Haystack
← Back to Jobs
Other
KT

IAM Architect

Kforce Technology StaffingManhattan Beach, CA🇺🇸United StatesPosted Sep 30, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Manhattan Beach, CA, United States
Posted
Yesterday
OAuthSAMLSSOLDAPLESSRisk ManagementStakeholder ManagementZero Trust

Job Description

RESPONSIBILITIES

A Kforce client in Manhattan Beach, CA is currently seeking an IAM Architect for a permanent, fully onsite role.

Summary

The IAM Architect will be responsible for designing, implementing, and maintaining enterprise Identity and Access Management (IAM) solutions across workforce, customer, privileged, and non-human identities. This role will serve as a technical leader, partnering with infrastructure, cloud, application, and cybersecurity teams to develop secure, scalable, and resilient identity architectures that support business objectives and reduce organizational risk.

Key Responsibilities

  • Lead the architecture and design of enterprise IAM solutions across workforce, customer, privileged, contractor, and machine identities
  • Develop and implement identity lifecycle management processes, including joiner, mover, and leaver workflows
  • Design secure authentication, authorization, federation, and access governance solutions
  • Partner with engineering, security, cloud, and application teams to integrate identity solutions across enterprise systems
  • Conduct architecture reviews and provide technical guidance for complex IAM initiatives
  • Design and implement privileged access management (PAM) and governance controls
  • Apply Zero Trust security principles to reduce identity-related risk and strengthen access controls
  • Evaluate and mitigate identity attack paths, credential risks, privilege escalation risks, and authentication vulnerabilities
  • Collaborate with Security Operations and Incident Response teams to improve identity monitoring, detection, and response capabilities
  • Automate IAM processes through APIs, scripting, infrastructure-as-code, and workflow automation tools
  • Ensure IAM solutions support regulatory, audit, privacy, and security requirements
REQUIREMENTS:
  • Extensive experience designing, implementing, and supporting enterprise Identity and Access Management solutions
  • Experience serving as a technical architect, lead engineer, or IAM subject matter expert
  • Experience securing workforce, customer, third-party, and non-human identities
  • Experience with cloud IAM platforms in enterprise environments
  • Experience designing access governance, role-based access controls, and entitlement management solutions
  • Experience supporting IAM integrations across cloud, enterprise, and application environments
  • Strong expertise in: Identity Lifecycle Management; Authentication & Authorization; Federation & Single Sign-On (SSO); Identity Governance & Administration (IGA); Privileged Access Management (PAM); Cloud Identity & Access Management
  • Deep knowledge of Zero Trust architecture and least-privilege security models
  • Strong knowledge of: SAML; OAuth 2.0; OpenID Connect (OIDC); SCIM; LDAP; Identity APIs and modern federation technologies
  • Strong understanding of security risks involving credentials, tokens, sessions, privileged accounts, service accounts, and machine identities
  • Excellent documentation and architectural governance skills
  • Strong communication and stakeholder management abilities
  • Strong analytical, problem-solving, and decision-making capabilities
  • Ability to explain complex security concepts to both technical and business audiences
  • Ability to influence technical direction across multiple teams and departments
  • Ability to troubleshoot and resolve complex identity and access challenges
Preferred:
  • Relevant IAM, security, cloud, or architecture certifications
  • Experience operating IAM programs within global, hybrid, or multi-cloud environments
  • Experience with Identity Threat Detection & Response (ITDR)
  • Experience with attack-path analysis, identity risk management, or exposure management programs
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.

Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law. This job is not eligible for bonuses, incentives or commissions. Kforce is an Equal Opportunity/Affirmative Action Employer.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages.

You will always have the right to cease communicating via text by using key words such as STOP.

Similar jobs