Haystack
← Back to Jobs
Other
CD

IAM Architect

Cloud Destinations LLCDallas, TX🇺🇸United StatesPosted Sep 29, 2026

Why This Role Stands Out

As an IAM Architect at Cloud Destinations LLC, you'll shape the future of enterprise identity management, driving innovation in a critical security domain and gaining exposure to cutting-edge multi-cloud identity solutions. This role is ideal for a seasoned professional with strong technical judgment and communication skills who thrives on defining strategic architecture and guiding implementation for significant business impact. Seize this opportunity to advance your career in a dynamic environment and contribute to a robust and secure identity ecosystem.

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Dallas, TX, United States
Posted
Yesterday
AWSMFAOAuthSAMLSSOActive DirectoryAzureCompliancePowerShellPython

Job Description

Position Overview: The Identity Architect will define and guide an enterprise identity architecture that connects authentication, identity governance, privileged access, secrets management, identity security, and multi-cloud identity into a cohesive operating model. This role will help evolve identity and access management (IAM) from platform-specific activities into an identity-as-a-service capability that enables the business while improving security, auditability, and user experience. The architect will combine technical depth, practical judgment, and strong communication to guide technical and business stakeholders through architecture decisions and implementation paths.

Onsite - Dallas 5x a week

Responsibilities:

· Own and maintain the target-state IAM architecture, reference patterns, principles, standards, and technology roadmap.

· Assess current identity capabilities and recommend improvements across Microsoft Active Directory, Microsoft Entra ID, hybrid identity, cloud identity, authentication, authorization, identity governance, privileged access management (PAM), secrets management, and identity security.

· Design how identity governance, PAM, multifactor authentication (MFA), secrets management, directories, applications, and security tooling should work together.

· Establish architecture patterns for human identities, service accounts, application identities, workload identities, privileged identities, and other non-human identities.

· Define identity lifecycle, joiner/mover/leaver, access request, access review, role, entitlement, privileged access, and exception management patterns.

· Guide single sign-on (SSO), MFA, Conditional Access, federation, identity proofing, adaptive access, and application integration decisions.

· Evaluate integration approaches using application programming interfaces (APIs), connectors, System for Cross-domain Identity Management (SCIM), Security Assertion Markup Language (SAML), OAuth 2.0, OpenID Connect, and related protocols.

· Provide architecture guidance for identity across Microsoft Azure and Amazon Web Services (AWS), including cloud identity models, account structures, roles, permissions, and governance.

· Translate business, security, regulatory, and operational requirements into architecture decisions, detailed requirements, implementation sequencing, and transition plans.

· Review proposed designs and implementations for least privilege, resiliency, supportability, auditability, and alignment with approved standards.

· Partner with IAM leadership, identity engineers, analysts, application teams, cloud teams, security operations, audit, compliance, and organizational change management.

· Use PowerShell, Python, APIs, data exports, or other practical techniques when a platform limitation requires an alternate solution or automation path.

· Maintain architecture documentation, decision records, data flows, integration diagrams, control mappings, and operational standards.

· Support remediation planning for identity data quality, orphaned accounts, stale identities, over-provisioned access, service-account ownership, and privileged-access risk.

· Advise on identity monitoring, detection, incident response, and integration with existing security tooling.

Qualifications:

· 10 or more years of progressive experience in identity, access management, cybersecurity, infrastructure, enterprise architecture, or a closely related discipline.

· 7 or more years of hands-on IAM architecture or senior IAM engineering experience in a large enterprise environment.

· Strong experience with Microsoft Active Directory and Microsoft Entra ID, including hybrid identity, directory synchronization, authentication, authorization, Conditional Access, MFA, and privileged access.

· Demonstrated experience designing or integrating at least two enterprise IAM platforms, with Saviynt preferred and SailPoint accepted.

· Experience with CyberArk or a comparable PAM platform, secrets management, and privileged identity controls.

· Strong understanding of IAM governance, lifecycle management, access reviews, role-based access control, segregation of duties, least privilege, and audit evidence.

· Practical knowledge of AWS and Azure identity and security models.

· Experience with APIs, application integration patterns, federation, SAML, OAuth 2.0, OpenID Connect, SCIM, and automation.

· Ability to analyze complex environments, make architecture decisions, document them clearly, and influence stakeholders without direct authority.

· Ability to work onsite in the Dallas-Fort Worth area approximately 2 to 3 days per week.

· Preferred qualifications:

· Experience in electric utilities, critical infrastructure, North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP), Sarbanes-Oxley Act (SOX), IT general controls, or similarly regulated environments.

· Microsoft identity or security certification, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Saviynt, SailPoint, CyberArk, AWS, or Azure certification.

· Experience with identity threat detection and response, identity security posture management, service-account governance, or non-human identity programs.

· Experience building identity standards, operating models, roadmaps, and governance forums.

Tools and Technologies:

  • Microsoft Active Directory
  • Microsoft Entra ID
  • Azure
  • AWS
  • Saviynt or SailPoint
  • CyberArk or comparable PAM platforms
  • MFA solutions
  • Secrets-management technologies
  • PowerShell
  • Python
  • APIs
  • SCIM
  • SAML
  • OAuth 2.0
  • OpenID Connect

Similar jobs