368,941open jobs
9,452companies
47,951added this week
Browse all
Salary
$145k – $175k per year
Location
Remote (United States)
Seniority
Architect · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
AHEAD helps enterprises build modern, secure, and scalable digital platforms by combining cloud, data, AI, and automation. Their consulting and managed services drive real business impact through smarter IT.

The Senior Identity Application Architect, CIAM/IAM, is responsible for leading the architecture, design, and evolution of identity solutions that support secure, scalable, and resilient customer and workforce access across the organization.

This role defines target-state architecture and implementation patterns for customer identity and access management and enterprise identity and access management, including authentication, authorization, federation, lifecycle orchestration, delegated administration, and identity data flows across cloud and enterprise platforms.

The architect partners with cybersecurity, infrastructure, application owners, product teams, and business stakeholders to translate business, security, privacy, and user experience requirements into practical identity architectures. This role also provides technical leadership for integrations across platforms such as Okta, Auth0, Azure, AWS, Salesforce, ServiceNow, and custom applications, with an emphasis on security, reliability, maintainability, and business enablement.

Duties/Responsibilities

      • Lead the architecture and design of CIAM and IAM solutions that support secure customer, partner, and workforce identity use cases across digital and enterprise environments.

      • Define reference architectures, technical standards, integration patterns, and guardrails for identity services, authentication flows, authorization models, and lifecycle automation.

      • Architect solutions for federation, single sign-on, adaptive authentication, MFA, delegated administration, identity proofing, registration, account recovery, consent, and progressive profiling.

      • Author an improvement plan to transform the way Agent and Agentic NHI risks are handled, enabling the business to continue rapid Agent creation in a secure manner.

      • Design identity application patterns and integrations using standards and protocols such as OAuth 2.0, OpenID Connect, SAML, SCIM, LDAP, REST APIs, webhooks, and event-driven architectures.

      • Partner with engineering teams to guide implementation of identity-enabled applications, APIs, portals, and workflows while ensuring alignment to architecture principles and security requirements.

      • Lead solution design for customer onboarding, workforce onboarding, joiner-mover-leaver processes, access request workflows, and fine-grained entitlement or role models where applicable.

      • Drive architecture decisions for identity data models, directory strategy, attribute governance, role and group strategy, policy design, and integration with HR, CRM, ITSM, and other enterprise platforms.

      • Evaluate and improve existing identity platforms, custom integrations, and application access patterns to reduce risk, technical debt, and operational friction.

      • Ensure identity solutions are designed for resilience, scalability, observability, auditability, privacy, and compliance by design.

      • Produce and maintainarchitecture diagrams, standards, roadmaps, decision records, and implementation guidance for technical and non-technical stakeholders.

      • Facilitate design reviews, threat-informed architecture reviews, and technical governance activities for identity-related initiatives.

      • Mentor engineers and administrators, providing architectural direction, implementation guidance, and best practices for secure identity application development and integration.

      • Collaborate with vendors and internal teams to assess new capabilities, validatepatterns, and recommend improvements aligned to strategic identity goals.

      • Stay current on IAM and CIAM trends, standards, threats, and vendor capabilities, and translate that knowledge into actionable architectural recommendations.

Education and Experience

    • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field, or equivalent practical work experience.

    • Minimum 7years of progressive experience in identity and access management, application security, or enterprise architecture, including significant experiencedesigning identity solutions in complex environments.

    • Minimum 4years of experience architecting or leading implementations for CIAM and/or IAM platforms, including authentication, federation, authorization, and lifecycle orchestration use cases.

    • Practical experience designing integrations across identity providers, cloud platforms, customer-facing applications, HR systems, CRM platforms, IT service management systems, and related enterprise applications.

    • Experience with platforms and services such as Okta, Auth0, Microsoft Entra ID, AWS, Azure, Salesforce, ServiceNow, or comparable identity and business platforms.

    • Experience leading technical design for secure APIs, identity-aware applications, and event-driven or service-based integrations.

    • Demonstrated success inbalancing security, privacy, user experience, scalability, and operational support requirements in production identity architectures.

    • Required certification in at least one relevant identity or cybersecurity discipline, such as CISSP, CCSP, IDPro, Okta Certified Professional or Administrator, Okta Certified Developer, Microsoft SC-300, AWS Security Specialty, or comparable credentials.

Required Knowledge, Skills, Abilities

      • Strong expertisein CIAM and IAM architecture, including authentication, authorization, federation, identity lifecycle management, provisioning and deprovisioning, delegated administration, and access governance concepts.

      • Deep understanding of identity standards and protocols, including OAuth 2.0, OpenID Connect, SAML, SCIM, and related token, session, and federation concepts.

      • Experience designing customer identity journeys with attention to registration, login, MFA, passwordlessoptions, account recovery, consent, profile management, and user experience.

