What are the responsibilities and job description for the IAM Architect position at Mega Cloud Lab?
Scope Of Services
Tasks
Skills: entra id,pki,iam,nist,sox,architecture,iso,edirectory,saml,azure active directory,oauth 2.0,pci-dss
- IAM architect, engineering, administration and operations with focus on directory services and PKI
- Assess and develop a roadmap for OTI’s disparate directories consolidation
- Provide guidance and implementation support for integration with Entra and other IAM
- Architect and implement Citywide-level PKI modernization, including infrastructure
- Advice on governance, compliance, lifecycle management and automation of digital
- Lead migration planning, risk assessment, and mitigation for directories and PKI modernization
- Perform technical knowledge transfer, upskilling internal teams on new infrastructure
Tasks
- PKI Architecture, Engineering and Administrator – 40%
- Entra ID Architecture, Engineering and Administrator – 30%
- Directory Architecture, Engineering and Administrator – 20%
- IAM Level 3 Technical Support – 10%
- 12 years in IAM architect, engineering, administration and operations with focus on
- Deep expertise in Active Directory (on-prem and hybrid), Entra ID, and eDirectory
- Hands-on experience in designing and operating Microsoft PKI, including certificate
- Solid understanding of modern authentication/authorization protocols (OAuth, SAML,
- Experience with security roadmap development, risk assessment, and compliance
- Strong documentation, communication, and stakeholder management skills
- Experience with cloud PKI services
- Familiarity with Entra ID Governance, Conditional Access Policy, and modern security
- Experience automating PKI workflows (API/script-based certificate management)
- Multi-forest, multi-tenant IAM architecture expertise
- Prior experience working with Government /State agency
- Working knowledge of enterprise ITSM, change management, and project management
Skills: entra id,pki,iam,nist,sox,architecture,iso,edirectory,saml,azure active directory,oauth 2.0,pci-dss