CIAM Senior Architect Manager, VP
About the role
We are seeking an experienced Consumer / Customer Identity and Access Management (CIAM) Architect to develop patterns for lines of business to onboard to a new CIAM platform. This role involves drafting the architecture of CIAM components across State Street, focusing on omni-channel (Digital, Voice, Paper) standard patterns and aligning current processes with industry-leading practices and standards.
Responsibilities
- Development of CIAM omni-channel (Digital, Voice, Paper) standard patterns, including:
- Registration / Onboarding
- Authentication
- Authorization
- Third-party Service/API Access & Authorization
- Invitation-Based User Registration
- Multi-Branded User Registration & Authentication
- User Access Delegation
- User De-provisioning
- Helpdesk Processes
- Omnichannel Services "Overlay"
- Identification of and recommendations for leading digital experiences to serve as benchmarks for clients' CIAM future state, including emerging digital experience trends.
- Evaluation of current processes against defined industry and leading practices, including:
- NIST Special Publication (SP) 800-63 (Digital Authentication)
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53 (Security and Privacy Controls)
- Development of findings and gaps based on analysis of current processes against industry-leading practices.
Your team
You'll be working in the Customer Identity & Access Management Team, part of Global Cybersecurity (GCS). This role aligns with External Authentication products, providing solutions for clients globally. The team consists of highly skilled technical experts across the globe and offers an opportunity to make a significant positive impact.
Requirements
- 5-7 years of senior-level experience as a CIAM Architect, creating reference and solution architecture (design pattern diagrams).
- Good understanding of CIAM and intimate familiarity with IAM-related protocols such as SAML, SPML, XACML, SCIM, OpenID, and OAuth.
- Strong experience with:
- Directories, SSO, Federation, Delegated administration
- API gateways, SOA services
- App Gateways, App Proxies, Live Chat, Chat Bots, Contact Centers, IVRs, and Web Portals for CIAM
- Good understanding of MFA, PAM, and Risk-Based Authentication.
- Deep technical understanding of IAM solutions across multiple vendors, such as Microsoft and Okta.
- Experience with NIST SP800-63 Digital Authentication Standard.
- Ability to work across teams and accommodate working across different time zones.
Preferred Qualifications
- ForgeRock and/or AWS certifications (e.g., Identity Security Engineer).
- Business outcomes mindset.
- Excellent interpersonal communication skills with strong spoken and written English.
- Collaborative team worker.
Pay
Salary Range: $125,000 - $226,250 Annual. The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location, the applicable range could differ.
Benefits
- Retirement savings plan (401K) with company match.
- Insurance coverage including:
- Basic life, medical, dental, and vision.
- Long-term disability and other optional additional coverages.
- Paid-time off including vacation, sick leave, short-term disability, and family care responsibilities.
- Access to Employee Assistance Program.
- Incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans).
- Eligibility for certain tax-advantaged savings plans.
- Paid volunteer days.
- Vibrant employee networks that keep you connected to what matters most.