Senior Identity Security Architect in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Identity Security Architect based in United States.
This is a senior-level opportunity focused on strengthening identity security across complex enterprise environments.
You will work at the intersection of identity architecture, attack path analysis, and large-scale security remediation.
The role combines hands-on technical expertise with customer advisory, architecture guidance, and methodology development.
You will help organizations turn sophisticated attack path findings into practical remediation strategies and measurable risk reduction.
Working closely with customers, researchers, consultants, and technical teams, you will influence security programs across critical identity environments.
You will also help shape repeatable frameworks, reference architectures, and delivery practices that can scale across enterprise engagements.
This remote role is ideal for an experienced identity security professional who enjoys solving complex problems and translating technical insight into business outcomes.
- Serve as a trusted advisor to enterprise customers implementing Identity Attack Path Management programs and help translate attack path findings into actionable remediation strategies.
- Analyze identity attack paths and help customers prioritize remediation based on risk, business impact, dependencies, and operational constraints.
- Facilitate collaboration across Security, Infrastructure, IAM, Endpoint Management, Engineering, and other stakeholder groups to drive remediation initiatives forward.
- Provide architectural and operational guidance across Active Directory, Microsoft Entra ID, and hybrid identity environments.
- Advise on delegated administration, privileged access management, administrative tiering, identity governance, service account security, and broader identity modernization initiatives.
- Assist customers with the development and operationalization of Privilege Zones and evaluate identity architectures through an adversary-focused, attack-path lens.
- Develop remediation frameworks, playbooks, reference architectures, and repeatable guidance covering prioritization, ownership, implementation, and validation.
- Identify recurring customer challenges and codify successful remediation patterns to strengthen scalable delivery methodologies.
- Partner with security researchers to translate emerging tradecraft and attack path research into practical customer guidance.
- Support consultants and Technical Account Managers through training, mentorship, and technical guidance while contributing to the evolution of identity security best practices.
- Help establish and mature enterprise remediation methodologies and architectural frameworks that improve customer outcomes and enable measurable reductions in identity-related risk.
- 8+ years of experience designing, operating, securing, modernizing, or remediating enterprise identity environments.
- Deep expertise in Active Directory and Microsoft Entra ID, including hybrid identity architectures and identity synchronization technologies.
- Practical experience with BloodHound or comparable attack path analysis methodologies.
- Demonstrated success leading enterprise remediation, modernization, migration, or security improvement initiatives.
- Strong understanding of administrative tiering, delegated administration, privileged access management, identity governance, and enterprise identity operations.
- Experience working directly with technical and business stakeholders, ideally in consulting, professional services, or customer-facing advisory environments.
- Proven ability to develop methodologies, frameworks, operational programs, and repeatable remediation practices.
- Excellent written and verbal communication skills, with the ability to translate complex security concepts into clear recommendations for varied audiences.
- Experience supporting large-scale enterprise Active Directory environments, particularly environments with 50,000+ users, is highly desirable.
- Familiarity with offensive security principles, adversary tradecraft, or red team operations is a plus.
- Experience with identity platforms such as Okta, Ping Identity, CyberArk, or SailPoint is advantageous.
- Familiarity with endpoint management technologies such as Microsoft Intune, SCCM, Tanium, or Jamf is beneficial.
- Knowledge of PKI, virtualization, cloud infrastructure, and other critical enterprise technologies is a plus.
- Must be authorized to work and reside in the United States; immigration sponsorship is not currently available for this position.
- Base salary: $175,000–$200,000 USD, with actual compensation depending on experience, location, and other relevant factors.
- Additional compensation: Eligibility for bonus and equity opportunities.
- Healthcare: 100% company-paid health, dental, vision, and life insurance for employees and their families.
- Retirement: 401(k) with up to a 4% company match.
- Time off: Flexible time-off policy plus 13 paid holidays annually.
- Remote work: $1,500 first-year home-office setup allowance and $500 annual home-office allowance thereafter.
- Connectivity: $150 monthly reimbursement for cell phone and internet expenses.
- Professional development: $5,000 annual professional development allowance.
- Education support: Up to $5,250 toward continuing education or student loan repayment.
- Wellness: $1,200 annual benefit supporting lifestyle, wellness, pet insurance, and related expenses.
- Family support: One-time $10,000 benefit toward family planning.
- Work environment: Fully remote U.S.-based position with optional quarterly travel for in-person company events and occasional meetings.
- Culture and collaboration: Opportunities to participate in virtual and in-person employee events while working with experienced security professionals on impactful identity security challenges.