Arctiq
IAM Architect - Remote Contract
Philadelphia, Pennsylvania, United States · Senior
Sponsorship not specifiedDetected 45 days ago
PythonGoAWSGCPAzureCloud PlatformsTerraformCI/CDPlatform EngineeringOAuthCybersecurityProject ManagementZero TrustLeadershipCommunicationCISSP
About the role
- We help organizations operate, secure, and modernize complex environments by unifying infrastructure, networking, data, security, automation, and observability under a single, integrated operating model.
- Utilize Wiz (CSPM) for cloud asset inventory, compliance reporting, evidence collection, and correlation to AWS/Azure/GCP documentation.
Responsibilities
- Design and enforce IAM least-privilege models across AWS Organizations, Landing Zones, and Service Control Policies (SCPs), with parity controls extended to Azure and GCP.
- Lead zero trust initiatives end-to-end: verify-explicitly policies, Just-in-Time (JIT) / Just-Enough-Access (JEA) provisioning, CIEM integration, and identity platform governance.
- Define and maintain approved access patterns for services and users, aligned to predefined roles (Reader, Contributor, Administrator) and documented as policy-as-code.
- Implement and govern OAuth/OIDC flows, service mesh identity controls, and federated identity across cloud and on-prem environments.
- Maintain a comprehensive inventory of all approved AWS and Azure services, cataloging IAM resources and differentiating between control plane (roles, policies) and data plane (user/key/role/policy/group) resources.
- Manage credentials for local data plane resources in vaults
- Develop a comprehensive metadata tagging strategy mapped to application service lines (ASL), environments, and repository associations.
- Design and build reusable IAM modules for each service access pattern, published to the service registry with consistent enforcement of naming conventions, metadata, and parameters.
- Manage credentials for local data plane resources in vaults; ensure resource policies are applied consistently across services.
- Develop methodologies and criteria for pre-approved service registry modules deployable via pipelines vs. those requiring manual review.
Requirements
- 10+ years of experience in IAM, cloud security, or identity engineering roles with demonstrated progression.
- Proficiency with CSPM tooling, specifically Wiz, for inventory, reporting, and compliance evidence collection.
- Proven experience leading zero trust initiatives including JIT/JEA provisioning, CIEM platforms, OAuth/OIDC, and service mesh identity.
- Hands-on experience with policy-as-code tooling and embedding IAM guardrails into IaC (Terraform / CloudFormation) and CI/CD pipelines.
- Experience securing microservices architectures (Python, Go) in async and event-driven environments across AWS, Azure, and GCP.
- Proficiency in metadata tagging strategies, service access pattern development, and credential vault management.
- Strong documentation, process development, and communication skills with the ability to influence cross-functional teams.
Nice to have
- Relevant cloud security certifications: AWS Security Specialty, CCSP, CISSP, or equivalent Azure/GCP security certifications.
- Experience implementing and managing enterprise-scale cloud infrastructure security programs.
- Familiarity with identity governance and administration (IGA) platforms and PAM solutions.
- Experience with service mesh technologies (Istio, Envoy) for service-to-service authentication.
- Strong project management skills with experience leading cross-functional security initiatives.
- This is a high-impact, senior individual contributor and leadership role at the intersection of cloud security architecture, identity engineering, and platform governance.
Skills
- This is a remote, contract opportunity for one of Arctiq's clients.
- Enterprise IAM Architecture & Multi-Cloud Governance
- verify-explicitly policies, Just-in-Time (JIT) / Just-Enough-Access (JEA) provisioning, CIEM integration, and identity platform governance.
- Inventory & Cloud Security Posture Management
This listing is sourced directly from Arctiq's careers page and normalized into a canonical job model.