IAM Architect

Posted Yesterday
Be an Early Applicant
Boston, MA, USA
In-Office
128K-297K Annually
Senior level
Financial Services
The Role
Lead design and implementation of enterprise Identity and Access Management and IGA strategy and target-state architecture. Assess current identity landscape, select and deploy IGA/IdP technologies, define governance/lifecycle controls for human and non-human identities, strengthen SOC1 controls, migrate legacy systems, and remain hands-on building integrations, workflows, and proofs-of-concept while partnering with security, IT, risk, compliance, and business stakeholders.
Summary Generated by Built In

Job Overview

We are seeking a senior Identity Management and Identity Governance & Administration (IGA) Architect to define and execute the firm's long-term identity strategy, governance model, target-state architecture, and technology roadmap.

This individual will serve as the firm's identity subject matter expert, partnering with technology, cybersecurity, risk, compliance, audit, and business stakeholders to modernize the organization's identity capabilities and establish identity as a foundational security control across the enterprise.

This role will assess the current Identity Provider and IGA landscape, including existing solutions, use cases, legacy systems, access governance processes, entitlement models, and application integrations. The candidate will identify what is working well, where gaps and risks exist, and define a clear path toward a modern, secure, scalable next-generation Identity Provider and IGA framework.

This is a highly visible role requiring both strategic leadership and hands-on execution. The successful candidate will architect and help build the next-generation identity platform, manage the transition from legacy systems, strengthen SOC1-related identity controls, and partner closely with IT, security, cloud, application, infrastructure, risk, compliance, and audit stakeholders.

Responsibilities

  • Define and lead the firm's Identity and Access Management strategy, target-state architecture, operating model, and multi-year roadmap across identity governance, access management, privileged access, and non-human identities.

  • Evaluate, select, and implement identity technologies and platforms, leading architecture reviews, technology assessments, proof-of-concepts, and vendor selection initiatives to support evolving business, security, and regulatory requirements.

  • Establish enterprise identity standards, governance frameworks, and success metrics, while partnering with technology and business leaders to drive adoption, manage risk, and continuously mature the firm's identity capabilities.

  • Own and lead the firm’s Identity Management, Identity Provider, and Identity Governance & Administration strategy and roadmap.

  • Assess current identity solutions, IGA processes, access models, legacy integrations, and control gaps across the firm.

  • Architect the next-generation identity and IGA framework covering human identities, non-human identities, privileged accounts, service accounts, workload identities, API identities, and AI agentic workload identities.

  • Define and implement governance standards for joiner/mover/leaver processes, access requests, approvals, provisioning, deprovisioning, entitlement management, access reviews, and role models.

  • Design modern authentication, authorization, federation, and delegation patterns using technologies such as OpenID Connect, OAuth 2.0, SAML, Kerberos, LDAP, Microsoft Entra ID, AWS IAM, Active Directory, and Secret Management platforms.

  • Establish governance and lifecycle controls for non-human identities, including ownership, risk classification, access review, secret rotation, and least-privilege enforcement.

  • Design identity patterns for On-Behalf-Of workflows, delegated permissions, service-to-service access, application impersonation, and AI/agent-based access scenarios.

  • Lead the smooth migration of legacy applications and systems to the next-generation Identity Provider and IGA architecture.

  • Partner with IT stakeholders to understand current challenges and define practical, secure, and scalable identity solutions.

  • Own and improve SOC1-related controls for Identity Provider and IGA processes, including audit evidence, control documentation, access reviews, and remediation tracking.

  • Remain hands-on in building and implementing identity solutions, integrations, workflows, standards, and proof-of-concepts.

Requirements

  • Demonstrated experience defining enterprise Identity and Access Management strategies, architectures, operating models in complex environments.

  • Experience evaluating, selecting, and implementing identity technologies, including leading platform assessments, proof-of-concepts, vendor evaluations, and architecture review processes.

  • Proven ability to influence and partner with senior technology, cybersecurity, risk, compliance, and business stakeholders to drive identity transformation initiatives and align identity capabilities with organizational objectives.

  • Proven experience leading or supporting identity and IGA transformation programs in a large enterprise environment.

  • Strong hands-on knowledge of IGA capabilities, including access request, approval workflows, provisioning, deprovisioning, joiner/mover/leaver processes, entitlement management, access certification, role-based access control, and application onboarding.

  • Experience with major IGA platforms such as SailPoint, Saviynt, Omada, One Identity, Microsoft Entra ID Governance, or equivalent solutions.

  • Deep technical knowledge of Microsoft Entra ID, on-premises Active Directory, AWS IAM, Kerberos, LDAP, federation, and hybrid identity environments.

