Identity Security Architect - Senior Engineer
FICOAbout the role
FICO (NYSE: FICO) is a leading global analytics software company, helping businesses in 100+ countries make better decisions. Join our world-class team today and fulfill your career potential!
The Opportunity
"As an Identity Security Architect on the Identity & Access Management (IAM) Architecture team you will help define strategy and technical implementation of IAM. You will collaborate closely with development teams, business units, and the Cybersecurity Trust organization to grow and develop IAM strategy and governance." - Cyber Security-Senior Director
What You'll Contribute
Partner with the IAM architecture team to develop and grow the organization’s IAM strategy and identity governance, aligning with enterprise security and business goals.
Partner with IT, HR, compliance, product developers and business units to ensure and enhance seamless onboarding, access provisioning, and role-based access controls (RBAC).
Partner with engineering and operations teams within the broader IAM function to ensure smooth execution of architecture solutions.
Identity opportunities for automation and reporting across IDP estate to enhance and mature identity governance, identity hygiene, increase self-service options, and decrease friction for our stakeholders.
Work with the team to define IAM Architecture roadmap, and goals.
Define IAM policies, standards, and controls to ensure compliance with internal security policies and external regulatory requirements (e.g., PCI-DSS, ISO 27001, NIST).
Develop architecture diagrams and presentations for audiences ranging from internal team to product developers to management.
Stay current with emerging trends and technologies in identity governance and identity threat protection and evaluate their potential impact on the organization (e.g., emerging threats, cloud-native PAM, JIT access, SSF (Shared Signals Framework), CAEP (Continuous Access Evaluation Protocol), Zero Trust).
Participate and collaborate with IAM and security tools vendors to understand new features, new products, and shape future identity security and governance tools selections.
What We’re Seeking
Hands-on experience with cloud IAM and IDPs (Entra ID, AWS IAM, GCP IAM, Okta, Ping, Active Directory, RHIM).
In-depth experience with SailPoint – Identity Security Cloud preferred.
Strong knowledge of IAM processes: provisioning, de-provisioning, certifications, RBAC, ABAC, MFA, SSO, PAM.
Experience with Federated Identity Management (SAML, OAuth, OpenID Connect).
Experience designing solutions to effectively manage privileged access (shared credentials and personal) using PAM solutions like CyberArk or Thycotic.
Strong understanding of modern authentication and authorization standards (SAML, OIDC) including when to apply them and how to perform high-level troubleshooting.
Familiarity with software development practices and experience working with Rest APIs.
Knowledge of Private Key Infrastructure (PKI), mTLS machine authentication, and FIDO2/WebAuthn.
Knowledge of Non-Human Identity (NHI) concepts and threat detections.
Knowledge of Zero Trust architecture and NIST cybersecurity frameworks.
Knowledge of AI and LLMs and use cases for identity governance is a plus.
Comfortable working with cross-functional teams.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s