Requisition ID: 107465-1
Title: AI Identity & Access Management Architect
Duration: 6+ months with possible extension
Location: Chicago, IL
Salary Range: $58- $64/ hour on W2/C2C
We are seeking a highly experienced AI Identity & Access Management Architect with 10+ years of experience in Identity, Authentication, Authorization, Access Management, and Cloud Security. The ideal candidate will have deep expertise in workforce identity security, modern authentication protocols, Zero Trust architecture, identity governance, and emerging agentic identity/AI architectures.
The architect will design secure, scalable, and compliant identity solutions across hybrid and cloud environments while partnering with security, infrastructure, application, and business teams.
Key Responsibilities
- Design identity-centric workforce security solutions for secure authentication and access management.
- Develop identity architectures aligned with Zero Trust, least privilege, defense-in-depth, and industry security frameworks.
- Provide architectural guidance for agentic AI architectures and identity concerns, including non-human and machine identities.
- Design and review solutions involving IAM, authentication, authorization, identity governance, and access management.
- Provide cybersecurity expertise across:
- MFA and SSO
- Conditional Access
- Passwordless authentication
- Device-based authentication
- VPN and proxy solutions
- Desktop virtualization
- YubiKey and biometric authentication
- Privileged Identity Management (PIM)
- Just-in-Time (JIT) access
- Role-Based Access Control (RBAC)
- Secrets and certificate management
- Identity federation
- Design and review security solutions involving OAuth, OIDC, SAML, Kerberos, LDAP, token handling, session management, and authorization patterns.
- Develop target architectures and technology roadmaps considering IAM controls, regulatory requirements, and audit requirements.
- Provide guidance on Cloud Infrastructure Entitlement Management (CIEM) and continuously improve cloud security posture.
- Apply threat modeling, cybersecurity risk management, supply-chain risk, and third-party risk principles.
- Review identity and access solutions proposed by application, infrastructure, and business stakeholders.
- Collaborate across cybersecurity, infrastructure, application, network, and business teams to improve security-centric designs.
- Provide identity and security solutions for Java microservices, React frontends, and Android/iOS applications running on Azure.
- Evaluate security technology choices covering cryptography, cloud-native services, secrets management, credential vaulting, data protection, and client-server communication.
Required Technical Skills
- 10+ years of experience in IAM, Identity Security, Cybersecurity, or Identity Architecture.
- Strong expertise in Identity, Authentication & Authorization (IAA).
- Deep knowledge of Client Entra ID / Azure AD.
- Strong hands-on knowledge of:
- OAuth 2.0
- OpenID Connect (OIDC)
- SAML
- SSO
- MFA
- Conditional Access
- Kerberos
- LDAP
- Identity Federation
- Strong knowledge of Zero Trust Architecture and least-privilege principles.
- Experience with Identity Governance and Administration (IGA).
- Strong understanding of Privileged Identity Management and entitlement management.
- Experience with Azure and AWS Security.
- Strong understanding of cloud security architectures and controls.
- Experience with Client Entra ID, EPM, Client Sentinel, Azure, and Client 365.
- Knowledge of Okta, PingFederate, and entitlement management solutions.
- Understanding of secrets management, certificate management, cryptography, token handling, and session management.
AI / Agentic Identity
- Strong understanding of agentic architectures and identity/security considerations for AI agents.
- Understanding of agent identities, authentication, authorization, access controls, and permissions for AI-driven systems.
- Ability to apply Zero Trust and least-privilege principles to human, machine, service, and agent identities.
- Awareness of emerging security challenges associated with AI agents and autonomous workloads.
Security Frameworks & Governance
- Strong knowledge of cybersecurity and IAM frameworks, standards, and controls, including:
- Understanding of cybersecurity risk management.
- Knowledge of supply-chain and third-party risk assessment controls.
- Experience with threat modeling methodologies.
- Ability to design architectures that satisfy security, compliance, and audit requirements.
Preferred Skills
- Experience with Client Sentinel.
- Experience with Okta and PingFederate.
- Experience with CIEM and entitlement management platforms.
- Experience securing cloud-native and hybrid environments.
- Experience with Java-based microservices and React-based applications.
- Experience securing mobile applications on Android/iOS.
- Strong communication, consulting, stakeholder management, and architectural documentation skills.