  • Strong understanding of OpenID Connect, OAuth 2.0, SAML, delegated authorization, On-Behalf-Of flows, and service-to-service authentication.

  • Experience with non-human identity management, including service accounts, workload identities, machine identities, API identities, secret management, ownership models, and lifecycle controls.

  • Experience with AI agentic workload identity, permission delegation, and autonomous or automated access patterns is strongly preferred.

  • Strong understanding of SOC1 controls, audit readiness, access governance, privileged access controls, and identity-related risk management.

  • Prior experience in a similar identity architecture, IGA, or security leadership role in another enterprise firm.

The base salary range for this position is $128,000 - $297,000 per year.

Arrowstreet Capital operates a robust talent acquisition program, and we also seek to compensate and reward our employees competitively within our industry and in line with our merit-based culture. Our approach to total compensation includes base salaries and annual discretionary bonuses, as well as a robust benefits package. The determination of a successful candidate’s base salary placement within the listed range will vary based on the candidate’s relevant experience and qualifications (which may also include relevant certifications, credentials and other education), the job responsibilities and scope, the commensurate resulting level of the position and other relevant factors. The listed range is also an estimate, and additional information regarding base salary and other elements of total compensation offered by Arrowstreet Capital to successful applicants will be communicated during the recruitment process.  

Arrowstreet Capital is a Boston-based systematic investment firm that manages global equity portfolios for institutional investors around the world. 

All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, ancestry, genetic information, age, pregnancy, medical condition, disability, veteran or military status, marital status or any other characteristic protected by federal, state, or local law.

Arrowstreet Capital is committed to working with and providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you need a reasonable accommodation for any part of the employment process due to a disability, contact us to discuss the nature of your request and contact information.

Skills Required

  • Demonstrated experience defining enterprise Identity and Access Management strategies, architectures, and operating models in complex environments.
  • Experience evaluating, selecting, and implementing identity technologies, including platform assessments, proofs-of-concept, and vendor evaluations.
  • Proven ability to influence and partner with senior technology, cybersecurity, risk, compliance, and business stakeholders.
  • Proven experience leading or supporting identity and IGA transformation programs in a large enterprise.
  • Strong hands-on knowledge of IGA capabilities: access request workflows, provisioning, deprovisioning, joiner/mover/leaver, entitlement management, access certification, RBAC, application onboarding.
  • Experience with major IGA platforms such as SailPoint, Saviynt, Omada, One Identity, Microsoft Entra ID Governance, or equivalent solutions.
  • Deep technical knowledge of Microsoft Entra ID, on-premises Active Directory, AWS IAM, Kerberos, LDAP, federation, and hybrid identity environments.
  • Strong understanding of OpenID Connect, OAuth 2.0, SAML, delegated authorization, On-Behalf-Of flows, and service-to-service authentication.
  • Experience with non-human identity management: service accounts, workload/machine/API identities, secret management, ownership models, lifecycle controls.
  • Experience with AI agentic workload identity, permission delegation, and autonomous or automated access patterns.
  • Strong understanding of SOC1 controls, audit readiness, access governance, privileged access controls, and identity-related risk management.
  • Prior experience in an identity architecture, IGA, or security leadership role at an enterprise firm.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
438 Employees
Year Founded: 1999

What We Do

Arrowstreet Capital is a Boston-based investment manager that provides global and international equity investment strategies and fund products to institutional investors such as pension plans, endowments, foundations, and registered/unregistered commingled investment funds. We offer a select range of global equity investment strategies managed as long-only, alpha extension and long/short utilizing a broad range of instruments, including swaps and futures. Our investment process utilizes quantitative methods that focus on identifying and incorporating investment signals into our proprietary return, risk and transaction cost models. Our investment approach involves creating and investing in diversified equity portfolios. We utilize a structured investment process that attempts to add value relative to a client specific benchmark. This involves identifying opportunities across companies, sectors and countries by evaluating a diverse set of fundamental and market-based predictive factors. Portfolios are constructed through the use of a mean variance optimizer and proprietary risk and transaction cost models. Arrowstreet Capital manages approximately $100 billion for over 200 client relationships in North America, the United Kingdom, Europe and the Asia-Pacific regions.

Similar Jobs

Wipfli Logo Wipfli

Data Architect

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
3000 Employees
142K-191K Annually

Wipfli Logo Wipfli

Assistant Controller

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
3000 Employees
73K-98K Annually

Mondelēz International Logo Mondelēz International

Product Owner

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
United States
90000 Employees
140K-193K Annually

Federal Reserve Bank of Boston Logo Federal Reserve Bank of Boston

Senior Analyst, Financial Support Office

Fintech • Information Technology • Payments • Sharing Economy • Financial Services • Cryptocurrency
In-Office
4 Locations
1200 Employees
98K-122K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account