freehire launches on Product Hunt on 26 August.

Follow →

Principal Security & IAM Architect

Summary

Principal Security & IAM Architect shaping security/identity strategy for a large-scale ServiceNow platform, focusing on authentication, authorization, identity governance, and lifecycle management. Core technologies include ServiceNow, Microsoft Entra ID, Okta, SailPoint, and AI-enabled security.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security & IAM Architect based in United States.

This is a senior architecture role responsible for shaping the security and identity strategy of a large-scale ServiceNow platform supporting thousands of users and customers. You will define the future-state access management model across authentication, authorization, identity governance, and lifecycle management. The role offers the opportunity to lead the consolidation of multiple identity platforms and modernize enterprise IAM capabilities. You will work across security, engineering, infrastructure, compliance, applications, and product teams to reduce risk and strengthen platform resilience. Your expertise will help translate regulatory and security requirements into practical, scalable architecture and governance. You will also guide security transformation initiatives involving cloud, SaaS, AI-enabled security, and emerging identity technologies. This is a strategic, highly influential position suited to an architect who enjoys solving complex problems and driving enterprise-wide change.

Accountabilities:

  • Define and own the future-state security and IAM architecture covering authentication, authorization, federation, access governance, and identity lifecycle management for customer and coworker populations.
  • Lead the consolidation of fragmented identity platforms, including Microsoft Entra ID, Okta, and native ServiceNow authentication, toward a unified and cost-effective identity model.
  • Architect the migration from SailPoint to Microsoft Entra ID Governance and establish appropriate RBAC, access tiers, certification, approval, and joiner/mover/leaver processes.
  • Design secure access request, approval, certification, and lifecycle workflows with clear ownership, traceability, and auditable controls.
  • Ensure security and identity architectures align with PCI DSS v4.0.1, SOC 2, corporate security policies, and enterprise hardening standards.
  • Establish IAM and security governance frameworks, including decision rights, ownership models, standards, and control mappings across the platform and ITSM processes.
  • Develop phased transition strategies that separate coworker and customer identity models while minimizing disruption and avoiding unnecessary identity changes.
  • Collaborate with application, integration, automation, engineering, infrastructure, compliance, and product architecture leaders to ensure IAM designs align with the broader target-state architecture.
  • Evaluate identity, security, and IGA technologies through benchmarking, proof-of-concept initiatives, risk assessments, and cost-benefit analysis.
  • Establish security monitoring, threat detection, identity analytics, and predictive risk capabilities to improve platform visibility and security posture.
  • Conduct threat modeling, security and identity risk assessments, architecture reviews, and remediation planning for legacy technical debt and emerging risks.
  • Lead, mentor, and establish technical standards for security engineering and IAM teams, providing architectural direction and hands-on guidance.
  • Communicate security strategies, architecture decisions, roadmaps, risks, and technical requirements effectively to technical teams, business stakeholders, and leadership.
  • Maintain comprehensive architecture documentation, including roadmaps, design decisions, technical specifications, and compliance control mappings.
  • Resolve complex security and identity challenges throughout design, migration, and operational phases while balancing security, user experience, budget, and business requirements.
  • Manage relationships with identity and security technology vendors, including technology evaluations, contract discussions, and ongoing partnership management.
  • Monitor emerging threats, identity standards, AI security developments, and industry trends to recommend innovative and defensible solutions.
  • Requirements:

    • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline with 10+ years of IT experience including security architecture and IAM, or 14+ years of relevant IT, security, and IAM experience.
    • Extensive hands-on expertise designing enterprise security and IAM architectures, including SSO, MFA, authentication, authorization, federation, SAML, OAuth, OIDC, and privileged access management.
    • Strong experience with Microsoft Entra ID and Entra ID Governance, along with identity governance platforms such as SailPoint; experience leading migrations between IGA platforms is highly valuable.
    • Advanced knowledge of RBAC/ABAC, access certification, identity lifecycle automation, and joiner/mover/leaver processes.
    • Strong understanding of regulatory and compliance requirements, particularly PCI DSS v4.0.1, SOC 2, and enterprise security and hardening standards.
    • Experience securing SaaS and ITSM platforms, with ServiceNow experience strongly preferred, including platform authentication and integration security.
    • Knowledge of AI principles applied to cybersecurity, including identity analytics, anomaly and threat detection, and governance of AI agents and automated workflows.
    • Proven ability to develop security and IAM strategies that align with business objectives while reducing risk, complexity, and cost.
    • Demonstrated experience leading architecture initiatives and influencing strategic decisions across complex, matrixed organizations without relying solely on direct authority.
    • Strong track record driving security transformation, risk reduction, technology modernization, and organizational change.
    • Extensive understanding of network architecture, cloud security, infrastructure, applications, data, and broader enterprise technology environments.
    • Exceptional analytical, problem-solving, and strategic thinking skills, with the ability to anticipate threats and translate them into actionable security strategies.
    • Excellent communication, facilitation, leadership, influencing, and conflict-resolution abilities.
    • Ability to manage multiple complex initiatives in a fast-paced, evolving environment while maintaining strategic focus.
    • Experience designing and implementing large-scale security and identity solutions across multiple technology domains.
    • Relevant certifications such as CISSP, CISM, SailPoint certifications, or Microsoft Identity and Access Administrator (SC-300) are a plus.
    • Master’s degree is a plus.
    • Benefits:

      • Base salary: $156,400–$218,920 annually, depending on experience, skills, and geographic location.
      • Annual bonus: Target of 10%, subject to applicable plan terms and conditions.
      • Comprehensive employee benefits and wellness offerings.
      • Remote work opportunity within the United States.
      • Salary may be adjusted based on geographic differentials.
      • Opportunity to work with evolving AI and security technologies in an AI-forward environment.
      • Collaborative culture focused on continuous learning, experimentation, and professional growth.
      • Opportunity to influence enterprise-wide security strategy and modernization initiatives.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

What this application asks

lever

Resume/CV, Full name, Email, Phone, Current location, Current company

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available