Principal Identity Architect
Boston, MA
Category: Security
Industry: Communications
Reference ID: JN -022026-105558
Date Posted: 02/17/2026
Shortcut: http://careers.eliassen.com/q5J142
Description:
Hybrid Tues, Wed, Thurs onsite in Boston, MA
The organization seeks a Principal Identity Architect to lead enterprise identity strategy and execution across Identity Governance and Administration and Privileged Access Management. The role will design scalable identity architectures, automate lifecycle processes, and implement zero trust controls including MFA, SSO, and conditional access. The Principal will partner across security, IT, and application teams to drive adoption of standards and serve as the subject matter expert for identity, authentication, authorization, and access governance.
This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.
Salary: $150,000 - $180,000/ yr. w2
Responsibilities:
- Lead the design, development, and implementation of the Identity Governance and Administration solution and support the implementation of the Privileged Access Management solution.
- Design integrations between the IGA solution and directory services, HR systems, and business applications.
- Translate business and security requirements into scalable identity architectures, workflows, and automation patterns.
- Architect solutions for joiner, mover, and leaver processes and identity lifecycle automation.
- Collaborate with the Security Operations team on PAM solution implementation.
- Work with Security Operations, Network, and Application teams to ensure consistent adoption of identity patterns.
- Implement zero trust access controls including conditional access, least privilege, and posture-based enforcement.
- Design enterprise-wide authentication and access control frameworks including enhancements to MFA, SSO, passwordless, and risk-adaptive authentication.
- Oversee maintenance of IGA and PAM solutions including configuration of identity policies.
- Partner with GRC to define IAM and PAM standards and execute related policies and entitlement governance standards.
- Provide guidance for third-party and vendor access assessments and IAM controls testing.
- Engage IT and business partners to drive adoption of the IGA solution and zero trust principles.
- Serve as SME for identity-related decisions and technologies, guiding engineers, administrators, and application owners.
- Establish standards for entitlement models, RBAC, segregation of duties, and certification workflows.
- Mentor IAM and PAM engineers, analysts, and administrators.
- Review system designs for alignment with IAM principles and security controls.
- Educate stakeholders on identity-related matters to increase awareness and improve processes.
Experience Requirements:
- 10 years of experience in identity security.
- Deep expertise with modern IAM platforms, with SailPoint preferred.
- Strong understanding of authentication and authorization protocols and directory services.
- Experience designing IAM solutions at enterprise scale.
- Proven ability to lead enterprise-scale identity transformations.
- Ability to convey complex identity concerns in an actionable manner and constructively challenge prevailing processes.
- Demonstrated judgment, urgency, and commitment to ethics, regulatory compliance, customer service, and business integrity.
- Approximately 10% travel.
- Strong organization, planning, and project management skills with the ability to prioritize to meet deadlines.
- Ability to work across functional groups and levels to achieve results professionally.
- Strong leadership skills with the ability to drive and motivate teams.
Education Requirements:
- Bachelor’s degree or equivalent work experience.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
Please be advised- If anyone reaches out to you about an open position connected with Eliassen Group, please confirm that they have an Eliassen.com email address and never provide personal or financial information to anyone who is not clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact InfoSec@eliassen.com.
-
GRC Business Analyst
Boston, MA
Description: Hybrid Tues, Wed, Thurs onsite in Boston, MA Our client is an American real estate investment trust that owns, develops, and operates wireless and broadcast communications infrastructure across several countries. The organization enables s...
Date Posted: 02/20/2026 Recommended
-
Okta IAM Architect
Culver City, CA
Description: Hybrid 4 days onsite in Culver City, CA The Okta/IAM will serve as the technical SME for identity and access management solutions, driving architecture, integration, and security strategy. The role requires deep expertise in Okta and relat...
Date Posted: 03/07/2026 Recommended
-
Principal Systems Analyst
Merrimack, NH
Description: Hybrid Every other week onsite/5 days in either Merrimack, NH or Smithfield, RI Our client seeks a Principal Systems Analyst to lead entitlement strategy and identity governance across enterprise platforms. The role will align access model...
Date Posted: 02/14/2026 Recommended
-
IAM/RBAC Engineer
Pittsburgh, PA
Description: Hybrid 4 in either Pittsburgh, PA, New York, NY or Lake Mary, FL The organization seeks an IAM/RBAC Engineer to design, implement, and administer access controls in Microsoft Entra ID and Azure RBAC. The contractor will enforce least-privi...
Date Posted: 03/03/2026 Recommended
-
Information Security Engineer (Ping Identity)
Anywhere
Description: Remote Our client is a large U.S. financial institution headquartered in Cincinnati, Ohio, with a broad regional branch and ATM network across multiple states. The organization is a principal subsidiary of a public bank holding company and...
