IAM Architect

CGIReston, VA
7dHybrid

About The Position

CGI has an immediate need for a IAM Architect to join our team. This is an exciting opportunity to work in a fast-paced team environment supporting one of the largest customers. We take an innovative approach to supporting our client, working side-by-side in an agile environment using emerging technologies. We partner with 15 of the top 20 banks globally, and our top 10 banking clients have worked with us for an average of 26 years!. This role is located at a client site in Reston, VA. A hybrid working model is acceptable. As an IAM Architect, you will drive the strategy, design, and implementation of Identity and Access Management programs. You will be responsible for creating secure, scalable identity architectures that align with Zero Trust principles, ensuring that all access requests are verified regardless of location. This role bridges business needs with technical solutions across cloud (AWS/Azure) and hybrid environments.

Requirements

  • 5+ years in Cybersecurity, with deep focus on IAM and Information Security Architecture.
  • Strong knowledge of IAM core pillars: IGA (Governance), AM (Access Management), and PAM (Privileged Access).
  • Experience with AWS security services, Azure AD/Entra ID, and directory services (LDAP, Active Directory).
  • Proven experience with NIST security frameworks, PCI-DSS, and regulatory compliance.
  • Understanding of micro segmentation, adaptive authentication, and device trust.
  • Zero Trust Strategy: Establish and maintain a Zero Trust security model, ensuring continuous verification of all access requests.
  • Architecture & Design: Design secure IAM architectures for cloud and hybrid platforms, focusing on authentication, authorization, role management, and federation.
  • Authentication & Authorization: Develop controls for modern authentication protocols, MFA, and SSO. Implement Attribute-Based Access Control (ABAC) and Policy-Based Access Control (PBAC).
  • Cloud Security Integration: Integrate Zero Trust principles with cloud-native tools (AWS, Azure, Entra ID).
  • Policy & Governance: Enforce least-privilege access principles and automated risk-based access controls.
  • Technical Leadership: Act as a subject matter expert, guiding matrixed teams and collaborating with Engineering and Information Security to ensure compliance with NIST frameworks.
  • Automation: Drive automation for identity governance, provisioning, and lifecycle management.

Nice To Haves

  • Industry certifications such as CISSP, CCSP, or AWS Security Specialty.
  • Experience with API security and containerization security.
  • Industry certifications such as CISSP, CCSP, or AWS Security Specialty.
  • Experience with API security and containerization security.

Responsibilities

  • Drive the strategy, design, and implementation of Identity and Access Management programs.
  • Creating secure, scalable identity architectures that align with Zero Trust principles, ensuring that all access requests are verified regardless of location.
  • Bridges business needs with technical solutions across cloud (AWS/Azure) and hybrid environments.
  • Establish and maintain a Zero Trust security model, ensuring continuous verification of all access requests.
  • Design secure IAM architectures for cloud and hybrid platforms, focusing on authentication, authorization, role management, and federation.
  • Develop controls for modern authentication protocols, MFA, and SSO. Implement Attribute-Based Access Control (ABAC) and Policy-Based Access Control (PBAC).
  • Integrate Zero Trust principles with cloud-native tools (AWS, Azure, Entra ID).
  • Enforce least-privilege access principles and automated risk-based access controls.
  • Act as a subject matter expert, guiding matrixed teams and collaborating with Engineering and Information Security to ensure compliance with NIST frameworks.
  • Drive automation for identity governance, provisioning, and lifecycle management.

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • Matching contributions through the 401(k) plan and the share purchase plan
  • Paid time off for vacation, holidays, and sick time
  • Paid parental leave
  • Learning opportunities and tuition assistance
  • Wellness and Well-being programs
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service