IAM Architect

Penn Medicine, University of Pennsylvania Health SystemPhiladelphia, PA
$101,750 - $135,000Onsite

About The Position

The Identity and Access Management (IAM) Architect provides technical leadership for the design, evolution, integration, and support strategy of the University's Identity and Access Management (IAM) services. This position has a strong focus on multifactor authentication, authentication architecture, authorization services, federation, public key infrastructure, SSL/TLS, and related security technologies. The architect collaborates with Information Security, IAM service teams, application owners, vendors, and other ISC stakeholders to develop secure, scalable, usable, and reliable IAM capabilities. This role balances security, usability, privacy, availability, and operational requirements while providing technical direction, architectural documentation, service improvement recommendations, and guidance to technical staff.

Requirements

  • Bachelor's degree and 4 to 6 years of experience or equivalent combination of education and experience is required.
  • Previous experience in the following areas: identity and access management, information security, systems architecture, and/or a related technical field.
  • Experience should include architectural design or senior technical leadership for IAM or security services; strong knowledge of multifactor authentication, authentication and authorization models, federation standards, PKI, SSL/TLS, and secure systems design; and the ability to communicate complex technical decisions to technical and non-technical stakeholders.
  • The successful candidate must be able to operate independently, manage ambiguity, guide others through complex technical problems, and balance security, usability, availability, and operational support needs.

Responsibilities

  • Provide technical direction and support for IAM services, including authentication, authorization, federation, MFA, PKI, SSL/TLS, and related security technologies.
  • Provide senior technical support for multifactor authentication services, including policy design, enrollment and recovery patterns, support strategy, assurance levels, usability, and security improvement initiatives.
  • Design and review complex IAM solutions and integration patterns using standards such as SAML, OAuth, OIDC, certificate-based trust, RBAC, ABAC, and related access management models.
  • Partner with Information Security, IAM operations, application owners, vendors, and campus stakeholders to assess requirements, evaluate risk, and recommend secure and supportable IAM approaches.
  • Establishes and follows architectural standards, design patterns, documentation, and operational best practices to improve IAM reliability, repeatability, transparency, and security.
  • Evaluate emerging IAM and authentication technologies, including passwordless authentication, WebAuthn/FIDO2, CIAM patterns, adaptive or risk-based authentication, and MFA service enhancements.
  • Provide escalation support, mentoring, and technical guidance to engineers and support teams; participate in planning for incidents, service changes, and scheduled maintenance as needed.
  • Other duties and responsibilities as assigned.

Benefits

  • excellent healthcare and tuition benefits for employees and their families
  • generous retirement benefits
  • a wide variety of professional development opportunities
  • supportive work and family benefits
  • a wealth of health and wellness programs and resources
  • Health, Life, and Flexible Spending Accounts
  • Tuition assistance for employee, spouse, and dependent children
  • Generous retirement plans
  • Time Away from Work
  • Long-Term Care Insurance
  • Wellness and Work-life Resources
  • Professional and Personal Development
  • Access to University Resources, cultural and recreational activities
  • Discounts and Special Services
  • Flexible Work Hours
  • Penn Home Ownership Services
  • Adoption Assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service