Date Posted: 02/08/2026 Recommended
-
Senior Cybersecurity Architect
Tustin, CA
Description: Onsite in Tustin, CA Our client seeks an experienced Security Architect with prior experience in law enforcement, government, or public safety IT environments and familiarity with CJIS, NIST, FedRAMP, or state compliance frameworks. Due to...
Date Posted: 02/13/2026 Recommended
-
Infrastructure Engineer
Pittsburgh, PA
Description: Hybrid 4 in either Pittsburgh, PA, New York, NY or Lake Mary, FL Our client is a global investments company that manages and services financial assets throughout the investment lifecycle. The organization supports institutions, corporation...
Date Posted: 02/24/2026 Recommended
-
Security Administrator
Cincinnati, OH
Description: Hybrid 4 days week onsite, then 3 days onsite/2 remote in Cincinnati, OH We are hiring a Security Administrator for our client, a leading plumbing, sewer, and water damage company headquartered in Cincinnati, Ohio. The role will secure ent...
Date Posted: 03/05/2026 Recommended
-
Software Engineer
Merrimack, NH
Description: Hybrid 2 weeks per month onsite in Merrimack, NH The Common Platform Solutions team within Asset Management provides standardized technology stacks, frameworks, and reusable components that accelerate delivery. This role reports to a direc...
Date Posted: 03/07/2026 Recommended
-
MDM Engineering & Operations Manager
Anywhere
Description: Remote Our client seeks an MDM Engineering & Operations Manager to lead design, deployment, administration, and daily operations of Customer MDM on Profisee. The role drives high-quality golden records for analytics, reporting, downstream ...
Date Posted: 03/06/2026 Recommended
-
AI Engineer
Pittsburgh, PA
Description: Hybrid 3 days onsite, 2 days remote in Pittsburgh, PA Our client is scaling enterprise generative AI and agent-based solutions across business functions. The team operates across data, application, and AI layers, emphasizing secure archite...
Date Posted: 02/10/2026 Recommended
-
Data Engineer
Westlake, TX
Description: Hybrid Every Other Week onsite in Westlake, TX Our client seeks a Data Engineer to build a modern data platform using Apache Iceberg on AWS with Spark, Kafka, and Python. The role emphasizes scalable data pipelines, distributed processing,...
Date Posted: 02/23/2026 Recommended
-
Sr. Mobile Application Developer I
Washington dc, DC
Description: Onsite in Washington, DC The organization seeks a Sr. Mobile Application Developer to deliver secure, mission-critical iOS and Android capabilities for a federal customer. The role operates within an Agile team focused on high-security mob...
Date Posted: 02/11/2026 Recommended
-
Application Security Engineer
Tysons Corner, VA
Description: Hybrid 3 days onsite in Tysons Corner, VA A private, non‑governmental entity that functions as a self‑regulatory organization, responsible for oversight, enforcement, and dispute resolution within the securities industry, following the con...
Date Posted: 02/17/2026 Recommended
-
Senior Cybersecurity Engineer
Washington dc, DC
Description: Hybrid 2-3 days onsite in Washington, DC Our client seeks a senior cybersecurity engineer to deliver NSA CSfC-compliant architectures for secure communications in classified environments. The role drives implementation of Data-at-Rest and ...
Date Posted: 02/10/2026 Recommended
-
Senior Oracle DBA (Azure)
Pittsburgh, PA
Description: Our client, a leader in their industry, has an excellent opportunity for a Senior Oracle DBA with Azure cloud experience to work on a 12-month+ contract position in Lake Mary, FL, or Pittsburgh, PA. This is a hybrid role working onsite two...
Date Posted: 03/03/2026 Recommended
-
Senior Full Stack Engineer, AI
Anywhere
Description: Remote Our client seeks a senior full stack engineer to accelerate AI adoption across the organization. The role blends full stack development, AI engineering, and internal consulting to design secure, scalable solutions and guide teams on...
Date Posted: 03/03/2026 Recommended
-
Cloud & Network Infrastructure Engineer
Washington, DC
Description: Onsite in Washington, DC Our client requires a senior Cloud and Network Infrastructure Engineer to lead cloud and on‑premises network design, implementation, and operations. The role focuses on hybrid connectivity, security, and reliabilit...
Date Posted: 02/08/2026 Recommended
-
Contractor Special Security Officer
Huntsville, AL
Description: Onsite in Huntsville, AL The organization seeks a Contractor Special Security Officer to lead SAP and SCI security operations, facility accreditation, and personnel access management. The role requires mastery of SAP/SCI directives and clo...
