Identity & Access Management Architect
Why This Role Stands Out
This hybrid role offers an exciting opportunity to lead a critical identity migration project, significantly impacting enterprise security and providing hands-on experience with cutting-edge IAM solutions. You'll thrive here if you're a proactive architect with a passion for building robust identity ecosystems, and this position is perfect for developing advanced skills in a dynamic environment. Apply now to leverage your expertise and grow your career with a competitive hourly rate and excellent benefits.
Quick Overview
Job Description
Job Title: Identity & Access Management Architect Pay rate: $78.19 - $103.41/hr. Location: Palo Alto, CA (Hybrid) Zip Code: 94304 Duration: 6 Months Start Date: Right Away Keywords: #PaloAltoJobs; #SeniorTechnicalProgramManagerjobs; #Identity&AccessManagementArchitect International travel will be required to Serbia We provide a competitive pay and benefits package. This position is offering a pay range of $78.19 - $103.41/hr. however, Belcan considers several factors when extending an offer, including but not limited to education, experience, geographic location, and discipline. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. Job Summary We are seeking a hands-on IAM Architect to lead our enterprise workforce identity migration from Microsoft Entra ID to Okta (~1,800 users), targeting a federation cutover in Q3 2026. You will own the migration architecture end-to-end ? federation design, app integrations, cutover, and stabilization ? working alongside our internal Enterprise Cybersecurity team and an external implementation partner. Beyond the migration, you'll help build and operate our identity ecosystem, with the opportunity to contribute to a custom identity orchestration and governance platform. This is a 6-month contract with strong potential for conversion to a full-time role. Key Responsibilities Okta Migration & IAM Operations (core) * Lead technical architecture for the Entra ID to Okta workforce identity migration: federation design, app integration sequencing, cutover planning, rollback strategy, and hypercare * Design and build SSO/SAML/OIDC integrations across the enterprise application portfolio; architect multi-tenant deployment (separate EU tenants) to meet regional data requirements * Architect lifecycle management and provisioning workflows (HR-driven joiner/mover/leaver), including SCIM integrations * Define and implement MFA, adaptive authentication, and device assurance policies aligned to a zero-trust roadmap * Serve as technical counterpart to the implementation partner: review designs, challenge assumptions, hold delivery quality to standard * Maintain and operate the Okta environment post-cutover: policy tuning, integration onboarding, incident support, and operational runbooks * Produce audit-ready documentation for an ISO 27001 / TISAX-aligned control environment Identity Orchestration & Governance (secondary) * Contribute to the design and build of a custom identity orchestration layer (Databricks or equivalent): attribute-driven provisioning, ABAC policy models, JIT privileged access, anomaly detection, automated deprovisioning, and audit/recertification capabilities * Support integration of identity and authorization event logs into the cybersecurity SIEM Required Qualifications * 7+ years in identity and access management, with 3+ years hands-on Okta experience building, deploying, and maintaining Okta Workforce Identity Cloud environments * At least one completed enterprise migration from Entra ID / Azure AD to Okta as architect or technical lead * Deep expertise in SAML, OIDC, OAuth 2.0, SCIM, and directory integration (AD/Entra ID hybrid scenarios) * Experience operating and administering Okta in production: policy management, app integrations, lifecycle workflows, troubleshooting * Experience designing MFA and adaptive access policies at enterprise scale * Strong documentation skills; able to produce audit-ready artifacts * Proven ability to work alongside system integrators while retaining architectural ownership Preferred Qualifications * Okta Certified Consultant or Okta Certified Architect * Experience building custom identity automation or governance tooling using Python/SQL, event-driven pipelines, and APIs * Working knowledge of data platforms (Databricks, Spark, or comparable) for event ingestion and processing * Experience with ABAC/policy-based authorization models and JIT/ephemeral privileged access patterns in AWS * SIEM integration experience (log normalization, detection engineering for identity signals) * Familiarity with IGA platforms, PAM solutions, and enterprise password managers * Experience in regulated or automotive environments (TISAX, ISO 27001, NIST 800-53) Engagement Details * Start date: ASAP; interviews conducted on a rolling basis * Reports to: Senior Manager, Enterprise Cybersecurity * Contract-to-hire: strong performers will be considered for a full-time Identity Engineering role at the conclusion of the initial term Belcan is a leading provider of qualified personnel to many of the world's most respected enterprises. We offer excellent opportunities for contract, temporary, temp-to-hire, and direct assignments. We are the employer of choice for thousands worldwide. For more information, please visit our website at Belcan.com
Skills
Similar jobs
Desktop Support Technician
Judge Group, Inc. · Princeton, United States
2 minutes agoDirector, Lead Consultant
TIAA · Frisco, United States
2 minutes ago$134k - $172k/yrManaging Director - Head of Service Reliability, Operations and Platform
TIAA · Charlotte, United States
3 minutes ago$206k - $309k/yrProgrammer Analyst - Remote
VIVA USA INC · United States
4 minutes agoOffice Conference Room Coordinator
Software Guidance & Assistance · Washington, United States
4 minutes agoCDx Clinical Lab Scientist I - RTD
Software Guidance & Assistance · Tucson, United States
4 minutes ago