Unknown Company

Cybersecurity IAM Architect - Staff Engineer

baltimore, md • Posted Today
Hybrid Full Time Financial Services

Architecture & Solution DesignDevelop enterprise-wide IAM and identity security architectures aligned to NIST standards, including NIST CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust principlesDesign scalable identity solutions for authentication, authorization, federation, lifecycle management, access governance, privileged access, and policy enforcement across cloud, on-premises, SaaS, and hybrid environmentsDefine secure design patterns for AI agent identities, non-human identities, workload identities, service accounts, API access, secrets, delegated authority, and agent-to-tool interactionsTranslate business, regulatory, and technical requirements into secure IAM solution blueprints, reference architectures, and reusable identity patternsEstablish least-privilege access models using RBAC, ABAC, PBAC, just-in-time access, dynamic credentials, and context-aware controls where appropriateSolution Review & Risk MitigationLead IAM architecture and security reviews for new technologies, applications, AI agents, automation platforms, APIs, and enterprise systemsIdentify identity-related gaps in proposed solutions, including over-permissioned roles, shared credentials, weak delegation models, insufficient audit trails, and unmanaged non-human identitiesAdvise on risk mitigation strategies for authentication, authorization, privileged access, identity lifecycle, secrets management, token use, tool binding, and agent runtime accessCollaborate with engineering, cloud, infrastructure, application, and AI platform teams to ensure secure deployment of identity-enabled systems and servicesProvide technical guidance to project and product teams throughout the system development lifecycle, with emphasis on secure-by-design IAM controlsGovernance & StandardsDevelop and maintain IAM architecture standards, identity control frameworks, access governance policies, and secure design patterns in alignment with NIST and industry best practicesParticipate in or lead internal security governance boards and architecture review boards with a focus on identity risk, Zero Trust alignment, and AI agent access governanceEnsure solutions meet internal risk, compliance, and regulatory requirements, including CMMC, PCI DSS, and audit expectations for identity controlsDefine governance expectations for joiner/mover/leaver processes, entitlement reviews, separation of duties, privileged access, service account ownership, non-human identity inventories, and exception managementContribute to maturity assessments and continuous improvement efforts for IAM architecture, identity governance, and AI agent identity management capabilitiesCollaboration & LeadershipAct as a subject matter expert on IAM, Zero Trust identity, non-human identity governance, and AI agent identity security for stakeholders across IT, engineering, compliance, risk, and AI product teamsMentor junior architects and security engineers on identity architecture, secure access patterns, and governance-driven solution designCommunicate complex identity, access, AI agent, and risk concepts clearly to business leaders and non-technical audiencesStay up to date on emerging threats, identity technologies, AI agent security patterns, and changes to the NIST ecosystemRequired Qualifications7–10 years of experience in cybersecurity, with 3+ years in IAM architecture, security architecture, or a similar solution design roleDeep working knowledge of NIST frameworks, including CSF, SP 800-53, SP 800-171, and SP 800-207 Zero TrustDemonstrated experience designing and reviewing IAM architectures for enterprise systems, cloud environments, SaaS platforms, APIs, and hybrid environmentsStrong understanding of IAM domains including identity lifecycle management, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of dutiesHands-on familiarity with identity platforms and standards such as Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologiesStrong understanding of LLMs, AI, and GenAI solutions, including agentic AI, MCP/tool hardening, non-human identity governance, agent-to-tool authorization, delegated access, and auditability of agent actionsExperience working in a large regulated environment and aligning identity controls to compliance frameworksExcellent communication, collaboration, architecture documentation, and executive-facing presentation skillsPreferredIndustry certifications such as CISSP, CISM, CISA, CCSP, or identity-focused certificationsExperience with Zero Trust Architecture, modern identity security models, and enterprise access governance programsExperience with policy-as-code, DevSecOps, infrastructure-as-code security, and automated identity control validationExperience developing governance models for non-human identities, machine identities, workload identities, AI agents, service accounts, secrets, and API credentialsOneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.SummaryLocation: Baltimore, MDType: Full time

Cybersecurity IAM Architect - Staff Engineer in baltimore at Unknown Company

This position is listed as full time and hybrid.

Back to Job Search