Haystack
← Back to Jobs
Other

Identity and Access Management (IAM) Architect (MN)

Dahl ConsultingUnited States🇺🇸United StatesPosted 27 Jul 2026

Quick Overview

Salary
€30/hr
Work Type
On Site
Level
Mid Senior

Job Description

Title: Identity and Access Management (IAM) Architect
Location: Remote (May require onsite work in Minneapolis, MN)
Job Type: Contract (3 Months)
Compensation: $75.19 - $120.30/hr
Industry: Retail

Shift Information: If a local candidate is selected, there may be an onsite requirement.
---
About the Role
Our firm is partnering with a leading national retail corporation to identify an experienced Identity and Access Management (IAM) Architect to lead enterprise identity strategy across their Google Cloud and Microsoft ecosystems. As one of the largest retailers in the country, our client manages a vast, complex data environment that supports millions of customers and thousands of internal and external stakeholders. This is a high-impact, hands-on architecture role central to a large-scale enterprise Data Strategy initiative.

Job Description
We are seeking an Identity and Access Management (IAM) Architect to design and implement secure federation, authorization, and analytics access controls spanning Google Workforce Identity Federation, Google Workload Identity Federation, Google Cloud IAM, Google Workspace, BigQuery, Looker, Microsoft Entra ID, and Power BI.
This is a hands-on architecture role requiring direct implementation experience across Google Cloud and Microsoft identity platforms. The ideal candidate will bring deep expertise designing scalable, secure, and highly governed identity solutions that support enterprise analytics and third-party collaboration. The architect will lead the design and implementation of secure access models for employees, applications, workloads, and external vendors using federated identities originating from Microsoft Entra ID, third-party identity providers, and on-premises enterprise directories.
Role Overview
The IAM Architect will help build the end-to-end identity architecture integrating Microsoft Entra ID with Google Cloud. This includes federated authentication for workforce users, secure workload identity for applications, and fine-grained data access controls for BigQuery, including secure consumption through Microsoft Power BI and Google Looker.
Strategic Responsibilities
  • Define and implement third-party vendor access strategies for Power BI and Looker, leveraging federated identities, conditional access policies, and least-privilege principles to ensure secure external collaboration.
  • Design and govern Microsoft Entra B2B guest access, Google Cloud external identity configurations, and cross-tenant collaboration models.
  • Lead enterprise implementation of Google Workforce and Workload Identity Federation integrated with Microsoft Entra ID.
  • Architect secure integration between BigQuery and Microsoft Power BI using federated identities.
  • Implement fine-grained data access controls, including row-level and column-level security.
  • Secure Looker and Google Workspace using enterprise SSO and lifecycle management.
  • Partner with security, cloud, and data engineering teams to govern platform access at scale.

Qualifications
Required Qualifications:
  • Deep expertise in Google Cloud IAM, Workforce Identity Federation, and Workload Identity Federation.
  • Advanced experience with Microsoft Entra ID, including federation, Conditional Access, and B2B collaboration.
  • Experience designing cross-cloud identity architectures in complex enterprise environments.
  • Demonstrated hands-on expertise in:
    • Google Workforce Identity Federation
    • Google Workload Identity Federation
    • Google Cloud IAM, including custom and conditional roles
    • Microsoft Entra ID federation and Conditional Access
  • Advanced knowledge of SAML 2.0, OAuth 2.0, OpenID Connect, and token-based federation flows.
  • Strong understanding of identity trust models, claims-based authorization, and token lifecycles.
  • Experience implementing row-level and column-level security in BigQuery.
  • Experience securing Looker with enterprise identity providers.
  • Experience securing platform software that provides semantic layer services.
  • Proven ability as a detail-oriented Power BI developer, with hands-on experience building and securing reports and datasets.
Preferred Qualifications:
  • Experience with AtScale or comparable semantic layer platforms.
  • Familiarity with additional enterprise analytics and identity governance tooling.

Benefits
Dahl Consulting is proud to offer a comprehensive benefits package to eligible employees that will allow you to choose the best coverage to meet your family’s needs. For details, please review the DAHL Benefits Summary: .

How to Apply
Take the first step on your new career path! To submit yourself for consideration for this role, simply click the apply button and complete our mobile-friendly online application. Once we’ve reviewed your application details, a recruiter will reach out to you with next steps!

Equal Opportunity Statement
As an equal opportunity employer, Dahl Consulting welcomes candidates of all backgrounds and experiences to apply. If this position sounds like the right opportunity for you, we encourage you to take the next step and connect with us. We look forward to meeting you!

#LI-CF1
#LI-Hybrid


Skills

Looker
OAuth
SAML
SSO
BigQuery
Google Cloud
Google Workspace
Power BI

Similar jobs