What are the responsibilities and job description for the IAM - Senior Lead / Architect position at capgemini?
What You'll Do:
Define and own the target-state architecture and reference designs for the identity security platform across BeyondTrust (Password Safe, EPM, PRA), Microsoft Entra ID, Active Directory, and SailPoint IDN.
Lead the architecture and deployment strategy for large-scale identity security modernization initiatives — privileged access transformation, identity governance modernization, cloud identity adoption, Active Directory and hybrid-identity modernization, and Zero Trust identity patterns.
Establish architecture standards, design patterns, integration blueprints, and guardrails that the build/engineering teams implement against, and serve as design authority through architecture and design reviews.
Develop migration and deployment strategies — sequencing, cutover, rollback, and risk mitigation — for moving large user and system populations onto modern identity platforms with minimal disruption.
Architect integrations across identity platforms, cloud (Azure, AWS, GCP), and enterprise/SaaS applications using APIs, federation, and provisioning standards (SAML, OAuth2/OIDC, SCIM, Kerberos, LDAP).
Drive phishing-resistant authentication and least-privilege/PAM architecture across the enterprise.
Partner with engineering leads, security architecture, platform/cloud teams, product, and program management to translate architecture into delivery roadmaps and executable workstreams.
Provide technical leadership and guidance to build engineers; review designs and key implementations to ensure alignment to architecture and security requirements.
Identify and document architectural risks, dependencies, and trade-offs; present recommendations and decisions to engineering and leadership audiences.
Contribute to the security posture and control objectives of the modernization program, ensuring designs meet Nordstrom security, compliance, and data-handling requirements.
Leverage AI tooling to accelerate architecture analysis, design documentation, and solution evaluation.
What You Bring:
Bachelor's or master's degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and experience.
15 years of security or identity engineering experience, including significant experience as an identity/security architect on enterprise-scale environments.
Demonstrated experience leading large-scale identity security modernization or transformation programs end to end — from target-state architecture through production deployment.
Deep architecture-level expertise across two or more of the following, with strong working knowledge of the rest: BeyondTrust, Microsoft Entra ID, Active Directory, Okta, and SailPoint.
Strong command of identity architecture fundamentals: authentication/authorization protocols (SAML, OAuth2/OIDC, SCIM, Kerberos, LDAP), federation, MFA and phishing-resistant authentication, RBAC/ABAC, least privilege, tiered administration, and Zero Trust identity.
Proven experience designing integrations and migrations across hybrid and multi-cloud environments at scale.
Experience setting architecture standards and acting as a design authority across multiple delivery teams.
Excellent communication skills — able to align engineers, architects, and senior leadership around architecture decisions and trade-offs.
Ability to operate independently in a fast-paced, multi-workstream program with high ambiguity.
Nice to Have:
Architecture or security certifications such as CISSP, SABSA, TOGAF, Microsoft Identity & Access Administrator (SC-300), or SailPoint Certified Engineer.
Experience with infrastructure-as-code (Terraform, Ansible) and CI/CD as enablers of identity platform delivery.
Experience with identity threat detection and response (ITDR) and integrating identity signals into SIEM/SOAR.
Large-scale retail, ecommerce, or other high-transaction enterprise experience.
The pay range that the employer in good faith reasonably expects to pay for this position is $58.25/hour - $91.01/hour. Our benefits include medical, dental, vision and retirement benefits. Applications will be accepted on an ongoing basis.
Tundra Technical Solutions is among North America’s leading providers of Staffing and Consulting Services. Our success and our clients’ success are built on a foundation of service excellence. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Unincorporated LA County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: client provided property, including hardware (both of which may include data) entrusted to you from theft, loss or damage; return all portable client computer hardware in your possession (including the data contained therein) upon completion of the assignment, and; maintain the confidentiality of client proprietary, confidential, or non-public information. In addition, job duties require access to secure and protected client information technology systems and related data security obligations.
Salary : $58 - $91