Source description
About the role
Role: IAM - Senior Lead / Architect
Location: Seattle Onsite
1 Position
JD
Description and Location
15+ years experience.
What You'll Do
-
Define and own the target-state architecture and reference designs for the identity security platform across BeyondTrust (Password Safe, EPM, PRA), Microsoft Entra ID, Active Directory, and SailPoint IDN.
-
Lead the architecture and deployment strategy for large-scale identity security modernization initiatives — privileged access transformation, identity governance modernization, cloud identity adoption, Active Directory and hybrid-identity modernization, and Zero Trust identity patterns.
-
Establish architecture standards, design patterns, integration blueprints, and guardrails that the build/engineering teams implement against, and serve as design authority through architecture and design reviews.
-
Develop migration and deployment strategies — sequencing, cutover, rollback, and risk mitigation — for moving large user and system populations onto modern identity platforms with minimal disruption.
-
Architect integrations across identity platforms, cloud (Azure, AWS, GCP), and enterprise/SaaS applications using APIs, federation, and provisioning standards (SAML, OAuth2/OIDC, SCIM, Kerberos, LDAP).
-
Drive phishing-resistant authentication and least-privilege/PAM architecture across the enterprise.
-
Partner with engineering leads, security architecture, platform/cloud teams, product, and program management to translate architecture into delivery roadmaps and executable workstreams.
-
Provide technical leadership and guidance to build engineers; review designs and key implementations to ensure alignment to architecture and security requirements.
-
Identify and document architectural risks, dependencies, and trade-offs; present recommendations and decisions to engineering and leadership audiences.
-
Contribute to the security posture and control objectives of the modernization program, ensuring designs meet Nordstrom security, compliance, and data-handling requirements.
-
Leverage AI tooling to accelerate architecture analysis, design documentation, and solution evaluation.
-
What You Bring
-
Bachelor's or master's degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and experience.
-
15+ years of security or identity engineering experience, including significant experience as an identity/security architect on enterprise-scale environments.
-
Demonstrated experience leading large-scale identity security modernization or transformation programs end to end — from target-state architecture through production deployment.
-
Deep architecture-level expertise across two or more of the following, with strong working knowledge of the rest: BeyondTrust, Microsoft Entra ID, Active Directory, Okta, and SailPoint.
-
Strong command of identity architecture fundamentals: authentication/authorization protocols (SAML, OAuth2/OIDC, SCIM, Kerberos, LDAP), federation, MFA and phishing-resistant authentication, RBAC/ABAC, least privilege, tiered administration, and Zero Trust identity.
-
Proven experience designing integrations and migrations across hybrid and multi-cloud environments at scale.
-
Experience setting architecture standards and acting as a design authority across multiple delivery teams.
-
Excellent communication skills — able to align engineers, architects, and senior leadership around architecture decisions and trade-offs.
-
Ability to operate independently in a fast-paced, multi-workstream program with high ambiguity.
-
Nice to Have:
-
Architecture or security certifications such as CISSP, SABSA, TOGAF, Microsoft Identity & Access Administrator (SC-300), or SailPoint Certified Engineer.
-
Experience with infrastructure-as-code (Terraform, Ansible) and CI/CD as enablers of identity platform delivery.
-
Experience with identity threat detection and response (ITDR) and integrating identity signals into SIEM/SOAR.
-
Large-scale retail, ecommerce, or other high-transaction enterprise experience.
More at Alpha Net Consulting
Related open roles
SVP – Cyber Technology Engineer
New York · Hybrid
Senior Full-Stack Engineer Python, Temporal & AI Workflows
Remote · San Francisco Bay Area
Onshore Senior Unix Linux SME -CGEMJP00349841
United States · Hybrid
Director, Splunk Platform Engineering & SRE
New York
IAM - Senior Lead / Architect-CGEMJP00347873
Seattle · Hybrid
Senior Security Engineer
United States · Onsite