Job Description - IAM Architect

Description

1. Position Summary:
Identity & Access Management (IAM) Architect is a strategic Cyber Security leadership role responsible for designing, architecting, and implementing modern Identity and Access Management solutions across IT and OT environments. The role drives enterprise IAM transformation initiatives leveraging Microsoft Entra ID, AI-enabled security capabilities, Zero Trust architecture, and advanced authentication technologies to strengthen cyber resilience, privacy, and regulatory compliance for employees, partners, suppliers, and customers. 

2. Key Job Responsibilities

2.1 Identity & Access Management Platform

•    Define and establish enterprise Authentication and Authorization reference architectures for current, emerging, and next-generation IAM technologies, and drive global adoption across IT, OT, cloud, and manufacturing environments.
•    Enforce enterprise Cyber Security standards and controls including Identity Governance, Access Management, Encryption, Logging, Conditional Access, and Privileged Access controls as part of the IAM reference architecture.
•    Design and implement scalable Identity and Access Management solutions to strengthen Cyber Security posture across enterprise IT systems, manufacturing plants, and digital platforms.
•    Architect and deploy integrated IAM solutions for hybrid environments spanning on-premises and cloud platforms, ensuring scalability, reliability, reusability, and alignment with strategic business and technology roadmaps.
•    Develop, maintain, and align enterprise Information Security policies, standards, and governance processes with industry best practices, Zero Trust principles, regulatory requirements, and secure cloud adoption strategies.
•    Lead and champion modern Identity solutions for digital transformation initiatives including Data Lakes, Smart Manufacturing, Industry 4.0, eCommerce, Factory Digitization, SaaS modernization, and AI-enabled business platforms.
•    Design secure identity architecture leveraging Microsoft Entra ID, SailPoint, CyberArk, PKI, Single Sign-On, adaptive authentication, and passwordless technologies to enhance user experience and enterprise security resilience.


2.2 Privileged Account Management

•    Design, implement, and mature the enterprise Privileged Access Management (PAM) program to secure privileged, administrative, and service accounts across global applications, infrastructure, cloud platforms, and OT environments.
•    Lead onboarding of critical and SOX-regulated applications into the CyberArk platform and standardize privileged access controls to ensure SOX ITGC compliance is implemented by design.
•    Ensure secure password vaulting, credential rotation, privileged session monitoring, and secrets management capabilities are implemented for all onboarded administrative and privileged accounts.
•    Define and execute the enterprise roadmap for privileged identity governance and elevated access management leveraging CyberArk, Microsoft Entra PIM, and Zero Trust security principles.
•    Implement least privilege, Just-In-Time (JIT), and Just-Enough-Administration (JEA) strategies to minimize identity attack surface and strengthen enterprise cyber resilience.
•    Develop and publish enterprise standards, architectural guidelines, and operational controls for Privileged Access Management platforms, ensuring consistent adoption and governance across global IT and business environments.
•    Enhance privileged access security through integration with Identity Governance, Multi-Factor Authentication (MFA), PKI, adaptive authentication, and AI-driven risk analytics capabilities.
•    Drive continuous improvement of PAM controls aligned to Confidentiality, Integrity, and Availability (CIA) principles, regulatory requirements, and industry best practices.


