Principal IAM/PAM Security Architect
New
J
JobgetherSecurity & IT
Remote work opportunity within the United States.Full-TimePrincipal
Salary$160,000 to $190,000 per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 8+ years
- Required Skills
- Python
Requirements
- Bachelor’s degree in a technology-related discipline or equivalent professional experience.
- 8+ years of experience in IAM, PAM, or security architecture in large enterprise environments.
- Expertise in Active Directory (multi-domain/forest), Microsoft Entra ID, and Okta (federation, conditional access, hybrid sync).
- Hands-on experience with an enterprise PAM platform at an architecture or lead engineering level (Delinea strongly preferred).
- Understanding of cloud IAM (AWS, Azure, GCP, OCI) including workload identity and cross-cloud access patterns.
- Knowledge of AI agent architectures, service identities, and non-human identity governance.
- Experience with secrets-management tools like HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager.
- Strong command of authentication protocols (SAML/OIDC, OAuth 2.0, Kerberos/NTLM, LDAP/LDAPS, PKI/certificates, MFA).
- Familiarity with compliance frameworks including SOX, HIPAA, PCI DSS, and ISO 27001.
- Proficiency in automation using PowerShell, Python, and REST APIs.
- Experience with CI/CD pipelines and infrastructure-as-code (Terraform, ARM, CloudFormation).
- Ability to maintain a dedicated, secure remote workspace with reliable high-speed internet connectivity.
Responsibilities
- Define and maintain enterprise security architecture across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity environments.
- Serve as the architectural authority for identity security decisions, aligning cloud and application teams with enterprise standards.
- Establish enterprise standards for Agentic Identity, including lifecycle management and governance for AI agents and non-human identities.
- Define security requirements and lead the implementation of the Delinea PAM platform, including Secret Server and Privilege Manager.
- Design privileged access controls based on least privilege, just-in-time administration, and session monitoring.
- Oversee secrets governance covering API keys, tokens, certificates, and vaulting across infrastructure and CI/CD pipelines.
- Drive the remediation of hardcoded or exposed secrets across source code and configuration environments.
View Full Description & ApplyYou'll be redirected to the employer's site