IAM Architect

The Voleon GroupBerkeley, CA

About The Position

Voleon is a technology company that applies state-of-the-art machine learning techniques to real-world problems in finance. For more than a decade, they have led their industry and worked at the frontier of applying machine learning to investment management, becoming a multibillion-dollar asset manager with ambitious goals. The IAM Architect will define and execute the identity and access management strategy across Voleon's hybrid infrastructure. Reporting directly to the CISO, this role involves designing and implementing modern identity solutions to protect critical intellectual property while enabling research, engineering, and operations teams to move quickly. Initially working as a senior individual contributor, the architect will design solutions across on-premise Linux environments, Kubernetes clusters, Windows systems, cloud identity providers, and public cloud platforms. As the IAM program matures, the architect will build and lead a team to scale identity management capabilities, establishing credibility with senior technical leaders and transforming identity management by focusing on high-risk areas while being mindful of production requirements.

Requirements

  • 8+ years of experience in identity and access management, security engineering, or infrastructure engineering with focus on authentication/authorization
  • Deep expertise in hybrid identity architectures bridging on-premise (LDAP, FreeIPA, Active Directory) and cloud identity platforms (AWS IAM, Azure AD/Entra, Google Workspace)
  • Strong understanding of modern authentication protocols: OIDC, SAML, OAuth2, LDAP, Kerberos
  • Hands-on experience implementing identity solutions in Linux-heavy environments with POSIX requirements
  • Experience with cloud IAM platforms (AWS IAM / Identity Center, Azure AD, GCP IAM) including roles, policies, federation, and service accounts
  • Knowledge of privileged access management (PAM) tools and patterns (CyberArk, HashiCorp Vault, AWS Secrets Manager, or similar)
  • Understanding of zero-trust architecture principles and implementation patterns
  • Demonstrated ability to balance security requirements with operational workflows and production stability
  • Proven track record working with senior technical leaders and building organizational trust
  • Strong communication skills to explain complex identity concepts to both technical and non-technical stakeholders
  • Experience or strong interest in building and leading technical teams

Nice To Haves

  • Experience with Kubernetes service account management and pod identity patterns
  • Familiarity with infrastructure-as-code (Terraform, Ansible) for identity provisioning
  • Experience implementing SCIM for automated user lifecycle management
  • Background in financial services, hedge funds, or high-security research environments
  • Experience with compliance frameworks (SOC 2, ISO 27001) as they relate to identity
  • Certifications such as CISSP, CCSP, or vendor-specific identity certifications
  • Bachelor's or Master's degree in Computer Science, Information Security, or related field

Responsibilities

  • Design and implement IAM strategy across hybrid infrastructure - Linux, Kubernetes, Windows, AWS, Azure, and cloud identity providers
  • Architect identity solutions that bridge POSIX-based authentication with modern cloud platforms (OIDC, SAML, federation), migrating from legacy models
  • Implement privileged access management - just-in-time access, least privilege, periodic reviews, and accountability for shared service accounts
  • Extend zero-trust capabilities beyond current SASE remote access to broader infrastructure
  • Partner cross-functionally with Security Engineering, Infrastructure, DevOps, and Corp IT to integrate identity controls without disrupting production
  • Define the IAM roadmap "," prioritize high-risk areas, translate business requirements into technical solutions, and establish credibility with senior engineering and research leaders
  • Build the IAM team - hire, mentor, and lead IAM engineers as the program scales

Benefits

  • highly competitive compensation and benefits packages
  • technology talks by our experts
  • a beautiful modern office
  • catered lunches
  • medical, dental and vision coverage
  • life and AD&D insurance
  • 20 days of paid time off
  • 9 sick days
  • a 401(k) plan with a company match
  • $15,000 if your referred candidate is successfully hired and employed by The Voleon Group (Referral Bonus Program)

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Senior

Education Level

No Education Listed

Number of Employees

101-250 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service