2.3 Single Sign-on and Access Governance

•    Design and implement a unified enterprise authentication platform supporting Single Sign-On (SSO) and Multi-Factor Authentication (MFA) across diverse enterprise, cloud, OT, and SaaS technology platforms.
•    Define secure authentication architecture leveraging Microsoft Entra ID, federation services, Conditional Access, adaptive authentication, and Zero Trust principles to protect against modern cyber threats, credential compromise, and MFA bypass techniques.
•    Ensure all critical enterprise applications are integrated with secure SSO, centralized identity governance, and phishing-resistant authentication mechanisms.
•    Drive enterprise-wide Least Privilege and Role-Based Access Control (RBAC) initiatives to strengthen identity security, regulatory compliance, and operational efficiency.
•    Implement and enhance integrated Identity Governance and Administration (IGA) capabilities including automated provisioning, access certifications, Segregation of Duties (SoD), Joiner-Mover-Leaver (JML) processes, and policy-based access controls.
•    Improve digital workplace experience by delivering seamless, secure, and frictionless authentication services for employees, partners, suppliers, and customers.
•    Enhance passwordless authentication architecture using Kerberos, PKI, certificate-based authentication, Windows Hello for Business, FIDO2, biometrics, and device-based trust technologies.
•    Champion enterprise security architecture best practices and promote global cross-functional collaboration for standardization, knowledge sharing, and continuous improvement of IAM and access governance capabilities.
•    Integrate AI-driven identity analytics, User and Entity Behavior Analytics (UEBA), and risk-based access controls to enable intelligent and adaptive authentication decisions.
                                                
                                                        
3. Education / Qualifications
• Bachelor’s degree in Information Technology or related discipline
                                                        
4. Experience
    12+ years of IT experience and 8 years of Identity Management. Must have delivered the role of Identity Management Lead/ Identity Management Technical Manager      for 3 years                                                    
                                                        
5. Key Skills and Knowledge
•    Strong hands-on experience with Identity Governance and Administration (IGA) platforms such as SailPoint IdentityIQ, SailPoint Identity Security Cloud, IBM Tivoli Identity Manager, or equivalent IAM technologies, including workflow configuration, Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), birthright provisioning, access certifications, and user lifecycle management.
•    Deep technical expertise in Microsoft Entra ID (Azure AD), Active Directory, hybrid identity integration, user and group provisioning, directory synchronization, and enterprise identity federation.
•    Strong experience in designing and implementing Public Key Infrastructure (PKI), certificate lifecycle management, certificate-based authentication, and cryptographic security controls.
•    Hands-on experience with Privileged Access Management (PAM) solutions such as CyberArk including privileged credential vaulting, session monitoring, secrets management, and Just-In-Time privileged access.
•    Proven expertise in Single Sign-On (SSO) and federation technologies including Microsoft Entra ID, Ping Identity, Okta, SAML, OAuth2, OpenID Connect (OIDC), and SCIM integration frameworks.
•    Strong experience implementing Multi-Factor Authentication (MFA), passwordless authentication, Windows Hello for Business, FIDO2, biometric authentication, and adaptive/risk-based access control solutions.
•    Good understanding of contemporary and emerging identity security technologies including Zero Trust architecture, AI-driven identity analytics, Identity Threat Detection & Response (ITDR), blockchain-based identity models, decentralized identity, and machine identity security.
•    Experience securing cloud and SaaS environments across platforms such as Microsoft Azure, AWS, Google Cloud Platform, ServiceNow, SAP, and Salesforce.
•    Strong understanding of cybersecurity, governance, risk, and compliance frameworks including SOX, NIST, ISO 27001, GDPR, and global data privacy and security regulations.
•    Ability to perform risk assessments, business impact analysis, identity security reviews, control assessments, and vulnerability analysis using manual and automated security tools.
•    Strong leadership, stakeholder management, interpersonal, presentation, and communication skills with the ability to influence and collaborate effectively across all organizational levels globally.
•    Ability to translate business requirements, cybersecurity objectives, and digital transformation strategies into scalable IAM architecture and actionable implementation plans.
•    Proven ability to work effectively within global and regional operational support models while promoting collaboration, innovation, and knowledge sharing across teams.
•    Highly organized, analytical, and solution-oriented professional with strong problem-solving, service design, architecture, and implementation capabilities.
 



Original job IAM Architect posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

About the Company

Garrett Advancing Motion

With a legacy of over 70 years, Garrett Motion is a cutting-edge technology leader enabling emission reduction and energy efficiency. We design, manufacture and sell highly engineered turbocharging, air and fluid compression, and high-speed electric motor technologies for customers in the mobility a...

Read more about the company

Similar IAM Architect Jobs in India

GrabJobs is the no1 job portal in India, connecting you to thousands of jobs fast! Find the best jobs in India, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.