Senior Identity & Access Architect- Remote within the US

Interview integrity requirement
*Candidates must personally complete all interviews and technical assessments. The use of proxies or third-party representatives during any stage of the hiring process is prohibited and will result in disqualification. Final candidates will be required to participate in at least one in-person interview. Some travel for this role is expected. Reasonable accommodations will be provided in accordance with applicable laws.*

Help us build secure, seamless access across a modern enterprise. As our Senior IAM Architect, you'll design and evolve identity platforms that keep the right people connected to the right resources—securely, reliably, and without friction—across on-prem, hybrid, and cloud environments. You'll partner closely with security, infrastructure, cloud, application, HR, and compliance teams to deliver solutions that balance strong controls with great user experience.

What You'll Do

Design and support hybrid identity architectures using Active Directory, Microsoft Entra ID, and Okta
Architect authentication, authorization, and federation patterns for workforce, partner, and service identities
Apply least-privilege models (RBAC, ABAC) and role lifecycle management
Design MFA, passwordless, conditional access, and adaptive authentication policies
Automate joiner/mover/leaver (JML) workflows and identity lifecycle processes
Integrate IAM platforms with HR systems, directories, and SaaS applications
Support identity incident response—investigating access misuse, auth failures, and compromise
Monitor identity signals and logs to strengthen detection capabilities
Produce architecture diagrams, standards, runbooks, and documentation
Provide design reviews and best-practice guidance to application and infrastructure teams

What You Bring

7+ years in security or identity architecture with hands-on enterprise IAM expertise
Advanced skills in Active Directory (domains, forests, trusts, GPOs), Microsoft Entra ID (Conditional Access, MFA, Identity Protection, PIM), and Okta (Workforce Identity, SSO, Lifecycle Management, Workflows)
Proven experience with hybrid AD/Entra ID architectures and directory synchronization
Strong background in identity lifecycle automation, role modeling, federation, Zero Trust design, PIM/PAM, access governance/certification, and large-scale directory transformations
Knowledge of Kerberos, LDAP, SAML, OAuth 2.0, and OpenID Connect
Excellent communication skills across technical and non-technical audiences
Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience)

Work Style: Remote/hybrid with occasional in-person collaboration; camera-on virtual meetings.

What We Offer:

Full benefits starting Day 1: Medical, Dental, and Vision
401(k) with company match
Unlimited Flex Time Off plus 10 company-paid holidays
Remote-first role with monthly communication stipend
Professional development programs and tuition assistance
Home office equipment stipend
Employee resource groups and exclusive employee discounts

See also

Architecture jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available