IAM Architect Job at The Voleon Group, New York, NY

NmZxdWk1elFrd0V4VXN0R3VzWHJEUWpkSHc9PQ==
  • The Voleon Group
  • New York, NY

Job Description

Voleon is a technology company that applies state-of-the-art machine learning techniques to real-world problems in finance. For more than a decade, we have led our industry and worked at the frontier of applying machine learning to investment management. We have become a multibillion-dollar asset manager, and we have ambitious goals for the future. In addition to our enriching and collegial working environment, we offer highly competitive compensation and benefits packages, technology talks by our experts, a beautiful modern office, catered lunches, and more. As an IAM Architect, you will define and execute our identity and access management strategy across our hybrid infrastructure. Reporting directly to the CISO, you will be responsible for designing and implementing modern identity solutions that protect our critical intellectual property while enabling our research, engineering, and operations teams to move quickly. Initially working as a senior individual contributor, you will architect solutions across on-premise Linux environments, Kubernetes clusters, Windows systems, cloud identity providers, and public cloud platforms. As our IAM program matures, you will build and lead a team to scale our identity management capabilities. This role is a means to make a difference: you will establish credibility with senior technical leaders and transform identity management by focusing on high-risk areas while being mindful of production requirements. Responsibilities Design and implement IAM strategy across hybrid infrastructure - Linux, Kubernetes, Windows, AWS, Azure, and cloud identity providers Architect identity solutions that bridge POSIX-based authentication with modern cloud platforms (OIDC, SAML, federation), migrating from legacy models Implement privileged access management - just-in-time access, least privilege, periodic reviews, and accountability for shared service accounts Extend zero-trust capabilities beyond current SASE remote access to broader infrastructure Partner cross-functionally with Security Engineering, Infrastructure, DevOps, and Corp IT to integrate identity controls without disrupting production Define the IAM roadmap — prioritize high-risk areas, translate business requirements into technical solutions, and establish credibility with senior engineering and research leaders Build the IAM team - hire, mentor, and lead IAM engineers as the program scales Requirements 8+ years of experience in identity and access management, security engineering, or infrastructure engineering with focus on authentication/authorization Deep expertise in hybrid identity architectures bridging on-premise (LDAP, FreeIPA, Active Directory) and cloud identity platforms (AWS IAM, Azure AD/Entra, Google Workspace) Strong understanding of modern authentication protocols: OIDC, SAML, OAuth2, LDAP, Kerberos Hands‑on experience implementing identity solutions in Linux-heavy environments with POSIX requirements Experience with cloud IAM platforms (AWS IAM / Identity Center, Azure AD, GCP IAM) including roles, policies, federation, and service accounts Knowledge of privileged access management (PAM) tools and patterns (CyberArk, HashiCorp Vault, AWS Secrets Manager, or similar) Understanding of zero-trust architecture principles and implementation patterns Demonstrated ability to balance security requirements with operational workflows and production stability Proven track record working with senior technical leaders and building organizational trust Strong communication skills to explain complex identity concepts to both technical and non-technical stakeholders Experience or strong interest in building and leading technical teams Preferred Qualifications Experience with Kubernetes service account management and pod identity patterns Familiarity with infrastructure-as-code (Terraform, Ansible) for identity provisioning Experience implementing SCIM for automated user lifecycle management Background in financial services, hedge funds, or high-security research environments Experience with compliance frameworks (SOC 2, ISO 27001) as they relate to identity Certifications such as CISSP, CCSP, or vendor-specific identity certifications Bachelor's or Master's degree in Computer Science, Information Security, or related field Equal Opportunity Employer The Voleon Group is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law. #J-18808-Ljbffr

Job Tags

Work at office, Local area, Remote work

Similar Jobs

Virtual Vantage

Customer Service 1.0 Job at Virtual Vantage

 ...Job DescriptionNow Hiring:Work-from-Home Customer Service Reps - Flexible Schedules !Are you ready toditch the commute and get paid...  ...your home officeFlexible scheduling options - including part-time and eveningsPay range: $12-$15/hr to start + performance bonuses (... 

Sutherland Breezy

Chat Support Specialist Remote Work From Home Job at Sutherland Breezy

 ...customers via online messaging. No phone calls required. Youll help answer questions, resolve...  ...required; paid training provided (call center or customer service experience is a plus)...  ...across U.S. time zones (weekend/evening availability is a plus). Sutherland Breezy... 

Laurel Dental Office

Sterilization Technician Job at Laurel Dental Office

 ...learner- looking to grow within the healthcare or dental field - punctual and highly responsible IDEAL opportunity for college students/grads looking to go into dental school. Pay is $16-17/hr. Please apply if this is you! Selected applicants will receive... 

JLL

Hybrid Senior Occupancy Planner - Space Strategy & Analytics Job at JLL

 ...in San Francisco, California. In this role, you will develop innovative space solutions and manage occupancy data. The ideal candidate has 5-7 years of experience in strategic occupancy planning and a relevant Bachelor's degree. Proficiency in Excel and CAFM software... 

Essentia Health

Registered Nurse (RN) Family Birthplace Job at Essentia Health

 ...Job Description: Become part of Essentias accomplished team as a Registered Nurse (RN) in Brainerd and Baxter, Minnesota, where 465 lakes provide endless options for water sports and recreation. These cities, 125 miles north of Minneapolis, are at the heart of the...