Job Description
The Solution Architect – Identity & Access Management (IAM) acts as the design authority for secure, scalable and integrated identity services across HOYA's global IT and OT environments. Reporting to the IAM Product Owner, the role translates business, security, regulatory and operational requirements into implementable solution architectures spanning Identity Governance & Administration (IGA), Privileged Access Management (PAM), Access Management and Directory Services (AM/DS), Microsoft Entra ID, Active Directory and OT Identity. The architect owns and maintains IAM reference architectures, design patterns and architectural decisions, and ensures solutions remain aligned with HOYA's target-state IAM architecture, operating model, enterprise architecture standards and security principles. The role provides end-to-end architectural oversight from strategy and roadmap through detailed design, implementation, transition to operations and continuous improvement.
Roles & Responsibilities
Role Scope
•Act as the IAM Design Authority across IGA, PAM, AM/DS, federation and SSO, MFA, Conditional Access, directory services, non-human identities and OT IAM.
•Provide architecture coverage across the full solution lifecycle, including discovery, requirements, options assessment, high-level and detailed design, implementation assurance, acceptance, build-to-run transition and operational change.
•Operate across HOYA Group Digital, divisions, regions and sites, balancing global standards and centralized governance with controlled federated execution and approved local requirements.
•Cover human and non-human identities across workforce, contractors, partners, privileged administrators, service accounts, workloads, applications, devices, OT engineers and third-party vendors.
IAM Architecture, Strategy and Roadmap
•Develop, own and maintain the enterprise IAM reference architecture, target-state blueprint, domain architectures, reusable patterns and technology standards.
•Translate business strategy, security objectives and IAM roadmap priorities into coherent solution architecture and sequenced implementation direction.
Solution Design and Requirements Transformation
•Lead the transformation of business, functional, non-functional, regulatory and operational requirements into high-level and detailed IAM solution designs.
• Define end-to-end solution components, integrations, data flows, trust boundaries, identity sources, provisioning patterns, authentication and authorization controls, resilience, monitoring and support requirements
Identity Governance & Administration Architecture
•Define architecture for authoritative-source integration, identity warehouse, automated joiner-mover-leaver processes, birthright access, self-service requests, approvals, provisioning, reconciliation and deprovisioning.
Privileged Access and Non-Human Identity Architecture
•Define PAM architecture for account discovery and onboarding, credential vaulting and rotation, session isolation, recording, monitoring, privileged access certification and threat analytics.
Access Management and Directory Services Architecture
•Define secure authentication, federation, SSO, MFA, passwordless, Conditional Access, session and token management, B2B access and application proxy patterns using Microsoft Entra ID.
•Guide the transition from fragmented on-premises directories toward the approved interim consolidated Active Directory model and long-term Entra ID-driven target state.
OT Identity and Secure Remote Access Architecture
•Define IAM and directory architectures for manufacturing and OT environments in alignment with Purdue segmentation and HOYA's IT/OT separation principles.
•Design division-level OT directory, DMZ, RWDC/RODC, IGA staging and resilient site authentication patterns, including compensating controls for disconnected, legacy or constrained environments.
Integration, Interoperability and Technology Evaluation
•Assess integration feasibility across cloud, SaaS, on-premises and OT platforms and define standards-based patterns using SAML, OIDC, OAuth, SCIM, LDAP, Kerberos, APIs, X.509 and approved OT protocols.
•Evaluate IAM products, services and emerging technologies against architecture principles, capability requirements, operational fit, vendor viability, scalability, security and total lifecycle impact.
Architecture Governance and Design Assurance
•Chair or participate in IAM architecture reviews and represent IAM in the Global Enterprise Architecture & Review Board and other design governance forums.
• Review and approve designs produced by projects, engineering teams, suppliers and implementation partners before build and deployment
Service Architecture and Continuous Improvement
•Own IAM Service Architecture and Catalogue Management, ensuring service definitions, boundaries, dependencies and underpinning platforms are aligned with the target operating model.
Stakeholder Management and Communication
•Partner with the IAM Product Owner, Enterprise Architecture, CISO organization, Security Operations, Risk and Compliance, Group Digital, divisions, application owners and OT stakeholders.
•Communicate complex IAM architecture, options, risks and decisions clearly to technical and non-technical audiences, including leadership and governance boards.
•Facilitate architecture workshops, design reviews and decision forums, building alignment across global and divisional stakeholders.
•Manage constructive technical engagement with strategic vendors, service providers and implementation partners while retaining HOYA design authority.
Education/Training Qualifications:
•Bachelor's degree in Computer Science or a related field.
•Certifications preferred: TOGAF, CISSP, CISM, Azure/AWS IAM specializations.
Experience:
•5-8 years of experience in solution architecture with a strong focus on IAM.
•Proven track record in designing and delivering complex IAM solutions.
•Experience with at least one full delivery lifecycle of IAM products like Saviynt, Sailpoint, Idira, BeyondTrust, Delinea
