Cybersecurity IAM Architect Staff Engineer
Baltimore, MD - USA
Job Summary
Architecture & Solution Design
Develop enterprise-wide IAM and identity security architectures aligned to NIST standards including NIST CSF SP 800-53 SP 800-171 and SP 800-207 Zero Trust principles
Design scalable identity solutions for authentication authorization federation lifecycle management access governance privileged access and policy enforcement across cloud on-premises SaaS and hybrid environments
Define secure design patterns for AI agent identities non-human identities workload identities service accounts API access secrets delegated authority and agent-to-tool interactions
Translate business regulatory and technical requirements into secure IAM solution blueprints reference architectures and reusable identity patterns
Establish least-privilege access models using RBAC ABAC PBAC just-in-time access dynamic credentials and context-aware controls where appropriate
Solution Review & Risk Mitigation
Lead IAM architecture and security reviews for new technologies applications AI agents automation platforms APIs and enterprise systems
Identify identity-related gaps in proposed solutions including over-permissioned roles shared credentials weak delegation models insufficient audit trails and unmanaged non-human identities
Advise on risk mitigation strategies for authentication authorization privileged access identity lifecycle secrets management token use tool binding and agent runtime access
Collaborate with engineering cloud infrastructure application and AI platform teams to ensure secure deployment of identity-enabled systems and services
Provide technical guidance to project and product teams throughout the system development lifecycle with emphasis on secure-by-design IAM controls
Governance & Standards
Develop and maintain IAM architecture standards identity control frameworks access governance policies and secure design patterns in alignment with NIST and industry best practices
Participate in or lead internal security governance boards and architecture review boards with a focus on identity risk Zero Trust alignment and AI agent access governance
Ensure solutions meet internal risk compliance and regulatory requirements including CMMC PCI DSS and audit expectations for identity controls
Define governance expectations for joiner/mover/leaver processes entitlement reviews separation of duties privileged access service account ownership non-human identity inventories and exception management
Contribute to maturity assessments and continuous improvement efforts for IAM architecture identity governance and AI agent identity management capabilities
Collaboration & Leadership
Act as a subject matter expert on IAM Zero Trust identity non-human identity governance and AI agent identity security for stakeholders across IT engineering compliance risk and AI product teams
Mentor junior architects and security engineers on identity architecture secure access patterns and governance-driven solution design
Communicate complex identity access AI agent and risk concepts clearly to business leaders and non-technical audiences
Stay up to date on emerging threats identity technologies AI agent security patterns and changes to the NIST ecosystem
Required Qualifications
710 years of experience in cybersecurity with 3 years in IAM architecture security architecture or a similar solution design role
Deep working knowledge of NIST frameworks including CSF SP 800-53 SP 800-171 and SP 800-207 Zero Trust
Demonstrated experience designing and reviewing IAM architectures for enterprise systems cloud environments SaaS platforms APIs and hybrid environments
Strong understanding of IAM domains including identity lifecycle management IGA SSO MFA federation PAM RBAC ABAC PBAC entitlement management access reviews and separation of duties
Hands-on familiarity with identity platforms and standards such as Okta Microsoft Entra ID SCIM SAML OAuth OIDC LDAP Kerberos and privileged access technologies
Strong understanding of LLMs AI and GenAI solutions including agentic AI MCP/tool hardening non-human identity governance agent-to-tool authorization delegated access and auditability of agent actions
Experience working in a large regulated environment and aligning identity controls to compliance frameworks
Excellent communication collaboration architecture documentation and executive-facing presentation skills
Preferred
Industry certifications such as CISSP CISM CISA CCSP or identity-focused certifications
Experience with Zero Trust Architecture modern identity security models and enterprise access governance programs
Experience with policy-as-code DevSecOps infrastructure-as-code security and automated identity control validation
Experience developing governance models for non-human identities machine identities workload identities AI agents service accounts secrets and API credentials
OneMain Holdings Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age ancestry citizenship status color creed culture disability ethnicity gender gender identity or expression genetic information or history marital status military status national origin nationality pregnancy race religion sex sexual orientation socioeconomic status transgender or on any other basis protected by law.
Required Experience:
Staff IC
About Company
Sometimes unexpected costs occur, so trust OneMain to provide personal loans for home improvement, debt consolidation, car purchases, & more.