Digital Identity Architect
New American FundingAbout the role
Overview
Position: Identity and Access Management Architect
Location: REMOTE OK - (Hybrid schedule if living within 31 miles of Tustin, CA)
Compensation: starting at $140K, DOE
Position Summary:
The Digital Identity Architect plays a pivotal role in defining, designing, and advancing the enterprise’s Identity & Trust architecture. This role ensures that every digital interaction—across workforce, customer, and machine identities—is secure, seamless, and compliant with evolving regulatory requirements.
As a strategic technologist and hands-on architect, this position shapes the long-term digital identity vision, aligning it with business goals, Zero Trust principles, and emerging industry trends. Partnering with the Identity leadership team, cybersecurity, cloud, and business stakeholders, the Architect translates enterprise identity strategy into actionable, scalable solutions that strengthen security, support innovation, and enhance user experience.
This position demands a forward-looking leader with deep technical mastery, innovation mindset, and the ability to own complex, enterprise-scale initiatives in a dynamic financial environment.
Identity Verification checks are in place throughout the Candidate journey to prevent candidate fraud
Responsibilities
Architecture & Implementation
- Define and execute the enterprise IAM and CIAM architecture roadmap, aligning with financial regulatory and business requirements.
- Design end-to-end identity architectures covering workforce, customer, privileged, and non-human identities, ensuring policy consistency and least-privilege enforcement.
- Architect and optimize Active Directory (AD) and Microsoft Entra ID environments to deliver secure, resilient, and compliant hybrid identity solutions.
- Lead the modernization of legacy identity systems into cloud-ready architectures integrated with Entra ID, Azure AD Connect, and federated authentication services.
- Establish governance and operational standards for AD forests, domains, and group policies aligned with least-privilege and Zero Trust principles.
- Manage cloud entitlements across AWS, Azure, and GCP using automation and policy-driven access controls to prevent privilege sprawl.
- Implement Just-in-Time (JIT) and Just-Enough-Access (JEA) for privileged accounts, service principals, and administrative roles to minimize standing privileges.
- Architect and oversee IAM and CIAM platforms, including SSO, MFA, PAM, IGA, API security, and directory services across hybrid and multi-cloud environments.
- Implement Identity Threat Detection and Response (ITDR) capabilities to proactively detect and contain credential misuse, account compromise, and insider threats.
- Integrate identity and access policies into DevSecOps pipelines, automating enforcement across SaaS and cloud workloads.
- Conduct proof-of-concepts for emerging IAM technologies, guiding evaluation, adoption, and enterprise scaling.
Governance, Risk & Compliance
- Establish identity lifecycle and entitlement governance for Active Directory, Entra ID, and Cloud Service Provider platform roles
- Define and enforce access policies for Privileged Access Management (PAM) and Just-in-Time Access (JIT)
- Integrate IAM controls within enterprise risk and compliance programs, ensuring alignment with best practice and regulatory frameworks.
Collaboration & Leadership
- Partner with enterprise architects, cloud security, infrastructure, and application teams to embed IAM standards and controls across the enterprise.
- Act as a trusted advisor to the CISO and senior technology leaders, providing architectural insight, risk posture assessments, and strategic investment recommendations.
- Provide technical leadership and mentorship to identity engineers and analysts, fostering a culture of innovation and accountability.
- Influence cross-functional teams to adopt identity-first security principles and ensure consistent application across systems and business units.
- Support incident response and post-event analysis for identity-related security or fraud investigations, embedding lessons learned into architecture improvements.
Innovation & Continuous Improvement
- Researc
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s