functions, networking, IAM, and cloud security services.Experience designing and implementing...Local areaImmediate start
- Reflection AI is seeking a Head of Identity and Access Management to architect, build, and operate a bleeding-edge, zero-trust identity platform for researchers and vast compute environments. You will mandate hardware-backed authentication, design just-in-time credentialing...
- ...Description/ Responsibilities Position Summary Seeking a hands‑on GCP Architect with strong expertise in Google Cloud Platform and Terraform to... ...AI Services Secondary Technical Skills GCP Security Services (IAM, Cloud Armor, KMS, Secret Manager) VPC Service Controls Security...
- ...BigQuery, Cloud Storage, Cloud SQL Networking & Security: VPC, IAM, Load Balancing, KMS Strong experience with Kubernetes, containers... ...and modernization approaches (re-host, re-platform, re-architect) Architect solutions using GKE, Cloud Run, BigQuery, Cloud SQL,...Contract work
$187.6k - $220.7k
Are you ready to make an impact?Agentic AI Architect-Google Cloud West Monroe is seeking an experienced Agentic AI Architect to join our Technology... ..., and DevSecOps practices. Knowledge of cloud networking, IAM, security, observability, reliability engineering, and...Local areaImmediate startFlexible hours$144.2k - $288.4k
...community at a time. Position Summary We're hiring a Principal Architect to take ownership of how we do observability and hybrid cloud at... ...identity and federation using SPIFFE/SPIRE and cloud‑native IAM patterns to move away from static secrets. Provide guidance...Hourly payFull timeTemporary workWork experience placementLocal areaRemote work- ...Job Title: GCP Architect Duration: 6-12 months Location: Onsite - New York, NY Work Type: Rate: Pay range offered to a... ...Services Secondary Technical Skills GCP Security Services (IAM, Cloud Armor, KMS, Secret Manager) VPC Service Controls Security...Work experience placement
$242k - $332k
...mission. If you are too, let's talk. The Okta on Okta Identity Architect Opportunity This is not a traditional architect role. At Okta... ...team, acting as Customer Zero. Reporting directly to the VP of IAM, you will configure, deploy, and battle-test cutting-edge platform...Local areaRemote workWorldwideFlexible hoursShift work- ...LinkedIn Certified Recruiter - Tech Recruitment Certified Title: GCP Architect Location: Remote Role Duration: 12+ Months Job Description:... ...Implement security policies including Identity and Access Management (IAM), encryption, firewall configuration, and continuous compliance...Contract workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IAM Architect. Be the first to apply!



