Principal Architect - Identity, Access, and Management
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities.
At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter.
This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today.
The RoleDefine and own identity, access management, and security architecture for Lumen's NaaS platform,
customer-facing digital services, and AI/agent ecosystems. This role embeds security architecture directly
into the Digital Journey Architecture and Solutions organization - providing the team with IAM and security
expertise at the point of design, not as a downstream review function.
The scope spans customer portal identity (who can access what and how), API security and authentication standards (OAuth2, OIDC, SAML), SSO integration (including Entra B2C for enterprise and government customers), FedRAMP and compliance-aligned security architecture, and the emerging security
requirements of agentic AI systems. This role also serves as the primary DJAS interface for security
architecture related to complex multi-cloud networking integrations and Lumen's public sector initiatives.
LocationThis is a remote opportunity open to candidates located anywhere in the U.S.
The Main ResponsibilitiesOwn IAM strategy and target-state architecture across Lumen's NaaS identity ecosystem:
LIAM/ECAPS, Microsoft Entra /B2C, AWS IAM.Design and operationalize Zero Trust identity principles: continuous verification, risk-based access,least privilege enforcement.
Architect customer identity and access management (CIAM): web portal, mobile, and API access patterns with security and customer experience in balance.
Define authentication and federation standards: OAuth 2.0, OpenID Connect, SAML - enforced across
APIs and customer-facing surfaces.
Design SSO architecture across NaaS portal, partner portals, and government-facing services (EntraB2C).
Develop IAM governance frameworks: RBAC/ABAC models, access lifecycle, entitlement review, audit evidence.
Define IAM-as-Code practices:
Terraform-based identity configuration, version-controlled, auditableArchitect security for agentic AI systems: agent authentication, authorization boundaries, audit trails forAI-generated actions, token lifecycle management for agents.
Provide security architecture for FedRAMP-aligned government initiatives: boundary preservation,tokenization patterns, identity flow compliance.
Serve as the embedded DJAS security architect for multi-cloud networking integration: define IAM and security boundary requirements across cloud-to-cloud and cloud-to-physical network interconnects
Conduct security architecture reviews on NaaS designs: threat modeling, attack surface analysis,risk-based recommendations.
Define security NFRs for DJAS architecture work: what every design must address from a security perspective regardless of work type.
Partner with Lumen's Security team (not owned by DJAS) and bring the security perspective into DJASdesign work proactively.
Bachelor's degree in computer science, engineering, information security, or related field with 12+years of relevant experience or
Master's degree with 10+ years of relevant experience
AI-first practitioner - actively…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).