About Astellas
Astellas is a global life sciences company committed to turning innovative science into VALUE for patients. We provide transformative therapies in disease areas that include oncology, ophthalmology, urology, immunology and women's health. Through our research and development programs, we are pioneering new healthcare solutions for diseases with high unmet medical need. Learn more at Astellas.com.
Are you driven to make a real difference in the lives of patients?
We're seeking passionate individuals who thrive in dynamic environments, embrace new ideas, and aren't afraid to take intelligent risks. People who act with unwavering integrity and are deeply committed to making a tangible impact.
Purpose and Scope:
As an Identity Management Architect, this role is responsible for defining, governing, and evolving the enterprise IAM architecture to ensure secure, scalable, and compliant access across systems and applications. The position is established to provide strategic ownership of IAM platforms, drive identity modernization initiatives, and align access controls with Zero Trust security principles. The IAM Architect will set architectural standards, guide solution design, and ensure consistent implementation across identity, access governance, and privileged access services.
Responsibilities and Accountabilities:
- Define, own, and govern the enterprise IAM architecture, strategy, roadmap, and reference standards, aligned with business objectives, security policies, and regulatory requirements.
- Provide strategic ownership of IAM platforms, including Microsoft Entra ID, Conditional Access, Multi‑Factor Authentication (MFA), Identity Governance (IGA), and Privileged Access Management (PAM).
- Design end‑to‑end IAM solutions covering authentication, authorization, identity lifecycle management (Joiner-Mover-Leaver), and privileged access, ensuring scalability, resilience, and security‑by‑
- Establish and enforce architecture standards, design patterns, and guardrails to ensure consistent and secure implementation across applications, APIs, directories, and cloud platforms.
- Lead identity modernization initiatives, embedding Zero Trust principles, least‑privilege access, and risk‑based controls across all identity and access solutions.
- Architect and govern Single Sign‑On (SSO), federation (SAML, OAuth2, OpenID Connect), RBAC/ABAC models, and integrations across enterprise and third‑party systems.
- Identify and assess identity‑related security risks, emerging threats, and architectural gaps, and define remediation or design improvements to mitigate current and future risks.
- Evaluate current‑state IAM capabilities and define target‑state architectures, including trade‑offs, dependencies, and phased modernization roadmaps.
- Ensure IAM architecture aligns with enterprise security standards and relevant frameworks (e.g., NIST, ISO 27001) and supports audit and regulatory requirements (e.g., ISO, SOX, GDPR).
- Partner with security, engineering, application, HR, and business teams to translate requirements into scalable IAM solutions and present architectural decisions, risks, and recommendations to senior leadership.
- Drive continuous improvement through automation, innovation, and adoption of modern IAM technologies, improving both security posture and user experience.