IAM Architect; Entra -Focused Hybrid in Plano
Listed on 2026-07-25
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
IAM Architect (Entra
-Focused) Hybrid in Plano
Company: NTT DATA Services
We are currently seeking a IAM Architect (Entra
-Focused) Hybrid in Plano to join our team in Plano, Texas (US-TX), United States (US).
Senior IAM Architect with deep expertise in Microsoft Entra , leading enterprise identity architecture with a primary focus on cloud identity, conditional access, zero trust, and hybrid identity. Complements Entra with strong experience in SailPoint, Cyber Ark, and PKI.
Role SummaryThe Senior IAM Architect is responsible for defining and delivering enterprise identity strategy with a primary focus on Microsoft Entra (Azure AD). This role will architect identity platforms, conditional access frameworks, and zero trust controls, while integrating SailPoint (IGA), Cyber Ark (PAM), and PKI services into a unified identity ecosystem.
The role partners with Security, Cloud, Dev Ops, and Application teams to ensure identity-first security, automation, and compliance
, with Entra the central control plane for workforce, application, and external identities.
- Entra & Strategy (Primary Focus)
- Define and own the enterprise Entra , including tenant design, identity governance, and security baselines.
- Design and implement Conditional Access policies
, Zero Trust models, and identity protection controls
. - Architect hybrid identity solutions (Entra Connect, cloud sync) and identity lifecycle integration across on-prem and cloud.
- Lead SSO and federation strategy using SAML, OAuth, and OIDC across SaaS and custom applications.
- Design B2B and B2C identity solutions
, including guest access governance and external identity management. - Standardize role-based and attribute-based access models aligned to Entra .
- Identity Governance & Administration (SailPoint)
- Integrate SailPoint with Entra
identity lifecycle management, provisioning, and certification campaigns
. - Design role models, entitlement mapping, and automated joiner/mover/leaver workflows.
- Integrate SailPoint with Entra
- Privileged Access Management (Cyber Ark)
- Align Cyber Ark PAM strategy with Entra , including privileged identity governance and least privilege enforcement
. - Design secure onboarding patterns for service accounts and privileged access workflows.
- Align Cyber Ark PAM strategy with Entra , including privileged identity governance and least privilege enforcement
- PKI and Identity Security Services
- Define PKI trust architecture and integrate certificate-based authentication with Entra .
- Lead certificate lifecycle automation for users, devices, and workloads.
- Automation and Cloud Integration
- Drive automation of identity processes using SCIM, Graph API, and Infrastructure as Code (Terraform).
- Enable identity integration across Azure, AWS, and GCP using Entra the identity provider.
- Security, Risk, and Compliance
- Translate compliance and regulatory requirements into Entra and policies
. - Lead access reviews, audit readiness, and continuous monitoring of identity risks.
- Translate compliance and regulatory requirements into Entra and policies
- Leadership & Delivery
- Provide architectural leadership, design governance, and mentorship to IAM engineering teams.
- Partner with stakeholders to embed identity into enterprise cloud and application strategies.
- 10+ years of IAM experience with strong emphasis on Entra / Azure AD architecture and engineering
. - Demonstrated expertise in:
- Conditional Access, Identity Protection, and Zero Trust
- Hybrid identity (AD + Entra )
- Federation (SAML, OAuth, OIDC) and SSO integrations
- Hands‑on experience integrating Entra
SailPoint and Cyber Ark
. - Strong understanding of identity lifecycle management and access governance
. - Experience with automation using Power Shell, Microsoft Graph API, Python, or Terraform
. - Working knowledge of PKI and certificate-based authentication
. - SIEM/Security monitoring tools experience
- Microsoft certifications:
Azure/Entra Identity (SC-300 or equivalent) - Experience with Zero Trust implementation frameworks
- Experience with Workday or HR-driven identity lifecycle integration
- Familiarity with cloud-native security and workload identity (Kubernetes, service principals, managed identities)
- Strong communicator with the ability to translate complex identity concepts into business value
- Strategic thinker with hands‑on technical depth in Entra
- Proven ability to drive identity transformation programs at scale
NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For Pay Transparency information, please . If you'd like more information on your EEO rights under the law, please . For our EEO Policy Statement, please .
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).