Cybersecurity IAM Architect - Staff Engineer

Posted Yesterday
Be an Early Applicant
Baltimore, MD, USA
In-Office
Senior level
Fintech
The Role
Design and lead enterprise IAM and identity security architecture aligned to NIST and Zero Trust. Build scalable authentication, authorization, federation, lifecycle, privileged access, and governance solutions across cloud, on-prem, SaaS, and hybrid systems. Review solutions, mitigate identity risks, advise engineering teams, and develop governance, policies, and patterns for non-human and AI agent identities. Mentor staff and communicate identity risk to stakeholders while ensuring regulatory compliance.
Summary Generated by Built In

Architecture & Solution Design

  • Develop enterprise-wide IAM and identity security architectures aligned to NIST standards, including NIST CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust principles

  • Design scalable identity solutions for authentication, authorization, federation, lifecycle management, access governance, privileged access, and policy enforcement across cloud, on-premises, SaaS, and hybrid environments

  • Define secure design patterns for AI agent identities, non-human identities, workload identities, service accounts, API access, secrets, delegated authority, and agent-to-tool interactions

  • Translate business, regulatory, and technical requirements into secure IAM solution blueprints, reference architectures, and reusable identity patterns

  • Establish least-privilege access models using RBAC, ABAC, PBAC, just-in-time access, dynamic credentials, and context-aware controls where appropriate

Solution Review & Risk Mitigation

  • Lead IAM architecture and security reviews for new technologies, applications, AI agents, automation platforms, APIs, and enterprise systems

  • Identify identity-related gaps in proposed solutions, including over-permissioned roles, shared credentials, weak delegation models, insufficient audit trails, and unmanaged non-human identities

  • Advise on risk mitigation strategies for authentication, authorization, privileged access, identity lifecycle, secrets management, token use, tool binding, and agent runtime access

  • Collaborate with engineering, cloud, infrastructure, application, and AI platform teams to ensure secure deployment of identity-enabled systems and services

  • Provide technical guidance to project and product teams throughout the system development lifecycle, with emphasis on secure-by-design IAM controls

Governance & Standards

  • Develop and maintain IAM architecture standards, identity control frameworks, access governance policies, and secure design patterns in alignment with NIST and industry best practices

  • Participate in or lead internal security governance boards and architecture review boards with a focus on identity risk, Zero Trust alignment, and AI agent access governance

  • Ensure solutions meet internal risk, compliance, and regulatory requirements, including CMMC, PCI DSS, and audit expectations for identity controls

  • Define governance expectations for joiner/mover/leaver processes, entitlement reviews, separation of duties, privileged access, service account ownership, non-human identity inventories, and exception management

  • Contribute to maturity assessments and continuous improvement efforts for IAM architecture, identity governance, and AI agent identity management capabilities

Collaboration & Leadership

  • Act as a subject matter expert on IAM, Zero Trust identity, non-human identity governance, and AI agent identity security for stakeholders across IT, engineering, compliance, risk, and AI product teams

  • Mentor junior architects and security engineers on identity architecture, secure access patterns, and governance-driven solution design

  • Communicate complex identity, access, AI agent, and risk concepts clearly to business leaders and non-technical audiences

  • Stay up to date on emerging threats, identity technologies, AI agent security patterns, and changes to the NIST ecosystem

Required Qualifications

  • 7–10 years of experience in cybersecurity, with 3+ years in IAM architecture, security architecture, or a similar solution design role

  • Deep working knowledge of NIST frameworks, including CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust

  • Demonstrated experience designing and reviewing IAM architectures for enterprise systems, cloud environments, SaaS platforms, APIs, and hybrid environments

  • Strong understanding of IAM domains including identity lifecycle management, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties

  • Hands-on familiarity with identity platforms and standards such as Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies

  • Strong understanding of LLMs, AI, and GenAI solutions, including agentic AI, MCP/tool hardening, non-human identity governance, agent-to-tool authorization, delegated access, and auditability of agent actions

  • Experience working in a large regulated environment and aligning identity controls to compliance frameworks

  • Excellent communication, collaboration, architecture documentation, and executive-facing presentation skills

Preferred

  • Industry certifications such as CISSP, CISM, CISA, CCSP, or identity-focused certifications

  • Experience with Zero Trust Architecture, modern identity security models, and enterprise access governance programs

  • Experience with policy-as-code, DevSecOps, infrastructure-as-code security, and automated identity control validation

  • Experience developing governance models for non-human identities, machine identities, workload identities, AI agents, service accounts, secrets, and API credentials

OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.

Skills Required

  • 7-10 years of experience in cybersecurity with 3+ years in IAM architecture, security architecture, or similar solution design role
  • Deep working knowledge of NIST frameworks including CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust
  • Experience designing and reviewing IAM architectures for enterprise systems, cloud, SaaS, APIs, and hybrid environments
  • Strong understanding of IAM domains: identity lifecycle, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, separation of duties
  • Hands-on familiarity with identity platforms and standards such as Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies
  • Strong understanding of LLMs, AI, and GenAI including agentic AI, non-human identity governance, agent-to-tool authorization, delegated access, and auditability
  • Experience working in a large regulated environment and aligning identity controls to compliance frameworks
  • Excellent communication, collaboration, architecture documentation, and executive-facing presentation skills
  • Industry certifications such as CISSP, CISM, CISA, CCSP, or identity-focused certifications
  • Experience with Zero Trust Architecture, modern identity security models, and enterprise access governance programs
  • Experience with policy-as-code, DevSecOps, infrastructure-as-code security, and automated identity control validation
  • Experience developing governance models for non-human identities, machine/workload identities, AI agents, service accounts, secrets, and API credentials

OneMain Financial Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about OneMain Financial and has not been reviewed or approved by OneMain Financial.

  • Retirement Support Retirement benefits include a 401(k) with a dollar-for-dollar match up to 4% after six months, supporting long-term savings. An employee stock purchase plan with a 10% discount adds another ownership-oriented reward element.
  • Leave & Time Off Breadth Time-off offerings include vacation that can grow to five weeks, paid holidays, personal days, sick time, and three paid volunteer days. Paid parental leave is offered at 100% pay for six weeks, adding to the overall leave mix.
  • Flexible Benefits A broad menu of benefits spans HSAs/FSAs, disability coverage, life and long-term care solutions, tuition reimbursement, and voluntary options like pet insurance and legal assistance. Backup child/elder care and adoption assistance further widen the set of selectable supports.

OneMain Financial Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Baltimore, Maryland
5,386 Employees
Year Founded: 1912

What We Do

OneMain provides personal loans with one on one, local service at branches nationwide. Our personalized loan solutions offer customers a simple and straightforward loan application, fixed rates, fixed payments, clear terms and multiple payment options.

Similar Jobs

PwC Logo PwC

Oracle SCM - Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
66 Locations
370000 Employees
77K-202K Annually

PwC Logo PwC

Data Scientist

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
65 Locations
370000 Employees
155K-410K Annually

General Motors Logo General Motors

Account Executive

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees
106K-141K Annually

Collectors Logo Collectors

Senior Platform Engineer

Consumer Web • eCommerce • Machine Learning • Software • Sports • Analytics
In-Office or Remote
2 Locations
2246 Employees
140K-200K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account