Principal IAM/PAM Security Architect

🏢 Cotiviti · all Cotiviti jobs (99)
📍 United States
💰 USD 160,000 - 190,000 / annual
📅 Posted 2026-09-07 · via Himalayas
🏷 Security-Architecture,IAM,Privileged-Access-Management,Cloud-IAM,Security-Governance,Senior-IAM-Architect,Principal-Identity-And-Access-Management-Engineer,Senior-Identity-and-Access-Management-Architect,Principal-Security-Architect,Identity-And-Security-Architect,Identity-And-Access-Management-Architect,IAM-Solutions-Architect,Security-Architect
Apply on original site ↗

Overview

The Principal IAM/PAM Security Architect defines and evolves security architecture for identity and privileged access across a large, complex, multi-domain environment spanning Active Directory, Microsoft Entra ID, and Okta, as well as cloud-native identities across AWS, Azure, GCP, and OCI.

This role sets security standards for each identity environment, leads the definition of emerging Agentic Identity standards for AI agents and other non-human identities, defines requirements for and drives implementation of the Delinea PAM platform, and owns secrets governance enterprise-wide — including API keys, OAuth/OATH tokens, service account credentials, and certificates. The architect partners closely with identity, cloud, and application teams to keep controls consistent, auditable, and scalable.
Responsibilities

-
Identity Architecture & Standards: Define and maintain security architecture and standards across Active Directory, Microsoft Entra ID, Okta, and multi-cloud identity (AWS, Azure, GCP, OCI), covering authentication, authorization, and lifecycle controls.

- Serve as the architectural authority for identity security decisions, aligning platform and cloud teams to enterprise standards across a large, complex identity environment.

- Lead architecture reviews and risk assessments for new identity integrations, platform migrations, and M&A activity.

-
Agentic Identity Standards: Define enterprise standards for Agentic Identity — governance, lifecycle, authentication, and authorization for AI agents and other non-human identities, including provisioning, scoped entitlements, and deprovisioning.

- Track the evolving agentic AI and non-human identity landscape and advise leadership on emerging risks, standards, and vendor capabilities.

-
Privileged Access Management (Delinea): Define security requirements for and lead enterprise-wide implementation of the Delinea PAM platform (Secret Server, Privilege Manager).

- Design privileged access controls — least privilege, JIT/JEA, session monitoring, credential rotation — across on-premises and cloud environments, and oversee onboarding of privileged accounts and systems.

- Produce audit-ready evidence of PAM controls aligned to frameworks such as SOX, HIPAA, PCI, and ISO 27001.

-
Secrets Governance: Own enterprise policy and lifecycle standards for all secrets — API keys, OAuth/OATH tokens, service account credentials, and certificates — including vaulting, rotation, and secure distribution.

- Drive detection and remediation of hardcoded, unmanaged, or leaked secrets across source code, configuration, and CI/CD pipelines.

- Establish metrics and reporting to track secrets governance maturity and compliance across the organization.

-
Governance & Collaboration: Participate in and help lead architecture review boards, governance forums, and risk committees for identity and privileged access.

- Maintain reference architectures, standards documentation, and roadmaps for identity, PAM, and secrets governance.

- Advise stakeholders on identity risk and control design for new initiatives, and mentor engineers implementing identity, PAM, and secrets solutions.

- Complete all responsibilities as outlined in the annual performance review and/or goal setting .

- Complete all special projects and other duties as assigned.

- Must be able to perform duties with or without reasonable accommodation.

This job description is intended to describe the general nature and level of work being performed and is not to be construed as an exhaustive list of responsibilities, duties and skills required. This job description does not constitute an employment agreement and is subject to change as the needs of Cotiviti and requirements of the job change.
Qualifications

- Bachelor’s degree in a technology discipline or equivalent professional experience.

- 8+ years of experience in identity and access management, privileged access management, or security architecture

← All remote jobs

Get remote developer jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you