1

Identity Access Management Architect Jobs (NOW HIRING)

next page

Showing results 1-20

Identity Access Management Architect information

See salary details

$21K

$116.4K

$189K

How much do identity access management architect jobs pay per year?

As of Aug 25, 2026, the average yearly pay for identity access management architect in the United States is $116,431.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,500.00 and $143,000.00 per year, depending on experience, location, and employer.

What is an identity access management architect?

An identity and access management architect deals with data security. Their responsibilities are to design and maintain the software systems by which users interact with the network and data systems of an organization. They perform situational analyses and software testing to determine vulnerabilities in the company’s databases to ensure that sensitive information is protected. If issues arise with the organization’s data security, the identity and access management architect’s duties are to design and implement solutions to these weak points. They often also test the users of a system by creating situations in which they could unintentionally compromise the system security and analyze how users react to those situations.

What does an identity access management architect do?

An Identity Access Management (IAM) Architect is responsible for designing and implementing systems that control and manage user identities and access permissions across an organization's digital resources. They ensure that only authorized users can access specific data or applications, safeguarding sensitive information and supporting regulatory compliance. IAM Architects work with technologies such as single sign-on (SSO), multi-factor authentication (MFA), and role-based access control (RBAC), and collaborate with IT teams to integrate security best practices throughout the company’s infrastructure.

How does an identity access management architect typically collaborate with other IT and business teams within an organization?

An Identity Access Management (IAM) Architect works closely with cross-functional teams, including IT security, application development, compliance, and business units. They are responsible for designing IAM solutions that align with organizational security policies while also supporting business requirements. Regular collaboration ensures that access controls integrate smoothly with existing systems and that user provisioning and deprovisioning processes are efficient and compliant. Effective communication and teamwork are essential, as IAM Architects often lead workshops, gather requirements, and provide guidance on best practices to both technical and non-technical stakeholders.

What are the key skills and qualifications needed to thrive as an identity access management architect, and why are they important?

To thrive as an Identity Access Management (IAM) Architect, you need a deep understanding of identity governance, authentication protocols, and security frameworks, typically supported by a degree in computer science or a related field. Familiarity with IAM tools such as Okta, SailPoint, or Microsoft Azure AD, as well as relevant certifications like CISSP or CISM, is highly valuable. Strong analytical thinking, communication, and problem-solving skills help you design secure, scalable solutions and collaborate effectively with stakeholders. These skills and qualifications are critical for protecting organizational assets, ensuring compliance, and enabling secure digital transformation.

What is the difference between Identity Access Management Architect vs Identity Access Management Engineer?

AspectIdentity Access Management ArchitectIdentity Access Management Engineer
CertificationsCertified Identity and Access Manager (CIAM), CISSPCISSP, CompTIA Security+
Work EnvironmentDesigns IAM frameworks, collaborates with stakeholdersImplements and maintains IAM solutions, supports systems
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security teams in similar industries

The main difference is that the Identity Access Management Architect focuses on designing and planning IAM systems, while the Identity Access Management Engineer handles the implementation and operational support of those systems. Both roles require relevant certifications and work within similar industries, but their responsibilities differ in scope and focus.

What cities are hiring for Identity Access Management Architect jobs?

Cities with the most Identity Access Management Architect job openings:

What are the most commonly searched types of Identity Access Management Architect jobs?

The most popular types of Identity Access Management Architect jobs are:

Who are the top companies hiring for Identity Access Management Architect jobs?

The top employers for Identity Access Management Architect jobs are:

What states have the most Identity Access Management Architect jobs?

States with the most job openings for Identity Access Management Architect jobs include:

What job categories do people searching Identity Access Management Architect jobs look for?

The top searched job categories for Identity Access Management Architect jobs are:

Infographic showing various Identity Access Management Architect job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $116,431 per year, or $56 per hour.

