Principal IAM/PAM Security Architect

New
J
JobgetherSecurity & IT
Remote work opportunity within the United States.Full-TimePrincipal
Salary$160,000 to $190,000 per year
Apply NowOpens the employer's application page

Job Details

Experience
8+ years
Required Skills
Python

Requirements

  • Bachelor’s degree in a technology-related discipline or equivalent professional experience.
  • 8+ years of experience in IAM, PAM, or security architecture in large enterprise environments.
  • Expertise in Active Directory (multi-domain/forest), Microsoft Entra ID, and Okta (federation, conditional access, hybrid sync).
  • Hands-on experience with an enterprise PAM platform at an architecture or lead engineering level (Delinea strongly preferred).
  • Understanding of cloud IAM (AWS, Azure, GCP, OCI) including workload identity and cross-cloud access patterns.
  • Knowledge of AI agent architectures, service identities, and non-human identity governance.
  • Experience with secrets-management tools like HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager.
  • Strong command of authentication protocols (SAML/OIDC, OAuth 2.0, Kerberos/NTLM, LDAP/LDAPS, PKI/certificates, MFA).
  • Familiarity with compliance frameworks including SOX, HIPAA, PCI DSS, and ISO 27001.
  • Proficiency in automation using PowerShell, Python, and REST APIs.
  • Experience with CI/CD pipelines and infrastructure-as-code (Terraform, ARM, CloudFormation).
  • Ability to maintain a dedicated, secure remote workspace with reliable high-speed internet connectivity.

Responsibilities

  • Define and maintain enterprise security architecture across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity environments.
  • Serve as the architectural authority for identity security decisions, aligning cloud and application teams with enterprise standards.
  • Establish enterprise standards for Agentic Identity, including lifecycle management and governance for AI agents and non-human identities.
  • Define security requirements and lead the implementation of the Delinea PAM platform, including Secret Server and Privilege Manager.
  • Design privileged access controls based on least privilege, just-in-time administration, and session monitoring.
  • Oversee secrets governance covering API keys, tokens, certificates, and vaulting across infrastructure and CI/CD pipelines.
  • Drive the remediation of hardcoded or exposed secrets across source code and configuration environments.
View Full Description & ApplyYou'll be redirected to the employer's site
$160,000 to $190,000 per year
Apply Now