Quick Overview
Job Description
RESPONSIBILITIES
A Kforce client in Manhattan Beach, CA is currently seeking an IAM Architect for a permanent, fully onsite role.
Summary
The IAM Architect will be responsible for designing, implementing, and maintaining enterprise Identity and Access Management (IAM) solutions across workforce, customer, privileged, and non-human identities. This role will serve as a technical leader, partnering with infrastructure, cloud, application, and cybersecurity teams to develop secure, scalable, and resilient identity architectures that support business objectives and reduce organizational risk.
Key Responsibilities
- Lead the architecture and design of enterprise IAM solutions across workforce, customer, privileged, contractor, and machine identities
- Develop and implement identity lifecycle management processes, including joiner, mover, and leaver workflows
- Design secure authentication, authorization, federation, and access governance solutions
- Partner with engineering, security, cloud, and application teams to integrate identity solutions across enterprise systems
- Conduct architecture reviews and provide technical guidance for complex IAM initiatives
- Design and implement privileged access management (PAM) and governance controls
- Apply Zero Trust security principles to reduce identity-related risk and strengthen access controls
- Evaluate and mitigate identity attack paths, credential risks, privilege escalation risks, and authentication vulnerabilities
- Collaborate with Security Operations and Incident Response teams to improve identity monitoring, detection, and response capabilities
- Automate IAM processes through APIs, scripting, infrastructure-as-code, and workflow automation tools
- Ensure IAM solutions support regulatory, audit, privacy, and security requirements
- Extensive experience designing, implementing, and supporting enterprise Identity and Access Management solutions
- Experience serving as a technical architect, lead engineer, or IAM subject matter expert
- Experience securing workforce, customer, third-party, and non-human identities
- Experience with cloud IAM platforms in enterprise environments
- Experience designing access governance, role-based access controls, and entitlement management solutions
- Experience supporting IAM integrations across cloud, enterprise, and application environments
- Strong expertise in: Identity Lifecycle Management; Authentication & Authorization; Federation & Single Sign-On (SSO); Identity Governance & Administration (IGA); Privileged Access Management (PAM); Cloud Identity & Access Management
- Deep knowledge of Zero Trust architecture and least-privilege security models
- Strong knowledge of: SAML; OAuth 2.0; OpenID Connect (OIDC); SCIM; LDAP; Identity APIs and modern federation technologies
- Strong understanding of security risks involving credentials, tokens, sessions, privileged accounts, service accounts, and machine identities
- Excellent documentation and architectural governance skills
- Strong communication and stakeholder management abilities
- Strong analytical, problem-solving, and decision-making capabilities
- Ability to explain complex security concepts to both technical and business audiences
- Ability to influence technical direction across multiple teams and departments
- Ability to troubleshoot and resolve complex identity and access challenges
- Relevant IAM, security, cloud, or architecture certifications
- Experience operating IAM programs within global, hybrid, or multi-cloud environments
- Experience with Identity Threat Detection & Response (ITDR)
- Experience with attack-path analysis, identity risk management, or exposure management programs
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law. This job is not eligible for bonuses, incentives or commissions. Kforce is an Equal Opportunity/Affirmative Action Employer.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
You will always have the right to cease communicating via text by using key words such as STOP.
Similar jobs
- W&
Cryptologic Cyber Planner 2 with Security Clearance
NewWeeghman & Briggs
Annapolis Junction, MD🇺🇸$113.3k - $125.9k/yrOn-siteYesterdayAgileTechnology - IO
Cyber Operations Engineer with Security Clearance
NewImagine One Technology & Management Ltd
Keyport, WA🇺🇸HybridYesterdayPenetration TestingTechnology - PS
Sr. System Vulnerability Analyst with Security Clearance
NewPower3 Solutions
Fort Meade, MD🇺🇸HybridYesterdayPenetration TestingTechnology - CR
Cyber All-Source Analyst, Mid with Security Clearance
NewClear Resolution Consulting, LLC
Fort Meade, MD🇺🇸$95k - $125k/yrRemoteYesterdayAgileTechnology - AW
Senior Security Engineer, Forward Deployed Engineering, AWS Forw with Security Clearance
NewAmazon Web Services, Inc.
Boston, MA🇺🇸On-siteYesterdayMicroservicesScalaAWS+7Technology - AS
Security Engineer, Forward Deployed Engineering, AWS Forward Dep with Security Clearance
NewAmazon.com Services LLC
Boston, MA🇺🇸$159.3k - $202.4k/yrHybridYesterdayMicroservicesScalaAWS+6Technology