This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal IAM/PAM Security Architect based in the United States.
The Principal IAM/PAM Security Architect will shape enterprise security architecture across a complex, multi-domain identity environment.
You’ll define standards spanning Active Directory, Microsoft Entra ID, Okta, and major cloud platforms including AWS, Azure, GCP, and OCI.
The role combines strategic architecture with hands-on technical leadership across identity, privileged access, and secrets governance.
You’ll lead enterprise PAM initiatives, establish secure controls for privileged accounts, and strengthen the protection of sensitive credentials and secrets.
A key focus will be defining emerging standards for AI agents and other non-human identities as enterprise adoption of agentic technologies evolves.
You’ll collaborate with identity, cloud, application, security, and engineering teams to create controls that are scalable, consistent, and audit-ready.
This is a high-impact remote opportunity for an experienced security architect who can turn complex identity challenges into practical enterprise standards.
Accountabilities
- Define and maintain enterprise security architecture and standards across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity environments, covering authentication, authorization, and identity lifecycle controls.
- Serve as the architectural authority for identity security decisions, aligning platform, cloud, and application teams with enterprise standards.
- Lead architecture reviews and risk assessments for new identity integrations, platform migrations, and mergers and acquisitions.
- Establish enterprise standards for Agentic Identity, including governance, lifecycle management, authentication, authorization, provisioning, scoped entitlements, and deprovisioning for AI agents and other non-human identities.
- Monitor developments in agentic AI and non-human identity technologies and advise leadership on emerging security risks, standards, and vendor capabilities.
- Define security requirements and lead the enterprise implementation of the Delinea PAM platform, including Secret Server and Privilege Manager.
- Design privileged access controls based on least privilege, just-in-time and just-enough administration, session monitoring, and credential rotation across on-premises and cloud environments.
- Oversee onboarding of privileged accounts and systems and ensure PAM controls produce audit-ready evidence aligned with frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001.
- Establish and maintain enterprise secrets governance covering API keys, OAuth/OATH tokens, service account credentials, certificates, vaulting, rotation, and secure distribution.
- Drive the identification and remediation of hardcoded, unmanaged, or exposed secrets across source code, configuration environments, and CI/CD pipelines.
- Develop metrics and reporting that measure secrets governance maturity, compliance, and remediation progress.
- Participate in and help lead architecture review boards, governance forums, and risk committees focused on identity and privileged access.
- Maintain reference architectures, security standards, roadmaps, and supporting documentation for identity, PAM, and secrets governance.
- Advise technical and business stakeholders on identity risk and control design for new initiatives while mentoring engineers responsible for implementing identity, PAM, and secrets solutions.
- Support strategic initiatives and special projects related to enterprise security architecture as required.
- Bachelor’s degree in a technology-related discipline or equivalent professional experience.
- 8+ years of experience in identity and access management, privileged access management, security architecture, or related security roles within large and complex enterprise environments.
- Demonstrated experience designing and implementing security standards across hybrid identity environments involving Active Directory, cloud IAM, and SaaS identity providers.
- Hands-on experience with an enterprise PAM platform at an architecture or lead engineering level; Delinea experience is strongly preferred.
- Strong expertise with Active Directory, including multi-domain and multi-forest architectures, as well as Microsoft Entra ID and Okta, including federation, conditional access, and hybrid identity synchronization.
- Strong understanding of cloud IAM across AWS, Azure, GCP, and OCI, including IAM roles and policies, workload identity, federation, and cross-cloud access patterns.
- Experience with AI agent architectures, service identities, workload identities, and emerging approaches to non-human identity governance.
- Hands-on experience with Delinea Secret Server and Privilege Manager, along with broader secrets-management technologies such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager.
- Strong knowledge of authentication and authorization protocols, including Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA.
- Experience applying security and compliance frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001 to identity, privileged access, and secrets controls.
- Experience using PowerShell, Python, and REST APIs to automate identity, PAM, and secrets lifecycle processes.
- Familiarity with CI/CD pipelines and infrastructure-as-code technologies such as Terraform, ARM, and CloudFormation.
- Exceptional analytical and architectural problem-solving abilities, with the capacity to translate complex multi-domain identity environments into clear, scalable standards.
- Strong communication and stakeholder-management skills, with the ability to explain architecture, risk, and security decisions to both technical and business audiences.
- Ability to work independently, maintain focus, interpret complex information, assess risks, and make timely decisions.
- Relevant security certifications such as CISSP, CISM, SABSA, or CCSP are preferred.
- Ability to maintain a dedicated, secure remote workspace with reliable high-speed internet connectivity.
- Base salary ranging from $160,000 to $190,000 per year, depending on experience, education, skills, certifications, and business needs.
- Eligibility for a discretionary bonus.
- Remote work opportunity within the United States.
- Medical, dental, and vision insurance.
- Disability and life insurance coverage.
- 401(k) savings plan.
- Paid family leave.
- 9 paid holidays per year.
- 17-27 days of paid time off (PTO), depending on level and length of service.
- Comprehensive benefits designed to support a wide range of personal and family needs.
- Opportunity to work on enterprise-scale identity, privileged access, secrets governance, and emerging AI identity challenges.

