This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Identity & Access Management (IAM) solution Security Architect reports to the IAM Program Manager in a hands-on role focused on the architecture, discovery, and design in the IAM space supporting PAM and IGA platforms. The Architect works directly with Lead Engineers, Program and Project Managers, hosting and server teams, and the client IAM resources through collaboration and mentoring to shape our program IAM deliverables within set scope and timeline.
Job Responsibility:
Designing and implementing IAM solutions
Focus on cloud security and collaboration with stakeholders
Architecture, discovery, and design in the IAM space supporting PAM and IGA platforms
Work directly with Lead Engineers, Program and Project Managers, hosting and server teams, and the client IAM resources through collaboration and mentoring
Support the development of security strategies and IAM related architecture vision
Provide a consensus-based enterprise solution that is scalable, adaptable, and synchronized with the ever-changing business needs
Drive the adoption of Authentication and Authorization reference architectures
Drive the adoption of creative solutions to address complex, global IAM problems
Participate in Identity and Access Management enterprise governance processes and drive IAM standards adoption
Develop effective architecture solutions
Create, maintain, and align with NTT's Information Security policies and standards
Represent Information Security on organizational project teams and ensure adherence to existing security policies and standards
Manage the successful technical delivery of Information Security projects and services
Review and management of technical security roadmaps related to cloud security and IAM
Develop solutions and recommendations for issues caused by process challenges, emerging threats, and technology changes
Requirements:
Minimum of 10 years of IT experience
Minimum of 5 years of direct Information Security experience
Bachelor's or Master's degree in Information Assurance, Computer Science, Information Systems or related field
Experience architecting IAM solutions such as SailPoint, Saviynt, CyberArk, Oracle platforms within Microsoft Azure, Amazon Web Services (AWS)
Intimately familiar with IAM related protocols such as SAML, JML, SPML, XACML, SCIM, OpenID, and OAuth
Experience working with cloud security and governance tools, cloud access security brokers (CASBs), and server virtualization technologies
Federation concepts and technologies, particularly with solutions from ADFS and Ping Identity
In-depth experience with Microsoft Azure, particularly Azure AD and architecture designs connecting Azure to enterprise infrastructure
Strong experience with Directories, SSO, Federation, Delegated administration, API gateways, SOA services
Strong understanding of cloud computing architecture, technical design, and implementations, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) delivery models
Excellent customer service and communication (oral/written) skills
Strong critical thinking and analytical skills
Must be able to work independently or with a team, under minimum supervision
Some knowledge of scripting languages (VBScript, PowerShell, Perl, JavaScript, etc.)
Must have working knowledge and understanding of networking technologies such as LAN, WAN, TCP/IP, load balancers, firewalls
Nice to have:
Expert level experience in Cloud Authentication and Access Management Services
Expert level experience in cloud solution development with Azure, AWS, Google, or other relevant cloud solution architectures
Good understanding of Multi-Factor authentication and Privileged Access Management
2-3 years of software development experience
A security industry certification is preferred, including but not limited to CISSP, SSCP, CISM, SANS GSEC, ECSA, ECSP, and Security+