Principal Identity Security Architect & Product Engineering LeadLocation: Irving, TX (Dallas/Fort Worth Area)
Work Model: Hybrid – 3+ Days Onsite
Experience Level: Advanced – 6–9+ Years
Primary Skill: Cybersecurity
Additional Skills: Identity & Access Management (IAM), IAM Engineering, Advanced Cybersecurity Engineering
Position Overview
We are seeking a highly experienced Principal Identity Security Architect & Product Engineering Lead to drive the design, engineering, integration, and deployment of next-generation identity security capabilities across the enterprise.
The ideal candidate will combine deep expertise in Identity & Access Management (IAM), Identity Security Architecture, Zero Trust, and cybersecurity engineering with hands-on experience implementing and operationalizing enterprise identity security platforms.
This role will lead strategic initiatives focused on Attack Path Analysis, Identity Threat Protection, Authentication Modernization, Policy-Based Access Control (PBAC), Risk-Based Authentication, and Identity-Driven Attack Containment.
The successful candidate will work closely with Cybersecurity, Infrastructure, Engineering, Architecture, and Product teams to advance enterprise identity security capabilities, reduce identity-related risk, improve cyber resilience, and enhance the user access experience.
Key Responsibilities1. Identity Security Strategy & Architecture- Define and execute enterprise identity security roadmaps aligned with Zero Trust principles.
- Design scalable IAM architectures supporting workforce, privileged, and machine identities.
- Develop identity-centric security controls to reduce attack surfaces and prevent identity-based threats.
- Establish architectural standards for authentication, authorization, and access governance.
- Define identity security patterns and technical standards for enterprise applications and infrastructure.
- Drive modernization of identity security capabilities across the enterprise.
2. Product Engineering & Security Platform IntegrationLead engineering, integration, deployment, and operationalization activities for identity security platforms, including:- Sgnl.ai
- PlainID
- CrowdStrike Identity Protection
- Microsoft Entra ID (Azure AD)
- Authentication and authorization platforms
Responsibilities include:- Partner with product vendors and internal engineering teams to deliver secure and scalable identity security solutions.
- Drive integration of identity security capabilities into enterprise applications, infrastructure, and security ecosystems.
- Lead product engineering activities, technical implementation, configuration, and integration.
- Evaluate and implement security platform capabilities based on enterprise requirements.
- Support operationalization and continuous improvement of identity security products.
- Troubleshoot complex integration and implementation challenges.
3. Identity Threat Protection & Attack Path Analysis- Expand attack path analysis and mapping capabilities to identify exploitable identity-based attack vectors.
- Identify relationships between identities, privileges, entitlements, applications, systems, and resources.
- Implement identity threat detection and risk-scoring capabilities.
- Develop and improve identity-driven attack containment processes.
- Proactively identify privilege escalation paths and lateral movement opportunities.
- Enhance enterprise visibility into identity relationships, entitlements, permissions, and access risks.
- Support Identity Threat Detection and Response (ITDR) initiatives.
- Develop security controls that enable proactive identification and remediation of identity-related threats.
4. Authentication & Access Modernization- Support enhancements to authentication services, including Citi Authenticator capabilities and user-experience improvements.
- Accelerate adoption of strong and adaptive authentication controls.
- Support modernization of enterprise authentication and authorization services.
- Advance Policy-Based Access Control (PBAC) initiatives using platforms such as PlainID.
- Design identity-aware authorization models that improve security while reducing operational complexity.
- Support modern authentication and federation capabilities across enterprise applications.
5. Behavioral Analytics & Risk-Based Security- Design identity-risk models that enable adaptive authentication and access decisions.
- Leverage identity intelligence and behavioral analytics to identify abnormal access patterns.
- Support continuous verification and Zero Trust access controls.
- Utilize identity and behavioral signals to improve risk-based security decisions.
- Help develop security capabilities that dynamically respond to changes in identity risk.
Required Skills & ExperienceIdentity & Access ManagementStrong hands-on experience with enterprise IAM and identity security, including:- Microsoft Entra ID / Azure AD
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Identity Governance
- Access Management
- Privileged Access Management (PAM)
- Identity federation
- Modern authentication protocols
- Authentication and authorization architectures
- Enterprise IAM architecture and security frameworks
Identity Security Product ExpertiseStrong hands-on engineering, integration, or operational experience with:- Sgnl.ai
- PlainID
- CrowdStrike Identity Protection
- Microsoft Entra ID / Azure AD
Candidates should demonstrate the ability to engineer, integrate, deploy, and operationalize enterprise identity security products, rather than having experience limited to IAM administration or access provisioning.Security ArchitectureStrong understanding and practical experience with:- Zero Trust Architecture
- Identity Threat Detection & Response (ITDR)
- Attack Path Analysis
- Identity Security Architecture
- Authorization Frameworks
- Policy-Based Access Control (PBAC)
- Risk-Based Authentication
- Identity-centric security controls
- Identity-driven attack containment
- Authentication and authorization modernization
Engineering & Technical Skills- Strong product engineering and solution delivery experience.
- Experience integrating security platforms with enterprise applications and infrastructure.
- Ability to translate identity security requirements into scalable technical solutions.
- Experience working with APIs, integrations, authentication services, and authorization platforms.
- Strong troubleshooting and problem-solving capabilities across complex identity and security environments.
- Ability to work with internal engineering teams and external technology vendors.
Cross-Functional Technical Leadership- Partner closely with Cybersecurity, IAM, Infrastructure, Engineering, Architecture, Product, and Application teams.
- Lead technical discussions and influence identity security architecture decisions.
- Work with vendors and technology partners to implement enterprise security capabilities.
- Communicate complex identity security concepts to both technical and business stakeholders.
- Provide technical leadership for strategic identity security initiatives.
- Drive initiatives from architecture and design through implementation and operationalization.
Preferred Qualifications- Experience leading enterprise-scale IAM or Identity Security transformation initiatives.
- Experience implementing Zero Trust identity architectures.
- Experience with ITDR, Attack Path Analysis, or identity threat protection solutions.
- Experience with adaptive or risk-based authentication.
- Experience implementing PBAC/identity-aware authorization.
- Experience integrating identity security platforms with enterprise cybersecurity ecosystems.
- Experience working in large, complex enterprise environments.
- Strong understanding of emerging identity security threats and identity-driven attack techniques.