      • Experience designing enterprise IAM patterns for role-based access, attribute-based access, entitlement management, least privilege, and segregation of duties.

      • Strong understanding of identity-related security principles, including session security, secretsprotection, API security, bot and fraud considerations, logging, monitoring, threat modeling, and auditability.

      • Ability to define architecture roadmaps, target states, transition plans, and decision frameworks for identity modernization initiatives.

      • Experience working across engineering, infrastructure, security, product, and business teams to align requirements and drive implementation outcomes.

      • Ability to review solution designs and code or configuration patterns at the right level to ensure architectural alignment without owning every implementation detail.

      • Familiarity with modern software and platform engineering practices, including CI/CD, infrastructure ascode, automated testing, observability, and secure development practices.

      • Demonstrated willingness and ability to adopt AI-assisted engineering tools for code generation, code review, test creation, and developer productivity, using tools such as Claude, GitHub Copilot, Cursor, or similar technologies in a secure and effective manner.

      • Strong written and verbal communication skills, including the ability to present architecture decisions, tradeoffs, and recommendations to technical and executive stakeholders.

      • Strong problem-solving skills and the ability to diagnose complex identity, integration, and access issues across distributed systems.

      • Interest in or experience addressing emerging identity control challenges related to agentic AI, non-human identities, machine identities, and modern IAM governance patterns.

      • Familiarity with Agile delivery practices and tools such as Jira.

Physical Requirements

    • Ability to safely and successfully perform the essential job functions consistentwith the ADA, FMLA, and other federal, state, and local standards, including meeting qualitative and/or quantitative productivity standards.

    • Ability to maintainregular, punctual attendance consistent with the ADA, FMLA, and other federal, state, and local standards.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,941 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$38k – $91k per year (Estimated) • Remote • Full-Time • 8+ years exp • PhD • Guadalajara
PowerShell
Python
Databases
Amazon Aurora
DynamoDB
AI/ML
Amazon SageMaker
AWS Bedrock
AWS Bedrock AgentCore
Ray
DevOps
Amazon CloudWatch
Amazon EC2
Amazon ECS
Amazon EKS
Amazon EventBridge
Amazon S3
AWS
AWS Lambda
AWS Step Functions
Azure
CI/CD
Datadog
FinOps
GCP
Git
GitLab
GitLab CI
IAM
Jenkins
JFrog Artifactory
Kubernetes
New Relic
Service Mesh
Splunk
Terraform
Cybersecurity
HIPAA
ISO 27001
PCI DSS
SOC 2
Apply
Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Riga
PowerShell
Python
DevOps
AWS
Azure
Azure AKS
Azure DevOps
Bicep
CI/CD
Configuration Management
Docker
FinOps
GCP
Git
GitLab
Jenkins
Kubernetes
Terraform
Apply
$29k – $73k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree • Guadalajara
Python
DevOps
Amazon CloudWatch
Azure
CI/CD
Datadog
Docker
Kubernetes
Prometheus
Terraform
Apply
$222k – $277k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • San Francisco
DevOps
CI/CD
Immutable Infrastructure
Apply
Remote/Hybrid • Full-Time • Riga
C#
JavaScript
TypeScript
C#
ASP.NET Core
Databases
MS SQL
Oracle
Frontend
Angular
React.js
Vue.js
DevOps
Azure
Azure DevOps
Apply
Data Engineer 10 hours ago
$150k – $180k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree
Python
SQL
Python
Hatch
Databases
Snowflake
AI/ML
AI Agents
dbt
Model Context Protocol
Frontend
GraphQL
DevOps
Azure
CI/CD
Analytics
ETL/ELT
Marketing
Salesforce
Apply
$130k – $145k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree
PowerShell
Python
SQL
DevOps
AWS
Azure
FinOps
GCP
Kubernetes
Analytics
Power BI
Tableau
Management
Jira
ServiceNow
Apply
$28k – $66k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Gurgaon
DevOps
VMWare
Apply
NetSuite Developer 5 days ago
$11k – $41k per year (Estimated) • Remote • Full-Time • 3+ years exp
JavaScript
SQL
Apex
Apex
MuleSoft
Databases
Snowflake
Analytics
ETL/ELT
Marketing
Salesforce
Apply
$230k – $290k per year • Remote • Full-Time • 8+ years exp • PhD
Python
AI/ML
AI Agents
Copilot
Anthropic
LLM Guardrails
OpenAI
DevOps
Azure
Azure DevOps
Bicep
CI/CD
FinOps
GitHub Actions
Platform Engineering
Terraform
GitHub
Cybersecurity
Microsoft Entra ID
Apply
See all jobs
This is one of many
368,941 more open roles from verified company boards, updated every day.