IAM Architect
IAM Architect
Location: Onsite in Washington DC
Duration: 6 month contract, extensions/conversion likely
*CURRENT OR PREVIOUS PUBLIC TRUST CLEARANCE (OR HIGHER) IS REQUIRED*
We are seeking a senior-level Identity Access Management (IAM) Architect to serve as the technical authority for enterprise identity and access management capabilities within a highly regulated federal environment. This individual will lead the design, implementation, and governance of modern IAM frameworks supporting secure authentication, authorization, compliance, and least-privilege access across hybrid cloud and on-premises environments.
This role is heavily focused on architecture, engineering, and strategic IAM leadership rather than program management. The ideal candidate brings deep hands-on expertise with Microsoft Entra ID, Microsoft ICAM, identity governance, privileged access controls, and Zero Trust security principles. The position partners closely with security, infrastructure, cloud, and operations teams to drive IAM modernization, ensure audit readiness, and support enterprise-scale identity services.
Responsibilities:
- Serve as the enterprise subject matter expert and technical lead for Identity and Access Management architecture and services.
- Design and implement secure authentication and authorization solutions leveraging Microsoft Entra ID, Microsoft ICAM, and role-based access control (RBAC).
- Lead integration of identity services with Microsoft 365 and enterprise applications to support identity lifecycle management and policy enforcement.
- Define IAM standards, architectural patterns, and operating procedures aligned with Zero Trust and federal security requirements.
- Manage identity lifecycle processes, including provisioning, deprovisioning, access changes, and account governance.
- Implement and maintain multifactor authentication (MFA), conditional access, privileged identity management (PIM), privileged access management (PAM), and identity protection controls.
- Establish and administer access reviews, entitlement management processes, and governance workflows to enforce least-privilege access.
- Design and oversee RBAC models, access assignments, recertification efforts, and automated access-control processes.
- Support compliance initiatives by creating and maintaining IAM documentation, control evidence, and audit artifacts.
- Assist with audit remediation efforts, corrective action plans, and resolution of IAM-related risks and findings.
- Lead troubleshooting and resolution of complex identity and access issues across hybrid enterprise environments.
- Drive automation of identity provisioning, policy enforcement, reporting, and administrative processes.
- Collaborate with security, cloud, endpoint, and service management teams to implement identity-dependent security controls.
- Provide strategic IAM guidance, roadmap recommendations, and modernization planning to stakeholder groups.
Qualifications:
Qualifications:
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, or a related field.
- Minimum 8 years of experience in Identity and Access Management, Identity Governance, Cybersecurity, or related enterprise security disciplines.
- Hands-on experience implementing and supporting Microsoft Entra ID (Azure AD) and Microsoft ICAM.
- Advanced experience with MFA, conditional access, RBAC, PIM, PAM, and identity governance solutions.
- Strong expertise in identity lifecycle management, access provisioning, and governance workflows.
- Experience integrating identity services with Microsoft 365 and enterprise applications.
- Strong understanding of Zero Trust architecture and identity-centric security controls.
- Experience supporting compliance and security frameworks including NIST, ISO 27001, CISA SCuBA, and FISMA.
- Ability to obtain and maintain a Public Trust clearance or higher.
- U.S. work authorization meeting contract requirements.
Preferred Qualifications:
- Experience leading IAM modernization initiatives within federal or highly regulated enterprise environments.
- Experience supporting financial regulatory, public sector, or mission-critical organizations.
- Experience implementing phishing-resistant authentication methods and legacy authentication modernization efforts.
- Hands-on experience with IAM automation, scripting, and integration of identity controls into DevSecOps environments.
- Experience supporting audit remediation activities, corrective action plans, and executive-level risk reporting.
- Microsoft Certified: Identity and Access Administrator Associate (SC-300).
- CISSP and/or CISM certification.
Compensation
$65.00-$71.00 HourlyAbout Us
Technology Doesn't Change the World, People Do.®
Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.
Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app and get 1-tap apply, notifications of AI-matched jobs, and much more.
All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.
© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s Terms of Use and Privacy Notice.
