
Posted 5 days ago
ICAM Architect
AI Summary
The ICAM Architect leads the design and modernization of enterprise Identity, Credential, and Access Management (ICAM) capabilities into a cloud-ready, Zero Trust architecture, defining target state and providing architectural oversight for distributed, secure, and scalable identity services.
About this role
We are seeking an experienced ICAM Solutions Architect to support a major Identity, Credential, and Access Management (ICAM) modernization initiative. This role will focus on transforming legacy Identity and Access Management capabilities into a modern, cloud-ready architecture using microservices, automation, and DevSecOps best practices.
As the technical architecture lead, you will define the target enterprise architecture, guide modernization efforts, and provide architectural oversight to ensure solutions are secure, scalable, interoperable, and aligned with Zero Trust (ZT) and enterprise ICAM strategies. You will collaborate closely with technical leadership, engineering teams, and program stakeholders to deliver mission-critical identity services supporting enterprise operations.
Responsibilities
- Define and maintain the enterprise ICAM architecture supporting the modernization of Policy Enforcement Points (PEP), Policy Information Points (PIP), Enterprise Management Services (EMS), and Resource & Policy Management Services (RPMS)
- Lead the transition from legacy Policy Decision Point (PDP) technologies to modern authorization frameworks
- Design end-to-end architectures supporting identity services, authorization workflows, policy management, attribute services, and resource lifecycle management
- Develop architecture artifacts including sequence diagrams, data models, interface specifications, and system design documentation
- Partner with Technical Leads and engineering teams to validate modernization roadmaps, architectural decisions, and cloud migration strategies
- Architect modern Policy Enforcement Point (PEP) and Policy Information Point (PIP) services supporting Attribute-Based Access Control (ABAC), dynamic policy evaluation, and event-driven authorization
- Design enterprise authorization services, policy lifecycle automation, resource registration, and attribute orchestration capabilities
- Provide technical guidance to software engineering, DevOps, and operations teams throughout the development lifecycle
- Conduct architecture reviews, technical risk assessments, and compliance evaluations to ensure modernization objectives are achieved
- Drive improvements in automation, observability, deployment pipelines, scalability, resilience, and operational efficiency
- Evaluate emerging identity technologies, authentication methods, authorization frameworks, and integration patterns to improve enterprise ICAM capabilities
- Serve as a trusted technical advisor to program leadership, supporting strategic planning, budgeting, customer engagements, and long-term modernization initiatives