Date Posted: 02/23/2026 Recommended
-
MuleSoft Architect
Anywhere
Description: Remote Our client seeks a MuleSoft Architect to lead architecture, design, and delivery of enterprise integrations centered on Deltek Costpoint. The role will define API-led connectivity, govern standards, and implement secure, scalable in...
Date Posted: 03/05/2026 Recommended
-
Senior Integration Developer – Oracle Cloud Integrations
Austin, TX
Description: Hybrid 2-3 days onsite in Austin, TX As a Senior Integration Developer – Oracle Cloud Integrations, you will be the definitive technical expert responsible for developing, maintaining, governing, and standardizing all data movement involvi...
Date Posted: 02/11/2026 Recommended
-
Master Data Management Expert
Anywhere
Description: Remote Our client, a top 20 financial services institution is seeking an MDM SME to join a growing Data team. This overall effort is focused on integrating acquired company data and ensuring accuracy, scalability and reliability. This is a...
Date Posted: 02/18/2026 Recommended
-
Security Analyst
Washington, DC
Description: Hybrid 3 days onsite / 2 days remote in Rockville, MD or Tysons Corner, VA Our client is a leading independent regulatory organization overseeing brokerage firms and registered financial professionals for compliance with federal securities...
Date Posted: 02/17/2026 Recommended
-
Product Owner III
Pittsburgh, PA
Description: Hybrid 4 days onsite in Pittsburgh, PA Our client seeks a Product Owner III with strong Agile delivery experience in regulated environments. The role translates mission-driven, security, and compliance requirements into a prioritized, exec...
Date Posted: 02/11/2026 Recommended
-
SailPoint Test Engineer
Westlake, MA
Description: Hybrid every other week onsite/5 days in Westlake, MA The Workforce Identity and Access Management product line team provides provisioning, lifecycle management, and control assessment solutions to technology teams and applications across ...
Date Posted: 02/18/2026 Recommended
-
Senior Software Engineer
Pittsburgh, PA
Description: Hybrid 4 in Pittsburgh, PA The organization is launching a secure, fault‑tolerant Azure platform for high‑volume data ingestion, ledger‑based recordkeeping, and analytics for a controlled user base. This backend‑focused full‑stack role emp...
Date Posted: 03/04/2026 Recommended
-
ERP Manager
Willingboro, NJ
Description: Onsite in either Willingboro, NJ or Downers Grove, IL The ERP Manager will lead and oversee the strategy, support, and ongoing improvement of the organization’s ERP ecosystem, including multiple instances of Epicor Prophet 21, one instance...
Date Posted: 02/12/2026 Recommended
-
Senior MuleSoft Integration Architect
Anywhere
Description: Remote The organization seeks a Senior MuleSoft Integration Architect to lead end-to-end API-led integration solutions on MuleSoft Anypoint Platform. The role will drive standards, governance, and delivery quality while executing nine core...
Date Posted: 03/01/2026 Recommended
-
IT Infrastructure Engineer/Administrator
Boston, MA
Description: Onsite in Boston, MA Seaport Area of Boston, 5 days a week onsite for the first few months, flexible for 3-4 days onsite after that. Interview: virtual, then onsite. Contract to hire role. Our client seeks a senior IT Infrastructure Engine...
Date Posted: 02/10/2026 Recommended
-
Lead Software Engineer
Hartford, CT
Description: Hybrid 2-3 days onsite in either Hartford, CT or Short Hills, NJ As Lead Software Engineer, you will drive technical direction and execution for robust, scalable, and maintainable enterprise software solutions within a cloud-first environm...
Date Posted: 02/12/2026 Recommended
Eliassen Group is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. Eliassen Group’s Affirmative Action Plan (AAP) is available for inspection by any employee or applicant for employment upon request, during normal business hours of Monday through Friday, 8:30am to 5:30pm EST. Interested persons should contact Phaedra Wells at pwells@eliassen.com for assistance. It is unlawful in Massachusetts and Maryland to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Applicants with disabilities that believe they require an accommodation or assistance with a position, please email our HR team at hradmin@eliassen.com. This email inbox is designed exclusively to assist job seekers whose disability prevents them from being able to apply online. Emails sent for other purposes will not receive a response.
Please be advised that a number of fraudulent job postings have been released under the Eliassen Group brand.
Unfortunately, fraudulent job postings can happen. If anyone reaches out to you about an open position connected with Eliassen Group, never provide personal or financial information to anyone who is not clearly associated with Eliassen Group
If anyone seemingly from Eliassen Group has ever requested this personal information in the past or does so in the future, please contactInfoSec@eliassen.com.
Please ensure that you are working directly with us by confirming the following:
- When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
- Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group, as indicated above