Job title: Identity & Access Management Architect
Company: StoneX Group
Job description: OverviewConnecting clients to markets – and talent to opportunityWith 4,300 employees and over 400,000 retail and institutional clients from more than 80 offices spread across five continents, we’re a Fortune-100, Nasdaq-listed provider, connecting clients to the global markets – focusing on innovation, human connection, and providing world-class products and services to all types of investors.At StoneX, we offer you the opportunity to be part of an institutional-grade financial services network that connects companies, organizations, and investors to the global markets ecosystem.As a team member, you’ll benefit from our unique blend of digital platforms, comprehensive clearing and execution services, personalized high-touch support, and deep industry expertise. Elevate your career with us and make a significant impact in the world of global finance.Corporate: Engage in a deep variety of business-critical activities that keep our company running efficiently. From strategic marketing and financial management to human resources and operational oversight, you’ll have the opportunity to optimize processes and implement game-changing policies.ResponsibilitiesPosition Purpose:At StoneX, our information security teams are the guardians of our digital frontiers — defending against cyber threats that aim to infiltrate our systems, compromise customer trust, and cause mayhem. As an Identity & Access Management (IAM) Architect, you will be a key player on our blue team, collaborating with business leaders, tech experts, and your peers to design and implement secure, scalable, and business-friendly identity architecture.On Day 1, we will be looking for you to come in and assess our workforce identity environment through active listening and stakeholder relationship building. After learning about our environment and our vision, we will look to you to help drive our next steps as we build out our identity journey and mature into a zero-trust identity world.Imagine yourself as the architect of trust: your work will empower secure connections while protecting data and privacy. As our IAM Architect, you’ll be more than just an architect — you’ll be a strategic leader and advocate for identity. You will help create technical identity strategies, develop programs and projects, be a consultative identity subject matter expert to those in need, and act as an ambassador for identity, ensuring that identity requirements are balanced against business needs. This role isn’t just about systems and strategies — it’s about people and trust.Primary duties will include:
- Strategic Creation: The IAM Architect is responsible for developing and owning technical strategies that align with StoneX’s Information Security and Identity visions, grounded in a Zero Trust Architecture methodology. In this role, you will create and drive comprehensive strategies for Identity & Access Management (IAM) and Identity Governance & Administration (IGA) to ensure security, scalability, and resilience.
- Collaboration with IT and other departments: Collaboration is central to the IAM Architect’s role, requiring close work with Identity Engineering, IT, legal, compliance, product leadership, and other departments. You will advocate for solutions that balance strong security with user-friendly experiences, proving that usability and security can coexist. Additionally, you will collaborate with various teams to address specific needs and ensure business activities are conducted securely and effectively.
- Organic Security Injection: Ability to understand, highlight, and implement specific security roles and functions that can be shifted onto other areas, including business units, to have them play a better part in security.
- Stakeholder Communication: As a key liaison, you will serve as a consultative subject matter expert to stakeholders across the organization. By explaining complex technical concepts in a clear and accessible way, you will inspire action, build trust, and ensure alignment on customer identity goals. Effective communication with senior management, employees, clients, and external partners will also be essential in keeping everyone informed about the organization’s customer identity posture and progress.
As an Identity & Access Management Architect, a typical week might include the following:
- Spending at least three days in the office, with occasional travel, collaborating with teams and stakeholders, fostering engagement and productivity.
- Developing and refining IAM and Identity Governance & Administration (IGA) technical strategies while conducting industry research to stay ahead of emerging threats and regulatory changes like FCA and GDPR. This includes contributing to the information security architecture roadmap aligned with NIST CSF, CIS Top 20, and global regulatory requirements.
- Mentoring junior engineers or analysts, providing guidance and support on projects and challenges to help them grow professionally.
- Collaborating with identity, application, security, and infrastructure teams to evaluate, design, and implement secure, enterprise-class identity solutions, while contributing to the development and refinement of identity standards and frameworks.
- Engaging proactively with business stakeholders to drive informed identity and risk management decisions, analyzing identity-related requests to identify strategic solutions, and tracking divisional identity metrics.
- Leading or participating in architecture review and design sessions, presenting initiatives to the Architecture Review Team, and managing IAM and IGA projects and change activities.
- Conducting security assessments related to identity architecture, supporting risk mitigation and compliance efforts, and assisting with security incident remediation when necessary.
- Reviewing and enhancing documentation related to identity standards and frameworks, ensuring alignment with business and technology strategies.
- Evaluating ongoing identity requests and requirements to develop enterprise-wide solutions that address root cause issues holistically.
QualificationsTo land this role:
- Approximately 10 years of overall experience in technology, with expertise demonstrated across multiple technology domains. Relevant areas of experience include networking, compute/storage, cloud technologies, endpoint computing, and cybersecurity.
- A bachelor’s degree in computer science, Information Security, Information Assurance, Information Systems, or a related field is preferred. Equivalent experience, certifications, or non-traditional educational paths will also be considered.
- Relevant professional certifications such as CISM, CISSP, or comparable qualifications are a strong asset.
What will make you stand out:
- Five or more years’ experience in:
- Expertise in Identity & Access Management (IAM), including internal and customer/consumer IAM infrastructure, authentication and authorization fundamentals, access control (RBAC and ABAC), and integration services (e.g., AD, LDAP, SCIM). Strong understanding of identity lifecycle management (ILM), federation concepts (SAML, OAuth, OIDC), secure software development practices, credential management, cryptography, and key management.
- Proven experience in identity architecture, including designing, implementing, and continuously improving identity solutions. This includes collaborating with information security teams to ensure alignment with organizational needs and emerging technologies.
- Strong knowledge of security risk management, including identifying and prioritizing risks, determining when to address them, and implementing compensating controls or remediation strategies as needed.
- Skilled in consulting and developing identity best practices and principles, ensuring alignment with business goals, customer expectations, and regulatory requirements.
- Familiarity with identity considerations in cloud computing environments, addressing challenges like data breaches, broken authentication, insider threats, account hijacking, and denial-of-service (DoS) attacks.
- Leadership in providing strategic guidance for enterprise identity initiatives, ensuring adherence to identity fundamentals while supporting business vision and roadmaps effectively and efficiently.
- Ability to communicate complex technical concepts to non-technical stakeholders and executives, effectively addressing potential threats, mitigating risks, and implementing controls.
Working Environment:
- Hybrid
#LI-Hybrid #LI-DK1Hiring Salary Range $145,000-$195,000 salary to be determined by the education, experience, knowledge, skills and abilities of the applicant, internal equity and alignment with market data.) Subject to business performance and recommendations of management, this role may be eligible to participate in an incentive compensation plan. This compensation package, in addition to a full range of medical, financial, and/or other benefits, dependent on the position, is offered.
Expected salary: $145000 – 195000 per year
Location: Kansas City, MO
Job date: Thu, 17 Apr 2025 03:09:51 GMT
Apply for the job now!