Cybersecurity IAM Architect - Staff Engineer

Trim
Trim

IT

Baltimore, MD, USA

Posted on Aug 8, 2026

Cybersecurity IAM Architect - Staff Engineer

Location: Baltimore, MD
Job Number R2607-51845 Date posted 08/07/2026

Architecture & Solution Design

  • Develop enterprise-wide IAM and identity security architectures aligned to NIST standards, including NIST CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust principles

  • Design scalable identity solutions for authentication, authorization, federation, lifecycle management, access governance, privileged access, and policy enforcement across cloud, on-premises, SaaS, and hybrid environments

  • Define secure design patterns for AI agent identities, non-human identities, workload identities, service accounts, API access, secrets, delegated authority, and agent-to-tool interactions

  • Translate business, regulatory, and technical requirements into secure IAM solution blueprints, reference architectures, and reusable identity patterns

  • Establish least-privilege access models using RBAC, ABAC, PBAC, just-in-time access, dynamic credentials, and context-aware controls where appropriate

Solution Review & Risk Mitigation

  • Lead IAM architecture and security reviews for new technologies, applications, AI agents, automation platforms, APIs, and enterprise systems

  • Identify identity-related gaps in proposed solutions, including over-permissioned roles, shared credentials, weak delegation models, insufficient audit trails, and unmanaged non-human identities

  • Advise on risk mitigation strategies for authentication, authorization, privileged access, identity lifecycle, secrets management, token use, tool binding, and agent runtime access

  • Collaborate with engineering, cloud, infrastructure, application, and AI platform teams to ensure secure deployment of identity-enabled systems and services

  • Provide technical guidance to project and product teams throughout the system development lifecycle, with emphasis on secure-by-design IAM controls

Governance & Standards

  • Develop and maintain IAM architecture standards, identity control frameworks, access governance policies, and secure design patterns in alignment with NIST and industry best practices

  • Participate in or lead internal security governance boards and architecture review boards with a focus on identity risk, Zero Trust alignment, and AI agent access governance

  • Ensure solutions meet internal risk, compliance, and regulatory requirements, including CMMC, PCI DSS, and audit expectations for identity controls

  • Define governance expectations for joiner/mover/leaver processes, entitlement reviews, separation of duties, privileged access, service account ownership, non-human identity inventories, and exception management

  • Contribute to maturity assessments and continuous improvement efforts for IAM architecture, identity governance, and AI agent identity management capabilities

Collaboration & Leadership

  • Act as a subject matter expert on IAM, Zero Trust identity, non-human identity governance, and AI agent identity security for stakeholders across IT, engineering, compliance, risk, and AI product teams

  • Mentor junior architects and security engineers on identity architecture, secure access patterns, and governance-driven solution design

  • Communicate complex identity, access, AI agent, and risk concepts clearly to business leaders and non-technical audiences

  • Stay up to date on emerging threats, identity technologies, AI agent security patterns, and changes to the NIST ecosystem

Required Qualifications

  • 7–10 years of experience in cybersecurity, with 3+ years in IAM architecture, security architecture, or a similar solution design role

  • Deep working knowledge of NIST frameworks, including CSF, SP 800-53, SP 800-171, and SP 800-207 Zero Trust

  • Demonstrated experience designing and reviewing IAM architectures for enterprise systems, cloud environments, SaaS platforms, APIs, and hybrid environments

  • Strong understanding of IAM domains including identity lifecycle management, IGA, SSO, MFA, federation, PAM, RBAC, ABAC, PBAC, entitlement management, access reviews, and separation of duties

  • Hands-on familiarity with identity platforms and standards such as Okta, Microsoft Entra ID, SCIM, SAML, OAuth, OIDC, LDAP, Kerberos, and privileged access technologies

  • Strong understanding of LLMs, AI, and GenAI solutions, including agentic AI, MCP/tool hardening, non-human identity governance, agent-to-tool authorization, delegated access, and auditability of agent actions

  • Experience working in a large regulated environment and aligning identity controls to compliance frameworks

  • Excellent communication, collaboration, architecture documentation, and executive-facing presentation skills

Preferred

  • Industry certifications such as CISSP, CISM, CISA, CCSP, or identity-focused certifications

  • Experience with Zero Trust Architecture, modern identity security models, and enterprise access governance programs

  • Experience with policy-as-code, DevSecOps, infrastructure-as-code security, and automated identity control validation

  • Experience developing governance models for non-human identities, machine identities, workload identities, AI agents, service accounts, secrets, and API credentials