Principal Identity Architect
Boston, MA
Category: Security
Industry: Communications
Reference ID: JN -022026-105558
Date Posted: 03/19/2026
Shortcut: http://careers.eliassen.com/q5J142
Description:
Hybrid Tues, Wed, Thurs onsite in Boston, MA
The organization seeks a Principal Identity Architect to lead enterprise identity strategy and execution across Identity Governance and Administration and Privileged Access Management. The role will design scalable identity architectures, automate lifecycle processes, and implement zero trust controls including MFA, SSO, and conditional access. The Principal will partner across security, IT, and application teams to drive adoption of standards and serve as the subject matter expert for identity, authentication, authorization, and access governance.
This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.
Salary: $150,000 - $180,000/ yr. w2
Responsibilities:
- Lead the design, development, and implementation of the Identity Governance and Administration solution and support the implementation of the Privileged Access Management solution.
- Design integrations between the IGA solution and directory services, HR systems, and business applications.
- Translate business and security requirements into scalable identity architectures, workflows, and automation patterns.
- Architect solutions for joiner, mover, and leaver processes and identity lifecycle automation.
- Collaborate with the Security Operations team on PAM solution implementation.
- Work with Security Operations, Network, and Application teams to ensure consistent adoption of identity patterns.
- Implement zero trust access controls including conditional access, least privilege, and posture-based enforcement.
- Design enterprise-wide authentication and access control frameworks including enhancements to MFA, SSO, passwordless, and risk-adaptive authentication.
- Oversee maintenance of IGA and PAM solutions including configuration of identity policies.
- Partner with GRC to define IAM and PAM standards and execute related policies and entitlement governance standards.
- Provide guidance for third-party and vendor access assessments and IAM controls testing.
- Engage IT and business partners to drive adoption of the IGA solution and zero trust principles.
- Serve as SME for identity-related decisions and technologies, guiding engineers, administrators, and application owners.
- Establish standards for entitlement models, RBAC, segregation of duties, and certification workflows.
- Mentor IAM and PAM engineers, analysts, and administrators.
- Review system designs for alignment with IAM principles and security controls.
- Educate stakeholders on identity-related matters to increase awareness and improve processes.
Experience Requirements:
- 10 years of experience in identity security.
- Deep expertise with modern IAM platforms, with SailPoint preferred.
- Strong understanding of authentication and authorization protocols and directory services.
- Experience designing IAM solutions at enterprise scale.
- Proven ability to lead enterprise-scale identity transformations.
- Ability to convey complex identity concerns in an actionable manner and constructively challenge prevailing processes.
- Demonstrated judgment, urgency, and commitment to ethics, regulatory compliance, customer service, and business integrity.
- Approximately 10% travel.
- Strong organization, planning, and project management skills with the ability to prioritize to meet deadlines.
- Ability to work across functional groups and levels to achieve results professionally.
- Strong leadership skills with the ability to drive and motivate teams.
Education Requirements:
- Bachelor’s degree or equivalent work experience.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:
· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact fraud@eliassen.com.
-
Business Systems Analyst
Covington
Description: Hybrid Onsite Every Other Week in Covington, KY Our client is seeking a Business Systems Analyst to support the Identity and Access Management Adoption Team within Enterprise Cybersecurity. The role will focus on business and systems analy...
Date Posted: 04/07/2026 Recommended
-
Sr. Software Developer II
Washington dc, DC
Description: Onsite in Washington dc, DC The organization seeks a Sr. Software Developer II to deliver secure and reliable software for mission-critical federal systems. The role focuses on building and modernizing enterprise applications using C#, .NE...
Date Posted: 03/16/2026 Recommended
-
Senior Oracle DBA (Azure)
Pittsburgh, PA
Description: Our client, a leader in their industry, has an excellent opportunity for a Senior Oracle DBA with Azure cloud experience to work on a 12-month+ contract position in Lake Mary, FL, or Pittsburgh, PA. This is a hybrid role working onsite two...
Date Posted: 04/02/2026 Recommended
-
Cloud Platform Engineer (AWS)
Anywhere
Description: Remote Our client is seeking a mid-level AWS Platform Engineer to design, build, and operate secure, scalable cloud infrastructure on AWS. The role focuses on developing reusable infrastructure patterns, automation, and governance that ena...
Date Posted: 03/11/2026 Recommended
-
Platform Engineer III
Cincinnati, OH
Description: Onsite in Cincinnati, OH The organization seeks a hands-on Kafka Platform Engineer to support and scale an enterprise event-driven architecture on Amazon MSK within AWS. The role owns Kafka infrastructure, automation, and operational excel...
