Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
TikTok USDS logo

Identity and Access Management Architect

TikTok USDS
  • ๐Ÿ‡บ๐Ÿ‡ธ United States
  • On-site
  • 3 weeks ago
  • IAM
  • Active Directory
  • Azure AD
  • Google Workspace
  • SOC2
  • Zero Trust
  • SIEM
  • Vulnerability Management
  • OIDC
  • SAML
  • SCIM
  • WebAuthn
  • Okta
  • Ping Identity
  • SailPoint
  • CyberArk
  • AWS IAM
  • Azure
  • GCP
  • LDAP
  • Python
  • Java
  • PowerShell
  • REST API
  • MySQL
  • Hive
  • Redis
  • SQL
  • NIST
  • Conditional Access
  • Microservices
  • ISO 27001
  • RMF
  • COBIT
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

About the Team

The Identity and Access Management vertical within USDS Data Protection Team is responsible for designing, operating and maintaining an identity and access management program with a mission to enforce the principle of security by design and least privilege. We strive to establish secure and compliant processes around provisioning, deprovisioning and governance of access to USDS data and infrastructure proactively identifying and reducing risks.

About the Role

As an Identity and Access Management Architect, you will be responsible for supporting the team along with a team of cross-functional cyber, privacy, engineering, and data protection analysts to define, implement, manage, and measure controls to protect data in accordance with USDS policies and standards relevant to geographical regulations, contractual commitments, and confidentiality requirements. The Identity and Access Management Architect will play a pivotal role in the design, deployment and operationalization of the identity ecosystem and access management programs in USDS.

Responsibilities

  • Develop enterprise-wide IAM strategies, including roadmaps for Workforce IAM, Identity Governance and Administration (IGA), Privileged Access Management (PAM)
  • Architect solutions for Single Sign-On (SSO), Multi-Factor Authentication (MFA), and directory services (Active Directory, Azure AD/Entra ID)
  • Engineer and support onboarding of applications onto IAM platforms (Azure AD, Google Workspace)
  • Define and implement automated workflows for user lifecycle management (joiners, movers, leavers).
  • Design and manage integrations between enterprise infrastructure components (identity provider, cloud services). Develop automated processes for privileged account lifecycle management
  • Ensure IAM solutions comply with global standards (ISO, SOC2, PCI) and Zero Trust architecture principles
  • Design identity and access management program that addresses data residency and fine-grained role-based access requirements and controls as necessitated by business need and regulations
  • Assist in the development and implementation of Access governance frameworks, policies, and procedures.
  • Integrate IAM solutions with cybersecurity technologies (SIEM, vulnerability management). - Engineer, deploy, and operationalize privileged access management (PAM) solutions (on-prem and Privilege Cloud). - Implement privileged session management, credential vaulting, and least privilege controls
  • Build and review technical and functional requirements for in-house or external technologies to support access management and assurance needs, including applying appropriate security measures
  • Operationalize access management workflows such as access reviews and access remediations to improve efficiency
  • Responsible for designing and reporting key metrics and visualizations for weekly, monthly and bimonthly cadences across multiple audiences
  • Participate in security reviews to ensure compliance with access governance policies.
  • Foster a principle of least privilege for access management
  • Collaborate with key stakeholders to ensure alignment of access governance initiatives with organizational goals. Communicating complex technical risks to non-technical executives and compliance teams.
  • Provide technical oversight and guidance for junior IAM engineers and administrators

Minium Qualifications

  • Bachelor's degree or Master's Degree in a related field (e.g., Information Management, Computer Science, Business Analytics, Cyber Security). 5+ years in Identity and Access Management, specifically focused on IAM architecture
  • Hands-on Experience with authentication and authorization protocols eg: OIDC / OAuth 2.0 For securing APIs, SAML 2.0 For federated identity and SSO, SCIM For automated user provisioning, FIDO2 / WebAuthn For passwordless authentication strategies
  • Experience in industry-leading IAM product suites like Okta, Ping Identity,Microsoft Entra ID (Azure AD), SailPoint,Saviynt,CyberArk , BeyondTrust etc
  • Experience architecting IAM in AWS (IAM Roles, SCPs), Azure, or GCP. Deep knowledge of LDAP, Active Directory, and Azure AD
  • Proficient in at least one software programming language ( Python,Java, PowerShell etc) with experience developing automations and integrating IAM platforms with downstream applications via RESTful APIs
  • Experience in designing/deploying Access management solutions. xperience analysing large data sets across multiple database types (e.g., MySQL, Hive, Redis etc) leveraging SQL etc
  • Experience with industry frameworks, standards and regulations (e.g. ISO, NIST, SOC2, PCI etc). Experience with role-based access control frameworks and Conditional Access policies

Preferred Qualifications

  • Experience working with Microservices architecture
  • Comfortable working in a fast-paced, dynamic environment
  • Experience in automating access management workflows to reduce operational overhead
  • Experience with risk and controls frameworks including (ISO 27001, NIST CSF, NIST RMF, FAIR, COBIT, NIST RMF, ISO 31000 etc.) is a plus
  • Ability to look beyond immediate fixes and build a scalable security roadmap

Identity and Access Management Architect ยท TikTok USDS

Auto apply with Likeremote