We are seeking an Senior Identity and Access Management Architect / Senior IAM Architect to lead the design and evolution of our enterprise identity strategy. You will define how identities are securely managed, authenticated, and authorised across all environments—enabling a scalable, Zero Trust-aligned approach that protects the business while delivering a frictionless user experience. This is a high-impact role at the centre of our security and digital transformation journey.
JOB DUTIES:
- Own the enterprise IAM architecture strategy, target state, and roadmap across cloud, on-premises, and hybrid environments, aligned to Zero Trust and security standards.
- Serve as the IAM technical authority and provide hands-on architectural leadership across infrastructure, cloud, and platform security initiatives.
- Design and document end-to-end IAM capabilities across IGA, access management, PAM, secrets, and non-human identities.
- Define integration patterns and reference architectures; evaluate build vs. buy and emerging IAM capabilities (e.g., passwordless, AI/agentic identities, decentralised identity) to deliver scalable services across applications, infrastructure, and DevOps tooling.
- Architect authentication and authorisation (SSO, MFA, RBAC/ABAC) and standardize protocols (OAuth2/OIDC, SAML, SCIM, LDAP).
- Lead IAM platform design and integration across cloud/hybrid (e.g., Microsoft Entra ID, Active Directory, SailPoint, PingFederate/Ping Identity, AWS IAM, CyberArk or equivalent).
- Define identity lifecycle controls (joiner/mover/leaver, provisioning, access certifications, and role/entitlement modeling).
- Identify IAM risks and architecture gaps; define constraints and mitigations, and drive remediation through roadmap and delivery items.
- Ensure IAM controls and integrations meet security and regulatory requirements (e.g., NIST SP 800-63, ISO 27001, SOC 2, GDPR) and support audit activities.
- Partner with business stakeholders to align IAM outcomes to enterprise objectives and communicate decisions and tradeoffs to senior leadership.
YOU MUST HAVE:
- Strong experience in the identity and access management, preferably at architecture level, however IAM Engineers seeking opportunities to advance to an architecture role will be considered
- Strong experience across core IAM domains: IGA (lifecycle, certifications), access management (SSO/MFA), Conditional Access, PAM, and non-human identity (workload/service identities), with hands-on-experience with one or more enterprise IAM platforms (e.g., Microsoft Entra ID/Azure AD, Okta, Ping, SailPoint) and integration across cloud/hybrid environments.
- Deep knowledge of authentication/authorisation patterns and protocols: OAuth 2.0/OIDC, SAML 2.0, SCIM, and LDAP/AD.
- Solid understanding of cloud IAM (AWS, Azure, and/or GCP), including identity federation and least-privilege design.
- Experience assessing IAM risks and security controls, defining mitigations, and supporting audits and compliance requirements (e.g., NIST/ISO).
Strong analytical, problem-solving, and communication skills, with the ability to engage both technical and non-technical stakeholders effectively
Collaborative team player who adapts quickly to changing priorities while maintaining attention to detail
WE VALUE:
- Proven ability to define IAM target state, reference architectures, standards, and multi-phase roadmaps aligned to Zero Trust.
- Experience with secrets management (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
- Knowledge of DevSecOps practices and integrating IAM controls into CI/CD pipelines.
- Exposure to machine/workload identity federation (e.g., SPIFFE/SPIRE) and modern approaches to non-human identity.
WHATS IN IT FOR YOU:
- Funding provided to support your self-development
- 5 weeks of paid vacation
- Fully remote work model
- Flexible working hours
- On-site canteen & home office meal vouchers
- Pension plan or DIP contributions
- Discounted phone plans & company product discounts
- Multisport Card & cafeteria program
#LI-AM3
#LI-REMOTE
About UsResideo is a global leader in smart home and building solutions, with trusted brands including Honeywell Home, First Alert, and Resideo helping people feel more comfortable, secure, connected, and in control every day. Our products and technologies are found in more than 150 million homes and businesses worldwide. From intelligent climate solutions to security, sensing, water, and connected home technologies, Resideo develops and manufactures products designed to simplify everyday life and help protect what matters most. Our global teams span engineering, manufacturing, software, product management, supply chain, customer experience, and more — all working together to shape the future of connected living through innovation, quality, and meaningful real-world impact. At Resideo, our teams help create products and experiences that make everyday life more comfortable, secure, and connected for millions around the world. Learn more at www.resideo.com.
You can find out more about how the talent community works here: Resideo Talent Community Terms. Our recruitment privacy notice Resideo -Recruitment Privacy Notice - Dec 16 2022 describes in more detail how we process your personal data and how you can exercise your personal data rights.
If a disability prevents you from applying for a job through our website, request assistance here.
Skills Required
- Experience in identity and access management at architecture level or senior IAM engineering
- Experience across IGA (lifecycle, certifications), access management (SSO/MFA), Conditional Access, PAM, and non-human identities
- Hands-on experience with enterprise IAM platforms (Microsoft Entra ID/Azure AD, Okta, Ping, SailPoint) and cloud/hybrid integration
- Deep knowledge of authentication/authorization protocols: OAuth2/OIDC, SAML2.0, SCIM, LDAP/AD
- Solid understanding of cloud IAM (AWS, Azure, and/or GCP), identity federation, and least-privilege design
- Experience assessing IAM risks, defining mitigations, and supporting audits/compliance (NIST, ISO, SOC2, GDPR)
- Strong analytical, problem-solving, and communication skills to engage technical and non-technical stakeholders
- Collaborative team player who adapts to changing priorities with attention to detail
- Ability to define integration patterns, reference architectures, and evaluate emerging IAM capabilities (passwordless, decentralised identity)
Resideo Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Resideo and has not been reviewed or approved by Resideo.
-
Retirement Support — Feedback suggests the retirement program features a standout employer match and access to an employee stock purchase plan. These elements add meaningful long-term value to total rewards.
-
Leave & Time Off Breadth — Feedback suggests time off is generous in some salaried roles, with flexible or unlimited PTO alongside company holidays and parental leave. Actual usage appears to depend on team norms and manager support.
-
Healthcare Strength — Feedback suggests medical, dental, and vision coverage are comprehensive, complemented by wellness resources and health savings options in some plans. This establishes a solid baseline of health support across many roles.
Resideo Insights
What We Do
Resideo is a global leader in ensuring homeowners are safe, productive and comfortable in their homes. The company became an independent, publicly traded company in late 2018 as a result of Honeywell spinning off its Homes product portfolio and ADI Global Distribution businesses. Resideo’s mission is to provide its customers with integrated, simple solutions for today’s connected home.
Why Work With Us
Resideo puts people in charge of their home comfort, safety, security, and energy efficiency. We are also a top global distributor of security, fire, and low-voltage products. We work as a team of teams, where we all understand and work towards a common goal to solve challenges, serve our customers, and support the communities where we live.
Gallery
%20copy.jpg)





