Haystack
← Back to Jobs
Technology

Principal Cybersecurity Architect

Spear StaffingUnited States🇺🇸United StatesPosted 5 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Leader

Job Description

Role : Principal Cybersecurity Architect - Identity, IAM & Zero Trust
LOCATTION : REMOTE
Duration:12+months

Interview: video

 

 

 

 

Role Summary

 

Looking for a Principal Cybersecurity Architect to own the enterprise security architecture across identity, access management, and Zero Trust. This is a senior individual contributor role with significant influence over how people, machines, and workloads authenticate, authorize, and access resources across our environment.

Responsibilities

·               Partner with IT, infrastructure, and business stakeholders to integrate security into technology decisions

·               Mentor and guide security engineers on architecture standards and design decisions

Zero Trust Architecture

·               Design and mature a Zero Trust architecture (ZTNA, MFA, PAM) spanning identity, device trust, network access, and application security — grounded in NIST SP 800-207 and BeyondCorp principles.

·               Define reference architectures, security patterns, and guardrails consumed across engineering and infrastructure teams

·               Lead threat modeling and security architecture reviews for major platform changes and initiatives

·               Evaluate and select security tooling (SASE, SSE, ZTNA, NDR, EDR) aligned to the overall architecture strategy

·               Drive continuous improvement of Zero Trust posture through gap assessments and maturity modelling 

Identity & Access Management (IAM)

·               Own the enterprise IAM architecture — covering workforce identity, B2B federation, machine identities, and cloud entitlements

·               Design and govern identity lifecycle management: provisioning, role assignment, access reviews, and deprovisioning — ensuring least privilege is enforced by default and not by exception

·               Architect federation and SSO standards across the enterprise: SAML 2.0, OIDC, OAuth 2.0 — including integrations with third-party SaaS, partner tenants, and customer-facing portals

·               Define authentication assurance levels by resource sensitivity, aligning MFA requirements to NIST AAL2/AAL3 — with a clear roadmap toward phishing-resistant MFA (FIDO2/WebAuthn) for privileged and high-risk access

·               Lead the PAM architecture — credential vaulting, just-in-time privilege, session recording, and endpoint privilege management — in partnership with the security operations team

·               Govern cloud entitlements across AWS, Azure, and Google Cloud Platform through a CIEM framework: identify over-permissioned roles, enforce least privilege for service principals and IAM roles, and manage cross-account trust relationships

·               Establish and maintain a non-human identity strategy: service accounts, API keys, application credentials, and pipeline secrets — eliminating hardcoded credentials and enforcing dynamic secrets via a secrets management platform

·               Drive identity governance processes: access certification campaigns, segregation of duties (SoD) controls, and role-based access control (RBAC) model design

·               Partner with HR, IT, and business application owners to ensure joiner/mover/leaver processes are automated and auditable

Governance & Stakeholder Engagement

·               Define security architecture standards, policies, and exception management processes

·               Mentor security engineers and serve as the escalation point for complex identity and access design decisions

·               Produce architecture artefacts — threat models, data flow diagrams, trust zone maps — suitable for both technical and executive audiences

·               Contribute to the security roadmap and annual planning, translating risk priorities into architectural investments

Qualifications

·               8+ years in information security, with 4+ years in an architecture or senior engineering role

·               Deep expertise in Zero Trust frameworks (NIST SP 800-207, BeyondCorp) and identity-centric security

·               Strong understanding of threat modeling methodologies (STRIDE, PASTA, ATT&CK)

·               Hands-on experience with enterprise IAM platforms — Microsoft Entra ID, Okta, Ping Identity, or equivalent

·               Strong grasp of federation protocols: SAML 2.0, OIDC, OAuth 2.0, SCIM

·               Experience with PAM platforms (CyberArk, BeyondTrust, Delinea) and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault)

·               Familiarity with CIEM tooling and cloud IAM governance across at least two major cloud platforms

·               Experience designing and governing identity lifecycle and IGA processes (SailPoint, Saviynt, or equivalent a plus)

·               Strong understanding of threat modelling methodologies (STRIDE, ATT&CK) and their application to identity attack surfaces

·               Excellent communication skills — able to translate complex architecture into clear guidance for engineers, business stakeholders, and executives

·               Provan experience using diplomacy skills

Certifications (preferred): CISSP, SABSA, TOGAF, Microsoft SC-100, Okta Certified Architect, or equivalent

 

Skills

AWS
MFA
OAuth
SAML
SSO
Azure
Google Cloud
Vault
Zero Trust

Similar jobs