Date Posted: 03/17/2026 Recommended
-
DevOps / MLOps Engineer
Westlake, TX
Description: Hybrid 50% ON SITE, requires candidates local to the area within Westlake, TX / DFW greater metro We are seeking a hands-on DevOps Engineer to support and modernize cloud infrastructure for a large, mission‑critical platform in the financi...
Date Posted: 03/15/2026 Recommended
-
Senior API Developer
Anywhere
Description: Remote The organization seeks a Senior API Developer to design, develop, and maintain APIs and system integrations across a digital ecosystem. The role will utilize Microsoft Azure services including API Management, Application Gateway, Lo...
Date Posted: 03/23/2026 Recommended
-
Security Administrator
Cincinnati, OH
Description: Hybrid 4 days week onsite, then 3 days onsite/2 remote in Cincinnati, OH We are hiring a Security Administrator for our client, a leading plumbing, sewer, and water damage company headquartered in Cincinnati, Ohio. The role will secure ent...
Date Posted: 04/04/2026 Recommended
-
AAA Network Engineer
Englewood, CO
Description: Onsite in Englewood, CO Our client seeks a core wireless and network engineer to deliver carrier-grade AAA for Wi‑Fi offload and roaming. The role focuses on RADIUS policy design, SIM-based EAP methods, secure transport, and high-throughpu...
Date Posted: 03/31/2026 Recommended
-
Physical Security Systems Engineer
Austin, TX
Description: Hybrid Monday - Thursday in either Austin, TX or Salt Lake City, UT or Dublin, IE The organization seeks a Physical Security Systems Engineer to support and optimize enterprise physical security technologies. The role will administer acces...
Date Posted: 03/26/2026 Recommended
-
Senior Cloud Platform Engineer
Anywhere
Description: Remote Our client seeks a senior platform engineer to design, build, and operate secure, scalable AWS infrastructure. The role focuses on reusable platform capabilities, automation, and governance that enable engineering teams to deliver a...
Date Posted: 03/11/2026 Recommended
-
Sr. Wireless Network Engineer III
Washington dc, DC
Description: Onsite in Washington, DC The organization seeks a Sr. Wireless Network Engineer III to design, deploy, and optimize secure enterprise Wi-Fi across a mission-critical federal environment. The role will perform RF site surveys, troubleshoot ...
Date Posted: 04/08/2026 Recommended
-
Cybersecurity Analyst
Cranberry Township, PA
Description: Hybrid 3 in Cranberry Township, PA The Cybersecurity Analyst will safeguard the organization’s information systems and data by monitoring security events, analyzing vulnerabilities, and responding to incidents. The role requires hands-on e...
Date Posted: 04/01/2026 Recommended
-
IT Infrastructure Engineer/Administrator
Boston, MA
Description: Onsite in Boston, MA Seaport Area of Boston, 5 days a week onsite for the first few months, flexible for 3-4 days onsite after that. Interview: virtual, then onsite. Contract to hire role. Our client seeks a senior IT Infrastructure Engine...
Date Posted: 03/12/2026 Recommended
-
Sr. Database Engineer I
Washington dc, DC
Description: Onsite in Washington dc, DC The organization seeks a Sr. Database Engineer with PostgreSQL expertise to support mission-critical federal applications. The role will design, administer, and optimize databases across on-premises and cloud en...
Date Posted: 03/16/2026 Recommended
-
Principal Software Engineer
Jersey City, NJ
Description: Hybrid 50% ON SITE, half remote, work site either Jersey City, NJ or Westlake, TX Our client seeks a Principal Software Engineer to advance an enterprise AI/ML platform within a large, highly regulated industry environment. This role is id...
Date Posted: 03/24/2026 Recommended
-
GenAI Scientist
Atlanta, GA
Description: Open to remote candidates - but must work EST hours. Our client, a nationally-recognized transportation and logistics company seeks a GenAI Scientist to build and enhance enterprise-grade conversational AI and document intelligence capabil...
Date Posted: 03/15/2026 Recommended
-
Server Administrator
Anaheim, CA
Description: Onsite in Anaheim, CA Our client seeks a Server Administrator to ensure stability, security, and resilience across Linux and Windows Server platforms supporting internet and intranet services. The role will design and operate enterprise ba...
Date Posted: 03/31/2026 Recommended
-
Senior Product Owner
Cincinnati, OH
Description: Onsite in Cincinnati, OH The Senior Product Owner will lead an agile engineering squad to deliver and scale an AI agent chatbot for customer service. The role will define and prioritize product roadmaps, collaborate with cross-functional p...
