Principal IAM/PAM Security Architect

🔥 13 hours ago

🇺🇸 United States – Remote

💵 $160k - $190k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cotiviti

Cotiviti

5001 - 10000 employees

🏥 Healthcare

💼 Consulting

📦 Logistics

Healthcare • Consulting • Logistics

Cotiviti is a healthcare technology and analytics company that specializes in improving payment accuracy and performance through advanced data analytics solutions. They partner with health plans, government agencies, and healthcare providers to deliver insights that enhance quality and efficiency in care delivery. With solutions such as risk adjustment, payment policy management, and member engagement, Cotiviti aims to optimize financial and clinical outcomes for the healthcare ecosystem.

📋 Description

• Define and maintain security architecture and standards across Active Directory, Microsoft Entra ID, Okta, AWS, Azure, GCP, and OCI identity environments • Serve as the architectural authority for identity security decisions across a large, complex identity environment • Lead architecture reviews and risk assessments for identity integrations, platform migrations, and M&A activity • Define enterprise standards for Agentic Identity governance, lifecycle, authentication, and authorization for AI agents and other non-human identities • Track the agentic AI and non-human identity landscape and advise leadership on risks, standards, and vendor capabilities • Define security requirements for and lead enterprise-wide implementation of the Delinea PAM platform, including Secret Server and Privilege Manager • Design least-privilege, JIT/JEA, session-monitoring, and credential-rotation controls across on-premises and cloud environments • Oversee onboarding of privileged accounts and systems • Produce audit-ready evidence of PAM controls aligned with SOX, HIPAA, PCI, and ISO 27001 • Own enterprise policy and lifecycle standards for API keys, OAuth/OATH tokens, service account credentials, and certificates • Drive detection and remediation of hardcoded, unmanaged, or leaked secrets across source code, configuration, and CI/CD pipelines • Establish metrics and reporting for secrets governance maturity and compliance • Participate in and help lead architecture review boards, governance forums, and risk committees • Maintain reference architectures, standards documentation, and roadmaps for identity, PAM, and secrets governance • Advise stakeholders on identity risk and control design for new initiatives • Mentor engineers implementing identity, PAM, and secrets solutions • Complete annual performance-review or goal-setting responsibilities and assigned special projects and other duties

🎯 Requirements

• Bachelor’s degree in a technology discipline or equivalent professional experience • 8+ years of experience in identity and access management, privileged access management, or security architecture roles • Experience across large, complex enterprise environments • Experience designing security standards across hybrid identity environments • Hands-on experience with a PAM platform at an architecture or lead engineering level; Delinea preferred • Experience with Active Directory, Microsoft Entra ID, and Okta, including federation, conditional access, and hybrid identity synchronization • Experience with AWS, Azure, GCP, and OCI IAM, including IAM roles/policies, workload identity, federation, and cross-cloud access patterns • Experience with AI agent architectures, service/workload identities, and emerging standards for non-human identity governance • Hands-on experience with Delinea Secret Server and Privilege Manager • Experience with HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, and secrets-detection tooling • Knowledge of Kerberos/NTLM, LDAP/LDAPS, SAML/OIDC, OAuth 2.0, RADIUS/TACACS+, PKI/certificates, and MFA • Knowledge of SOX, HIPAA, PCI DSS, and ISO 27001 as applied to identity, privileged access, and secrets controls • Experience with PowerShell, Python, and REST APIs for identity/PAM/secrets lifecycle automation • Experience embedding identity, PAM, and secrets controls into CI/CD pipelines and infrastructure-as-code using Terraform, ARM, and CloudFormation • Strong analytical and architectural problem-solving skills • Ability to translate complex, multi-domain identity environments into clear standards • Ability to communicate architecture and risk decisions to technical and business stakeholders • Relevant security certifications preferred, such as CISSP, CISM, SABSA, or CCSP • Must be able to perform duties with or without reasonable accommodation • Must provide high-speed internet access/connectivity and office setup and maintenance • Must provide a dedicated, secure work area

🏖️ Benefits

• Discretionary bonus consideration • Medical insurance coverage • Dental insurance coverage • Vision insurance coverage • Disability insurance coverage • Life insurance coverage • 401(k) savings plan • Paid family leave • 9 paid holidays per year • 17–27 days of Paid Time Off (PTO) per year, depending on level and length of service • High-speed internet access/connectivity and office setup and maintenance provided by the team member • Dedicated, secure work area provided by the team member

Apply Now

Similar Jobs

🔥 15 hours ago

Samsara

1001 - 5000

📦 Logistics

🏗️ Construction

🏥 Healthcare

Staff Offensive Security Engineer leading vulnerability management for Samsara's Connected Operations Cloud. Automating security across cloud, firmware, IoT, and corporate systems.

🔥 15 hours ago

Samsara

1001 - 5000

📦 Logistics

🏗️ Construction

🏥 Healthcare

Staff Offensive Security Engineer leading vulnerability management and application security for Samsara’s Connected Operations Cloud. Building automation across cloud, firmware, IoT, and corporate systems.

🔥 15 hours ago

Zero Hash

51 - 200

💳 Fintech

₿ Crypto

🌐 Web 3

Security Architect securing zerohash’s crypto and stablecoin infrastructure platform. Designing cloud, blockchain, and application security across global financial services systems.

🔥 15 hours ago

Cencora

10,000+ employees

💼 Consulting

📦 Logistics

🏥 Healthcare

Principal Architect shaping Cencora’s enterprise cybersecurity architecture across cloud, data, AI, and identity. Guiding security strategy, governance, and engineering execution for a healthcare-focused global company.

🔥 17 hours ago

Optiv

1001 - 5000

Security engineering director leading SIEM, EDR, SOAR, and MDR platforms for Optiv’s managed security services. Directing practice strategy, service quality, automation, staffing, and client escalations.