Senior Principal, Enterprise Identity & Access Management Architect

The Cigna GroupBloomfield, ConnecticutOn-siteFull-timeSenior, 5–8 yearsListed 2 hours ago

Apply now

About this role

The Senior Principal Enterprise Identity & Access Management (IAM) Architect leads the strategy, design, and governance of identity and access security across the organization. This role sets the long-term IAM vision and ensures identity solutions support business goals, cybersecurity standards, risk management, and regulatory requirements. This senior technical leader serves as a trusted advisor to executives and technology leaders. The role leads large IAM modernization efforts across cloud and on-premises environments, including workforce, customer, partner, privileged, and machine identities. The Senior Principal IAM Architect also helps guide technology investments, improve security, support compliance, and prepare the organization for emerging technologies, including AI-enabled security capabilities.

Responsibilities:

- Define and lead the enterprise IAM strategy, architecture, standards, and multi-year roadmap.
- Create standards for identity governance, authentication, authorization, privileged access, and access controls.
- Serve as a senior technical advisor for complex IAM and identity security programs.
- Partner with cybersecurity, technology, risk, compliance, and business leaders to align IAM solutions with business needs.
- Explain complex identity and security risks in clear business terms to support leadership decisions.
- Guide technology investments and recommend IAM platforms and solutions based on business and security needs.
- Establish and maintain IAM policies, security controls, and governance standards.
- Support compliance with requirements such as HIPAA, SOX, GDPR, NIST, ISO, and other cybersecurity standards.
- Lead identity risk assessments and strategies to reduce security risks.
- Strengthen identity governance, role-based access, access reviews, segregation of duties, and privileged access management.
- Lead the evaluation and adoption of new IAM technologies and platforms.
- Advance cloud identity, Zero Trust, passwordless authentication, adaptive access, privileged access management, and AI-enabled security.
- Define identity integration strategies across applications, APIs, cloud services, data platforms, and digital channels.
- Provide technical direction for large IAM implementations, migrations, and transformation programs.
- Guide architecture, engineering, security, and operations teams through complex identity challenges.
- Ensure IAM solutions are secure, reliable, scalable, and able to support future growth.
- Mentor architects, engineers, and technical leaders while encouraging knowledge sharing and continuous learning.
- Provide IAM guidance during mergers, acquisitions, business changes, and technology modernization efforts.

Qualifications:

- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field. Master's degree preferred.
- 12+ years of experience in cybersecurity, identity management, enterprise architecture, or a related area.
- 8+ years of experience leading enterprise IAM architecture, strategy, or large transformation programs.
- Experience leading complex technology initiatives and influencing senior and executive leaders.
- Experience working in large, highly regulated organizations.
- Deep knowledge of IAM, Identity Governance & Administration (IGA), Privileged Access Management (PAM), Customer IAM (CIAM), and Zero Trust.
- Experience with technologies such as CyberArk, Okta, Ping Identity, SailPoint, and Microsoft Entra ID (Azure AD).
- Strong knowledge of SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, LDAP, Kerberos, FIDO2, and modern authentication methods.
- Experience designing identity solutions across AWS, Azure, GCP, hybrid-cloud, and multi-cloud environments.
- Strong knowledge of API security, directory services, identity federation, automation, and enterprise integrations.
- Experience using automation and AI-enabled capabilities to improve identity governance, security, and access processes.
- Experience with PowerShell, Python, and infrastructure-as-code methods.
- Strong communication skills with the ability to explain technical topics to both technical and business leaders.
- Ability to lead through complex business and technology changes and build agreement across teams.

If you will be working at home occasionally or permanently, the internet connection must be obtained through a cable broadband or fiber optic internet service provider with speeds of at least 10Mbps download/5Mbps upload.

For this position, we anticipate offering an annual salary of 174,800 - 291,300 USD / yearly, depending on relevant factors, including experience and geographic location.

This role is also anticipated to be eligible to participate in an annual bonus and long term incentive plan.

At The Cigna Group, you’ll enjoy a comprehensive range of benefits, with a focus on supporting your whole health. Starting on day one of your employment, you’ll be offered several health-related benefits including medical, vision, dental, and well-being and behavioral health programs. We also offer 401(k), company paid life insurance, tuition reimbursement, a minimum of 18 days of paid time off per year, paid holidays, and leaves of absence. For more details on our employee benefits programs, click here .

About The Cigna Group

Doing something meaningful starts with a simple decision, a commitment to changing lives. At The Cigna Group, we’re dedicated to improving the health and vitality of those we serve. Through our divisions Cigna Healthcare and Evernorth Health Services, we are committed to enhancing the lives of our clients, customers and patients. Join us in driving growth and improving lives.

Qualified applicants will be considered without regard to race, color, age, disability, sex, childbirth (including pregnancy) or related medical conditions including but not limited to lactation, sexual orientation, gender identity or expression, veteran or military status, religion, national origin, ancestry, marital or familial status, genetic information, status with regard to public assistance, citizenship status or any other characteristic protected by applicable equal employment opportunity laws.

If you need a reasonable accommodation to complete the online application process, please email [email protected] for assistance.  Please note that this email inbox is dedicated to accommodation requests only and cannot provide application updates or accept resumes.

The Cigna Group has a tobacco-free policy and reserves the right not to hire tobacco/nicotine users in states where that is legally permissible. Candidates in such states who use tobacco/nicotine will not be considered for employment unless they enter a qualifying smoking cessation program prior to the start of their employment. These states include: Alabama, Alaska, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Iowa, Kansas, Maryland, Massachusetts, Michigan, Nebraska, Ohio, Pennsylvania, Texas, Utah, Vermont, and Washington State.

Qualified applicants with criminal histories will be considered for employment in a manner consistent with all federal, state and local ordinances.