remote

Salary
Posted
Jul 15, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior contract role focused on designing and leading the build-out of a centralized, next-generation authentication platform intended to replace a decade-old legacy identity system at a large financial services enterprise. Day-to-day work spans defining target-state architecture, guiding credential consolidation across business lines, advising on a vendor-agnostic identity abstraction layer, and mentoring engineering teams. Best suited to a seasoned IAM architect with Fortune 150-scale experience across protocols such as OAuth 2.0, OIDC, SAML, and FIDO2.

Senior level · 12+ years · Remote · Contract

Must have (7)
OAuth 2.0OIDCSAML 2.0FIDO2 or WebauthnLDAP or Active DirectoryPing Identity, Transmit Security, Forgerock, Okta, Sailpoint or CyberarkAPI security
Nice to have (2)
CISSP, Ciam or Ping Certified ArchitectSOX, Pci Dss or Ffiec

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
LDAP50%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (10)

The role is titled 'IAM Solutions Architect' with no seniority level in the title, but the 12+ years requirement and Fortune 150 / global enterprise scale scope clearly support a Senior classification. The scope does not rise to Staff or Principal — it is a single-program technical lead, not an org-wide authority.

SOC classification is a judgement call: IAM architecture sits at the intersection of security (15-1212) and broader systems/solutions architecture (15-1299). The primary day-to-day work — designing authentication platforms, evaluating identity protocols, and setting security standards — aligns most closely with Information Security Analysts (15-1212), with 15-1299 as a reasonable runner-up.

The enterprise identity platform requirement lists Transmit Security, Ping Identity, ForgeRock, Okta, SailPoint, and CyberArk as interchangeable options ('two or more … or equivalent'). These are captured as alternatives on a single skill; the JD gates on depth in at least two, but the specific tools are interchangeable.

FIDO2 and WebAuthn are treated as a single skill with WebAuthn as an alternative, as they are two names for the same standard/protocol family.

LDAP and Active Directory are listed together in the JD as a paired protocol/directory standard; captured as one skill with Active Directory as an alternative.

Transmit Security (hands-on, platform-specific) appears only under Preferred Qualifications, as does passkey/FIDO2 at scale — both marked preferred accordingly.

No compensation figures are stated in the posting.

The role is an independent contractor engagement; no sponsorship is offered and US work authorization is required.

Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.

This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