← Back to all jobs

Senior Identity Application Architect, CIAM/IAM

Ahead · United States · Posted 2026-08-31

Apply on the company site →

Job description

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation. At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived. We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD. The Senior Identity Application Architect, CIAM/IAM, is responsible for leading the architecture, design, and evolution of identity solutions that support secure, scalable, and resilient customer and workforce access across the organization. This role defines target-state architecture and implementation patterns for customer identity and access management and enterprise identity and access management, including authentication, authorization, federation, lifecycle orchestration, delegated administration, and identity data flows across cloud and enterprise platforms. The architect partners with cybersecurity, infrastructure, application owners, product teams, and business stakeholders to translate business, security, privacy, and user experience requirements into practical identity architectures. This role also provides technical leadership for integrations across platforms such as Okta, Auth0, Azure, AWS, Salesforce, ServiceNow, and custom applications, with an emphasis on security, reliability, maintainability, and business enablement. Duties/Responsibilities Lead the architecture and design of CIAM and IAM solutions that support secure customer, partner, and workforce identity use cases across digital and enterprise environments. Define reference architectures, technical standards, integration patterns, and guardrails for identity services, authentication flows, authorization models, and lifecycle automation. Architect solutions for federation, single sign-on, adaptive authentication, MFA, delegated administration, identity proofing, registration, account recovery, consent, and progressive profiling. Author an improvement plan to transform the way Agent and Agentic NHI risks are handled, enabling the business to continue rapid Agent creation in a secure manner. Design identity application patterns and integrations using standards and protocols such as OAuth 2.0, OpenID Connect, SAML, SCIM, LDAP, REST APIs, webhooks, and event-driven architectures. Partner with engineering teams to guide implementation of identity-enabled applications, APIs, portals, and workflows while ensuring alignment to architecture principles and security requirements. Lead solution design for customer onboarding, workforce onboarding, joiner-mover-leaver processes, access request workflows, and fine-grained entitlement or role models where applicable. Drive architecture decisions for identity data models, directory strategy, attribute governance, role and group strategy, policy design, and integration with HR, CRM, ITSM, and other enterprise platforms. Evaluate and improve existing identity platforms, custom integrations, and application access patterns to reduce risk, technical debt, and operational friction. Ensure identity solutions are designed for resilience, scalability, observability, auditability, privacy, and compliance by design. Produce and maintain architecture diagrams, standards, roadmaps, decision records, and implementation guidance for technical and non-technical stakeholders. Facilitate design reviews, threat-informed architecture reviews, and technical governance activities for identity-related initiatives. Mentor engineers and administrators, providing architectural direction, implementation guidance, and best practices for secure identity application development and integration. Collaborate with vendors and internal teams to assess new capabilities, validate patterns, and recommend improvements aligned to strategic identity goals. Stay current on IAM and CIAM trends, standards, threats, and vendor capabilities, and translate that knowledge into actionable architectural recommendations. Education and Experience Bachelor’s degree in Computer Science , Information Technology, Cybersecurity, Software Engineering, or a related field, or equivalent practical work experience. Minimum 7 years of progressive experience in identity and access management, application security, or enterprise architecture, including significant experience designing identity solutions in complex environments. Minimum 4 years of experience architecting or leading implementations for CIAM and/or IAM platforms, including authentication, federation, authorization, and lifecycle orchestration use cases. Practical experience designing integrations across identity providers, cloud platforms, customer-facing applications, HR systems, CRM platforms, IT service management systems, and related enterprise applications. Experience with platforms and services such as Okta, Auth0, Microsoft Entra ID, AWS, Azure, Salesforce, ServiceNow, or comparable identity and business platforms. Experience leading technical design for secure APIs, identity-aware applications, and event-driven or service-based integrations. Demonstrated success in balancing security, privacy, user experience, scalability, and operational support requirements in production identity architectures. Required certification in at least one relevant identity or cybersecurity discipline, such as CISSP, CCSP, IDPro , Okta Certified Professional or Administrator, Okta Certified Developer, Microsoft SC-300, AWS S