Identity & Access Management Architect

Belcan

Palo Alto, CA • On-site

$78.19 - $103.41/hr

Full-time, Contractor

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 2 days ago


Job description

Job Title: Identity & Access Management Architect
Pay rate: $78.19 - $103.41/hr.
Location: Palo Alto, CA (Hybrid)
Zip Code: 94304
Duration: 6 Months
Start Date: Right Away
Keywords: #PaloAltoJobs; #SeniorTechnicalProgramManagerjobs; #Identity&AccessManagementArchitect
International travel will be required to Serbia
We provide a competitive pay and benefits package. This position is offering a pay range of $78.19 - $103.41/hr. however, Belcan considers several factors when extending an offer, including but not limited to education, experience, geographic location, and discipline. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.
Job Summary
We are seeking a hands-on IAM Architect to lead our enterprise workforce identity migration from Microsoft Entra ID to Okta (~1,800 users), targeting a federation cutover in Q3 2026. You will own the migration architecture end-to-end ? federation design, app integrations, cutover, and stabilization ? working alongside our internal Enterprise Cybersecurity team and an external implementation partner. Beyond the migration, you'll help build and operate our identity ecosystem, with the opportunity to contribute to a custom identity orchestration and governance platform. This is a 6-month contract with strong potential for conversion to a full-time role.
Key Responsibilities
Okta Migration & IAM Operations (core)
* Lead technical architecture for the Entra ID to Okta workforce identity migration: federation design, app integration sequencing, cutover planning, rollback strategy, and hypercare
* Design and build SSO/SAML/OIDC integrations across the enterprise application portfolio; architect multi-tenant deployment (separate US/EU tenants) to meet regional data requirements
* Architect lifecycle management and provisioning workflows (HR-driven joiner/mover/leaver), including SCIM integrations
* Define and implement MFA, adaptive authentication, and device assurance policies aligned to a zero-trust roadmap
* Serve as technical counterpart to the implementation partner: review designs, challenge assumptions, hold delivery quality to standard
* Maintain and operate the Okta environment post-cutover: policy tuning, integration onboarding, incident support, and operational runbooks
* Produce audit-ready documentation for an ISO 27001 / TISAX-aligned control environment
Identity Orchestration & Governance (secondary)
* Contribute to the design and build of a custom identity orchestration layer (Databricks or equivalent): attribute-driven provisioning, ABAC policy models, JIT privileged access, anomaly detection, automated deprovisioning, and audit/recertification capabilities
* Support integration of identity and authorization event logs into the cybersecurity SIEM
Required Qualifications
* 7+ years in identity and access management, with 3+ years hands-on Okta experience building, deploying, and maintaining Okta Workforce Identity Cloud environments
* At least one completed enterprise migration from Entra ID / Azure AD to Okta as architect or technical lead
* Deep expertise in SAML, OIDC, OAuth 2.0, SCIM, and directory integration (AD/Entra ID hybrid scenarios)
* Experience operating and administering Okta in production: policy management, app integrations, lifecycle workflows, troubleshooting
* Experience designing MFA and adaptive access policies at enterprise scale
* Strong documentation skills; able to produce audit-ready artifacts
* Proven ability to work alongside system integrators while retaining architectural ownership
Preferred Qualifications
* Okta Certified Consultant or Okta Certified Architect
* Experience building custom identity automation or governance tooling using Python/SQL, event-driven pipelines, and APIs
* Working knowledge of data platforms (Databricks, Spark, or comparable) for event ingestion and processing
* Experience with ABAC/policy-based authorization models and JIT/ephemeral privileged access patterns in AWS
* SIEM integration experience (log normalization, detection engineering for identity signals)
* Familiarity with IGA platforms, PAM solutions, and enterprise password managers
* Experience in regulated or automotive environments (TISAX, ISO 27001, NIST 800-53)
Engagement Details
* Start date: ASAP; interviews conducted on a rolling basis
* Reports to: Senior Manager, Enterprise Cybersecurity
* Contract-to-hire: strong performers will be considered for a full-time Identity Engineering role at the conclusion of the initial term
Belcan is a leading provider of qualified personnel to many of the world's most respected enterprises. We offer excellent opportunities for contract, temporary, temp-to-hire, and direct assignments. We are the employer of choice for thousands worldwide. For more information, please visit our website at Belcan.com

Belcan logo

About Belcan

Sourced by ZipRecruiter

Belcan is a leading provider of qualified personnel to many of the world's most respected enterprises. We offer excellent opportunities for contract/temporary, temp-to-hire, and direct assignments in the engineering, IT, and professional fields. We are the employer of choice for thousands worldwide. Our overriding goal is to provide quality staffing solutions that help people, organizations, and communities succeed.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

Cincinnati, OH, US

Year founded

1958