Position Summary
The
Senior Solution Architect – Access Management & Data Privacy
will lead the modernization and integration of enterprise-level Access Management and Data Privacy programs. This role focuses on transitioning from legacy, manual processes to automated, cloud-based platforms supporting enhanced security, regulatory compliance, and operational efficiency. The incumbent will design and implement future-state architectures leveraging tools such as
PlainID v5
,
OneTrust Data Scanning
,
SailPoint
, and
Azure Entra
, ensuring scalable governance, automation, and data protection across systems.
Key Responsibilities
- Solution Architecture, Design & Implementation
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Design and implement future-state architectures for modern Access Management and Data Privacy workflows.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Define and implement policy governance, identity lifecycle management, and compliance reporting workflows.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Architect and maintain platform integrations across systems such as SailPoint, Salesforce, Collibra, and Azure Entra.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Translate business requirements into scalable, secure, and auditable technical solutions.
- Platform Modernization & Migration
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Lead migration of PlainID from on-premises (v4) to hybrid cloud (v5).
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Transition Data Privacy scanning processes from Informatica DPM to OneTrust Data Scanning Module.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Ensure high availability (HA), disaster recovery (DR) readiness, and platform resilience.
- Production Support & Maintenance
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Provide L3-level production support for Access Management and Data Privacy platforms.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Manage and enhance authorization reference databases, role-based APIs, and integrations.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Monitor key performance indicators (KPIs) and resolve technical or operational bottlenecks.
- Data Privacy & Governance Enhancements
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Expand the use of OneTrust as a unified repository for sensitive data classification and metadata.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Enable automated scanning and classification for both structured and unstructured data sources.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Integrate privacy controls into organizational data governance tools and practices.
- Access Management Integrations & Reporting
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Develop and maintain centralized Access Management dashboards using Power BI and IFC-approved tools.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Standardize Access and Privacy Reporting frameworks for visibility, auditability, and compliance.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Onboard enterprise applications to SailPoint and Azure AD for centralized governance.
- Process & Workflow Modernization
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Automate Access Recertification cycles and entitlement reviews.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Implement Privacy by Design (PbD) and Access by Design (AbD) frameworks.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Deploy AI and machine learning-based risk detection mechanisms for access behavior analytics.
- Governance, Compliance & Strategy
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Develop and maintain governance frameworks, RACI matrices, and workflow documentation.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Provide strategic advisory insights, gap assessments, and modernization roadmaps.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Ensure full alignment with IFC security policies and global regulatory requirements (GDPR, ISO 27001).
- Documentation & DevOps Enablement
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Establish CI/CD pipelines to streamline deployments, enhancements, and version management.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Maintain detailed technical documentation, architecture diagrams, and operational procedures.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Collaborate across development and operations teams to ensure continuous improvement.
Technical Expertise
Skills & Experience Required
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Strong hands-on experience in Azure cloud services and hybrid identity architectures.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Proven expertise in Access Management, Identity Governance (IGA), and Data Privacy frameworks.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Proficiency with PlainID, SailPoint, Azure Entra (AD), and OneTrust platforms.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Deep understanding of data classification, privacy scanning, and governance workflows.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Familiarity with automation scripts, REST APIs, and DevOps tools (CI/CD pipelines).
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Experience implementing AI/ML-driven solutions for identity or privacy monitoring.
Functional Competencies
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Strong command over policy enforcement models, role-based access control (RBAC), and attribute-based access control (ABAC).
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Excellent understanding of data security, compliance, and risk management principles.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0">
Soft Skills
Experience defining
business requirements, technical documentation
, and
governance standards
.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Strong analytical and problem-solving ability with a focus on results delivery.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Excellent interpersonal, communication, and stakeholder management skills.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Ability to lead cross-functional teams and work in agile, collaborative environments.
Qualifications
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> 10+ years of relevant experience, including Identity and Access Governance and Data Privacy Program Management.
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0">
Preferred Certifications
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Microsoft Certified: Azure Solutions Architect Expert
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Certified Information Privacy Professional (CIPP)
- p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Certified Identity and Access Manager (CIAM) or SailPoint/PlainID certifications
Skills: sailpoint,data privacy,cipp,azure,identity & access management (iam),ciam,plain id,azure entra,one trust,identity governance