×
Register Here to Apply for Jobs or Post Jobs. X

IAM - Senior Lead​/Architect

Job in Seattle, King County, Washington, 98127, USA
Listing for: Capgemini
Full Time position
Listed on 2026-07-20
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 58.25 - 91.01 USD Hourly USD 58.25 91.01 HOUR
Job Description & How to Apply Below
Position: IAM - Senior Lead / Architect

Seattle, WA, United States (On-site)

Contract (11 months 29 days)

Published 3 days ago

OKTA

Security Operations

Dev Ops & Automation

api integrations

terraform

cross - functional collaboration

What You'll Do

Define and own the target-state architecture and reference designs for the identity security platform across Beyond Trust (Password Safe, EPM, PRA), Microsoft Entra , Active Directory, and SailPoint IDN.

Lead the architecture and deployment strategy for large-scale identity security modernization initiatives — privileged access transformation, identity governance modernization, cloud identity adoption, Active Directory and hybrid-identity modernization, and Zero Trust identity patterns.

Establish architecture standards, design patterns, integration blueprints, and guardrails that the build/engineering teams implement against, and serve as design authority through architecture and design reviews.

Develop migration and deployment strategies — sequencing, cutover, rollback, and risk mitigation — for moving large user and system populations onto modern identity platforms with minimal disruption.

Architect integrations across identity platforms, cloud (Azure, AWS, GCP), and enterprise/SaaS applications using APIs, federation, and provisioning standards (SAML, OAuth2/OIDC, SCIM, Kerberos, LDAP).

Drive phishing-resistant authentication and least-privilege/PAM architecture across the enterprise.

Partner with engineering leads, security architecture, platform/cloud teams, product, and program management to translate architecture into delivery roadmaps and executable work streams.

Provide technical leadership and guidance to build engineers; review designs and key implementations to ensure alignment to architecture and security requirements.

Identify and document architectural risks, dependencies, and trade-offs; present recommendations and decisions to engineering and leadership audiences.

Contribute to the security posture and control objectives of the modernization program, ensuring designs meet Nordstrom security, compliance, and data-handling requirements.

Leverage AI tooling to accelerate architecture analysis, design documentation, and solution evaluation.

What You Bring

Bachelor's or master's degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and experience.

15+ years of security or identity engineering experience, including significant experience as an identity/security architect on enterprise-scale environments.

Demonstrated experience leading large-scale identity security modernization or transformation programs end to end — from target-state architecture through production deployment.

Deep architecture-level expertise across two or more of the following, with strong working knowledge of the rest:
Beyond Trust, Microsoft Entra , Active Directory, Okta, and SailPoint.

Strong command of identity architecture fundamentals: authentication/authorization protocols (SAML, OAuth2/OIDC, SCIM, Kerberos, LDAP), federation, MFA and phishing-resistant authentication, RBAC/ABAC, least privilege, tiered administration, and Zero Trust identity.

Proven experience designing integrations and migrations across hybrid and multi-cloud environments at scale.

Experience setting architecture standards and acting as a design authority across multiple delivery teams.

Excellent communication skills — able to align engineers, architects, and senior leadership around architecture decisions and trade-offs.

Ability to operate independently in a fast-paced, multi-workstream program with high ambiguity.

Nice to Have

Architecture or security certifications such as CISSP, SABSA, TOGAF, Microsoft Identity & Access Administrator (SC-300), or SailPoint Certified Engineer.

Experience with infrastructure-as-code (Terraform, Ansible) and CI/CD as enablers of identity platform delivery.

Experience with identity threat detection and response (ITDR) and integrating identity signals into SIEM/SOAR.

Large-scale retail, ecommerce, or other high-transaction enterprise experience.

The pay range that the employer in good faith reasonably expects to pay for this position is $58.25/hour - $91.01/hour. Our benefits include medical,…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary