Haystack
← Back to Jobs
Other
TE

Principal Identity and Access Management (IAM) Architect

TekDallasChevy Chase, MD🇺🇸United StatesPosted Sep 28, 2026

Quick Overview

Seniority
Leader
Work mode
Hybrid
Location
Chevy Chase, MD, United States
Posted
20 hours ago
AWSMFASAMLSOC 2SSOComplianceContract ReviewGoogle CloudPerformance ManagementWorkday

Job Description

Principal Identity and Access Management (IAM) Architect

Location: Chevy Chase, MD — Hybrid (3 days onsite / 2 days remote)

Duration: Long Term Contract

Position Summary

The Principal Identity and Access Management (IAM) Architect is a senior technical leadership role responsible for the strategic direction of Client's identity and access management program. This position leads a comprehensive assessment of the current IAM tool landscape (including Okta and Workday-driven identity processes, and emerging integrations such as Claude Desktop and other AI platforms), and develops and drives execution of a multi-year IAM strategy that positions Client's identity infrastructure to meet current and future organizational, security, and compliance needs.

This is primarily a strategy, architecture, and oversight role, with a smaller, targeted component of direct operation and implementation. The Principal IAM Architect sets technical direction, evaluates and selects tools and platforms, and directly manages a team of up to three (3) IAM Engineers and Analysts who perform the majority of day-to-day implementation, configuration, and operational support; the Architect is expected to engage hands-on for high-complexity design work, proof-of-concept builds, critical escalations, and evaluation of new tools or platforms where direct, current technical exposure is required to make sound architectural decisions. The successful candidate will have deep, credible technical grounding in IAM — typically built through years as a senior IAM engineer or analyst — combined with demonstrated experience operating at the architect, director, or VP level, translating technical identity risk into strategy, roadmaps, and business decisions for executive stakeholders.

Key Responsibilities

·  Current-State Assessment. Conduct a comprehensive analysis and assessment of client's existing IAM tool implementations and identity processes — including Okta (access management/SSO/MFA), Workday-driven identity lifecycle and provisioning, and identity/access considerations introduced by AI platforms such as Claude Desktop — to identify gaps, redundancies, technical debt, and risk exposure.

·  IAM Strategy Development. Design, document, and lead execution of a multi-year enterprise IAM strategy and roadmap aligned to client’s risk tolerance, compliance obligations, research/business needs, and long-term technology direction.

·  Tool Evaluation and Selection. Own the evaluation, selection, and lifecycle roadmap for IAM, identity governance and administration (IGA), and privileged access management (PAM) tooling, including build-vs-buy and consolidation decisions; assess how emerging technologies — including AI/agentic tools — should be incorporated into or governed by the IAM ecosystem.

·  Architecture and Standards. Define reference architecture, technical standards, and design patterns for identity lifecycle management, authentication, authorization, provisioning/deprovisioning, federation (SAML/OIDC), and access governance across client's tool ecosystem.

·  Human and Machine Identity Governance. Set the strategy and standards for managing both human and non-human (service account, API key, workload, and other machine) identities across client, including enterprise-wide multi-factor authentication (MFA), access permissions defined on a least-privilege basis, clear ownership and attribution for every machine identity, and lifecycle management practices that ensure timely review and decommissioning of stale, orphaned, or under-used accounts of either type.

·  People Leadership and Technical Oversight. Directly manage a team of up to three (3) IAM Engineers and Analysts, including performance management, staff development, and workload prioritization; provide architectural direction and design review, and mentor staff on architecture and best practices. This role sets direction and reviews work product — the engineering and analyst team performs the majority of day-to-day build, configuration, and operational execution — while the Architect personally engages hands-on for complex design problems, proof-of-concept work, and critical escalations.

·  Stakeholder Engagement and Governance. Partner with HR/Workday system owners, IT infrastructure, application owners, Legal, Compliance, and executive leadership to align the IAM roadmap with business needs; present strategy, roadmap progress, and risk posture to senior leadership and governance bodies.

·  Risk, Audit, and Compliance. Ensure the IAM program addresses audit findings and known risk areas (e.g., segregation of duties, least privilege, access certification, orphaned/stale access) and satisfies relevant regulatory, contractual, and grant-related compliance requirements.

·  Vendor and Budget Management. Manage strategic vendor relationships and contract review for IAM/IGA/PAM platforms; develop business cases and contribute to budget planning for tool and program investments.

·  Metrics and Reporting. Establish KPIs and maturity metrics for the IAM program and report progress, risk, and roadmap status to the Director of Cybersecurity and other stakeholders.

Minimum Qualifications

•     Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent professional experience.

•     Relevant certifications such as CISSP, CISM, Okta Certified Professional/Architect, SC-300, or an enterprise architecture credential (e.g., TOGAF).

•     10+ years of progressive experience in identity and access management, including substantial time as a senior IAM analyst or senior IAM engineer.

•     3–5 years of experience in a senior IAM architect, IAM Director, or VP of Identity/IAM-level role, with demonstrated ownership of IAM strategy, architecture, or program leadership — not solely hands-on implementation.

•     Demonstrated experience developing and driving execution of an enterprise-level IAM strategy and roadmap, including tool evaluation, selection, and consolidation decisions.

•     Deep working knowledge of core IAM/IGA concepts: identity lifecycle management, RBAC/ABAC, SSO and federation (SAML, OIDC), multi-factor authentication, privileged access management, provisioning/deprovisioning, and access certification/recertification.

•     Demonstrated skill managing both human and machine (service account, API key, workload) identities, including enforcing MFA, defining access permissions on a least-privilege basis, establishing ownership and attribution for machine identities, and driving lifecycle management and decommissioning of stale or under-used accounts of either type.

•     Direct experience with, or strong working knowledge of, Okta and Workday-driven identity processes; familiarity with the identity and access implications of enterprise AI tools (e.g., Claude Desktop or comparable platforms) is a plus.

•     Prior experience selecting, implementing, or overseeing the implementation of enterprise IAM, IGA, or PAM platforms.

•     Demonstrated experience directly managing engineers or analysts, including performance management, mentorship, and workload prioritization.

•     Excellent written and verbal communication skills, with demonstrated ability to translate technical identity/access risk into business terms for executive and non-technical audiences.

•     Working knowledge of relevant security and compliance frameworks (e.g., NIST Cybersecurity Framework, SOC 2, applicable regulatory or grant-related requirements) as they pertain to identity and access.

Preferred Qualifications

•     Experience in a research institution, higher education, healthcare, or other complex, decentralized nonprofit environment.

•     Experience with cloud identity platforms (e.g., Microsoft Entra ID, AWS IAM, Google Cloud IAM) in addition to Okta.

•     Experience defining governance models for AI/agentic tool access and provisioning within an enterprise identity program.

•     Experience presenting technology strategy and risk to executive leadership, boards, or governance committees.

Similar jobs