Date Posted: 03/29/2026 Recommended
-
Senior Software Engineer – Power BI & Angular
Durham, NC
Description: Hybrid two weeks onsite a month in Durham, NC The organization seeks a senior engineer to deliver data-driven reporting and intuitive user interfaces using Power BI and Angular. The role will design scalable dashboards, secure data models,...
Date Posted: 03/20/2026 Recommended
-
Sr. Network Security Engineer III
Washington dc, DC
Description: Onsite in Washington, DC The Sr. Network Security Engineer III will secure and harden mission-critical enterprise networks for our client within a federal environment. The role will design and manage firewalls, VPNs, IDS/IPS, and NAC, enfo...
Date Posted: 04/08/2026 Recommended
-
Senior Data Engineer
Burbank, CA
Description: Hybrid 3-4 days onsite in either Burbank, CA or Orlando, FL Our client seeks senior data engineers to build and refactor data pipelines supporting enterprise data collection, transformation, and delivery. The role centers on Snowflake and ...
Date Posted: 03/31/2026 Recommended
-
FedRAMP & AWS GovCloud Program Lead
Anywhere
Description: Remote Our client seeks a senior FedRAMP and AWS GovCloud leader to advise telecommunications and regulated clients on modernization, migration, and authorization. The role owns strategy, roadmap, and oversight to move legacy workloads to ...
Date Posted: 03/30/2026 Recommended
-
Sr. Telecommunications Design Engineer III
Washington dc, DC
Description: Onsite in Washington dc, DC Our client seeks a Sr. Telecommunications Design Engineer III to provide senior technical leadership for mission-critical telecommunications operations and long-range modernization. The role will design and sust...
Date Posted: 03/13/2026 Recommended
-
Product Manager – ServiceNow HRSD
Anywhere
Description: Remote Our client seeks a Product Manager to lead ServiceNow HR Service Delivery with a focus on foundational reporting. The role will define product vision, optimize HRSD modules, and deliver analytics that enhance employee experience and...
Date Posted: 03/31/2026 Recommended
-
Jr. Integration Engineer
Atlanta, GA
Description: Hybrid 2-3x weekly in Atlanta, GA Our client seeks a junior integration engineer to design and maintain RESTful APIs and connect internal and external systems across a modern platform. The role will contribute to integration development, d...
Date Posted: 03/31/2026 Recommended
-
Mid-Level Software Test Engineer
San Diego, CA
Description: Hybrid 3 days on site in San Diego, CA The organization seeks a Mid-Level Software Test Engineer to ensure product quality for a mobile user application within an agile environment. The role will author and execute manual and automated tes...
Date Posted: 04/07/2026 Recommended
-
Data Architect
St. Louis, MO
Description: Hybrid Local candidates strongly preferred - onsite 2-3 days per week. If non-local, they will be required to come usually ~2 months for 3 days. in St. Louis, MO The organization seeks a Data Architect to design and build capabilities for ...
Date Posted: 04/08/2026 Recommended
-
Contractor Special Security Officer
Huntsville, AL
Description: Onsite in Huntsville, AL our client seeks a Contractor Special Security Officer to lead SAP and SCI security operations, facility accreditation, and personnel access management. The role requires mastery of SAP and SCI directives, includin...
Date Posted: 03/25/2026 Recommended
-
Sr. Network Engineer III
Washington dc, DC
Description: Onsite in Washington, DC The Sr. Network Engineer III will serve as a subject matter expert for unified communications across voice, video, and collaboration platforms in a fast-paced, mission-critical environment. The role will design, im...
Date Posted: 04/08/2026 Recommended
Eliassen Group is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. Eliassen Group’s Affirmative Action Plan (AAP) is available for inspection by any employee or applicant for employment upon request, during normal business hours of Monday through Friday, 8:30am to 5:30pm EST. Interested persons should contact Phaedra Wells at pwells@eliassen.com for assistance. It is unlawful in Massachusetts and Maryland to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Applicants with disabilities that believe they require an accommodation or assistance with a position, please email our HR team at hradmin@eliassen.com. This email inbox is designed exclusively to assist job seekers whose disability prevents them from being able to apply online. Emails sent for other purposes will not receive a response.
Please be advised that a number of fraudulent job postings have been released under the Eliassen Group brand.
Unfortunately, fraudulent job postings can happen. If anyone reaches out to you about an open position connected with Eliassen Group, never provide personal or financial information to anyone who is not clearly associated with Eliassen Group
If anyone seemingly from Eliassen Group has ever requested this personal information in the past or does so in the future, please contactInfoSec@eliassen.com.
Please ensure that you are working directly with us by confirming the following:
- When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
- Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group, as indicated above