Sr Identity Architect
Strategic Staffing Solutions is currently looking for a Sr Identity Architect for a W2 contract opportunity!
Sr Identity Architect
Location: Detroit, MI - Hybrid schedule (In office Tue, Wed, Thu)
Duration: 12+ month contract with eligibility for renewal.
Role Type: W2 contract
Required Skills:
10+ years of experience in Cybersecurity, Information Security, or Enterprise Architecture, with at least 5 years dedicated specifically to enterprise-scale IAM architecture and design.• Proven track record of leading identity transformation programs within highly regulated industries (e.g., utilities, financial services, aerospace, or critical infrastructure).
• Extensive experience designing, visualizing, and implementing IAM solutions across hybrid environments, including multi-tier infrastructures and major public cloud domains.
Company Overview
As a leading Fortune 500 public utility company, we provide safe, reliable, and essential energy and infrastructure services to millions of customers. Operating in a highly regulated and rapidly evolving landscape, we are launching a multi-year technology modernization initiative. Utility infrastructure requires applying security best practices and operational consistency across both corporate IT and operational technology (OT) environments, while maintaining the necessary isolation to protect critical infrastructure. We are seeking a visionary Principal Identity Architect to serve as the chief designer and strategist for our enterprise identity ecosystem.
Position Summary
The Principal Identity Architect is a senior-level, hybrid leadership role operating as a high-influence individual contributor. This position is responsible for defining the long-term vision, strategy, and target architecture for our enterprise Identity and Access Management (IAM) program. This position will serve as a hands-on technical authority who blends macro-level strategy with actionable, engineering blueprints.
The successful candidate will lead the unification of a highly diverse technical landscape that has grown organically through various business cycles. Your mission will be to visually interpret this distributed environment, map it against our long-term corporate and technical strategies, and build an executable 5-year modernization roadmap. Importantly, this role demands immediate impact: you will prioritize the concurrent mitigation of areas yielding the highest risk and greatest short-term benefit while simultaneously shaping the long-term, foundational strategy. You will act as the authoritative voice on how identities are governed, authenticated, and authorized, ensuring our technical architecture complies with stringent federal and state utility regulations.
Key Responsibilities
Tactical Execution & Architecture Unification
• Conduct an immediate, visually driven inventory of the distributed identity landscape across all corporate IT, cloud, and operational technology (OT) systems.
• Translate abstract security concepts into clear, high-utility technical diagrams, end-to-end process workflows, and architectural visualizations that effectively communicate the current and future state to both executive leadership and technical engineers.
• Identify areas yielding the highest risk and greatest short-term benefit within the current environment during your first 90 days and engineer practical, tactical remediations to be fully executed while the broader strategy takes root.
• Establish authoritative enterprise identity standards incorporated into all aspects of the organization, ensuring implementations follow technical baselines.
• Establish clear transformation milestones and operational metrics to track the migration from legacy infrastructure to modern, consolidated identity ecosystems, ensuring the business sees measurable progress at every phase.
Regulatory Compliance & Governance Engineering
• Architect practical identity solutions that natively satisfy the compliance mandates of a publicly traded utility, including Public Service Commission (PSC) regulations, Sarbanes-Oxley (SOX), Payment Card Industry Data Security Standards (PCI-DSS), North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards, and Transportation Security Administration (TSA) security directives.
• Partner directly with Compliance, Control Owners, and Technical teams to design access controls and automated evidence-generation workflows that achieve successful, repeatable audit outcomes across multiple frameworks and general IT controls simultaneously.
• Develop identity architectures and unified operational patterns that satisfy multiple overlapping regulatory mandates, eliminating redundant, compliance-specific system silos.
• Implement structured Identity Governance and Administration (IGA) frameworks, focusing on rigorous role-based access control (RBAC), automated joiner-mover-leaver workflows, and separation of duties (SoD) to reinforce general IT controls.
Security Framework & Cloud Integration
• Align the enterprise identity architecture with industry-standard frameworks, mapping identity capabilities directly to the NIST Cybersecurity Framework (NIST CSF) and the CIS Critical Security Controls.
• Drive the organizational adoption of Zero Trust principles, ensuring that identity serves as a practical, technical security perimeter across major cloud provider ecosystems and on-premises environments.
• Architect and secure the identity lifecycle for Artificial Intelligence (AI) agents, large language models (LLMs), and automated programmatic workloads, ensuring these entities are securely governed, authenticated, and authorized with least privilege.
• Implement adaptive governance models to manage the unique data access, API authentication, and runtime behavior challenges introduced by the advancement and integration of enterprise AI technologies.
Cross-Functional Partnership & Leadership
• Partner with business unit leaders, Enterprise Architecture, Infrastructure, and Operational Technology teams to ensure localized technical decisions align with the identity strategy.
• Collaborate closely with Human Resources to optimize the HR Information System (HRIS) as the authoritative source of truth for identity lifecycles, ensuring upstream personnel changes trigger real-time, automated downstream access adjustments.
• Act as a consultative, peer-level advisor to cross-functional teams, identifying areas where decentralized systems deviate from corporate standards and advising leadership on necessary strategy adjustments.
Behavioral Competencies & Team Attributes
We are seeking an individual who balances exceptional technical mastery with strong interpersonal leadership. As an individual contributor tasked with elevating program maturity, you must naturally exhibit the core traits of highly effective team collaboration:
• Organizational Humility: You focus on the success of the enterprise transformation over personal recognition. You willingly listen to feedback from disparate business units and validate their challenges.
• Execution Drive: You possess an internal motivation to deliver results. You take ownership of a complex environment, lean into technical problem-solving, and proactively push through roadblocks to modernize our systems.
• Interpersonal Agility: You understand how your words and actions impact others. You communicate complex identity security concepts clearly to non-technical stakeholders, building strong organizational relationships through empathy and active listening.
Qualifications & Requisite Experience:
Preferred Technical Tool Knowledge
While this role focuses on architecture, deep technical familiarity with industry-standard platform capabilities is required for vendor evaluation, design validation, and low-level pattern creation. Familiarity with the following domains is preferred:
• Identity Governance & Administration (IGA): SailPoint, Saviynt, or equivalent tools.
• Access Management & Federation: Microsoft Entra ID, Okta, Ping Identity, and core protocols (SAML 2.0, OIDC, OAuth 2.0, SCIM).
• Privileged Access Management (PAM): CyberArk, BeyondTrust, or Delinea.
Industry Certifications & Training
Candidates must possess advanced, industry-recognized professional certifications that demonstrate broad cybersecurity and architectural authority, such as:
• Certified Information Systems Security Professional (CISSP)
• Information Systems Security Architecture Professional (CISSP-ISSAP)
• TOGAF (The Open Group Architecture Framework) or SABSA (Sherwood Applied Business Security Architecture)
• Relevant advanced SANS/GIAC certifications (e.g., GDSA, GCPM, GSEC)
• Identity Management Institute credentials, such as Certified Identity and Access Manager (CIAM) or Certified Identity Management Professional (CIMP), are a plus.
*Beware of scams. S3 never asks for money during its onboarding process
Required Skills
Required Languages
🇬🇧 English