All Jobs Vacancy

Principal Cybersecurity Architect - Identity, IAM & Zero Trust

Posted 1 day ago by Spear Staffing

Role Summary

Looking for a Principal Cybersecurity Architect to own the enterprise security architecture across identity, access management, and Zero Trust. This is a senior individual contributor role with significant influence over how people, machines, and workloads authenticate, authorize, and access resources across our environment.

Responsibilities

  • Partner with IT, infrastructure, and business stakeholders to integrate security into technology decisions
  • Mentor and guide security engineers on architecture standards and design decisions

Zero Trust Architecture

  • Design and mature a Zero Trust architecture (ZTNA, MFA, PAM) spanning identity, device trust, network access, and application security — grounded in NIST SP 800-207 and BeyondCorp principles.
  • Define reference architectures, security patterns, and guardrails consumed across engineering and infrastructure teams
  • Lead threat modeling and security architecture reviews for major platform changes and initiatives
  • Evaluate and select security tooling (SASE, SSE, ZTNA, NDR, EDR) aligned to the overall architecture strategy
  • Drive continuous improvement of Zero Trust posture through gap assessments and maturity modelling

Identity & Access Management (IAM)

  • Own the enterprise IAM architecture — covering workforce identity, B2B federation, machine identities, and cloud entitlements
  • Design and govern identity lifecycle management: provisioning, role assignment, access reviews, and deprovisioning — ensuring least privilege is enforced by default and not by exception
  • Architect federation and SSO standards across the enterprise: SAML 2.0, OIDC, OAuth 2.0 — including integrations with third-party SaaS, partner tenants, and customer-facing portals
  • Define authentication assurance levels by resource sensitivity, aligning MFA requirements to NIST AAL2/AAL3 — with a clear roadmap toward phishing-resistant MFA (FIDO2/WebAuthn) for privileged and high-risk access
  • Lead the PAM architecture — credential vaulting, just-in-time privilege, session recording, and endpoint privilege management — in partnership with the security operations team
  • Govern cloud entitlements across AWS, Azure, and Google Cloud Platform through a CIEM framework: identify over-permissioned roles, enforce least privilege for service principals and IAM roles, and manage cross-account trust relationships
  • Establish and maintain a non-human identity strategy: service accounts, API keys, application credentials, and pipeline secrets — eliminating hardcoded credentials and enforcing dynamic secrets via a secrets management platform
  • Drive identity governance processes: access certification campaigns, segregation of duties (SoD) controls, and role-based access control (RBAC) model design
  • Partner with HR, IT, and business application owners to ensure joiner/mover/leaver processes are automated and auditable

Governance & Stakeholder Engagement

  • Define security architecture standards, policies, and exception management processes
  • Mentor security engineers and serve as the escalation point for complex identity and access design decisions
  • Produce architecture artefacts — threat models, data flow diagrams, trust zone maps — suitable for both technical and executive audiences
  • Contribute to the security roadmap and annual planning, translating risk priorities into architectural investments

Qualifications

  • 8+ years in information security, with 4+ years in an architecture or senior engineering role
  • Deep expertise in Zero Trust frameworks (NIST SP 800-207, BeyondCorp) and identity-centric security
  • Strong understanding of threat modeling methodologies (STRIDE, PASTA, ATT&CK)
  • Hands-on experience with enterprise IAM platforms — Microsoft Entra ID, Okta, Ping Identity, or equivalent
  • Strong grasp of federation protocols: SAML 2.0, OIDC, OAuth 2.0, SCIM
  • Experience with PAM platforms (CyberArk, BeyondTrust, Delinea) and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault)
  • Familiarity with CIEM tooling and cloud IAM governance across at least two major cloud platforms
  • Experience designing and governing identity lifecycle and IGA processes (SailPoint, Saviynt, or equivalent a plus)
  • Strong understanding of threat modelling methodologies (STRIDE, ATT&CK) and their application to identity attack surfaces
  • Excellent communication skills — able to translate complex architecture into clear guidance for engineers, business stakeholders, and executives
  • Proven experience using diplomacy skills

Certifications (preferred): CISSP, SABSA, TOGAF, Microsoft SC-100, Okta Certified Architect, or equivalent

Rate:
Not specified
Location:
Remote
IR35 Status:
Not specified
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Share job