To Apply for this Job Click Here
Title: Senior Domain Architect – IAM
Location: Remote
Type: Contract to Hire
Overview
A Senior Domain Architect – IAM is a subject matter expert who leads the design and governance of the enterprise identity architecture, serves as design authority across platform teams, and coaches and mentors architects and platform administrators. This role collaborates with cross-functional teams to ensure the identity estate aligns with business objectives and complies with healthcare industry standards.
Responsibilities:
Domain Architecture Design:
• Lead the design and development of the enterprise identity architecture, including platform boundaries across request intake, fulfillment, governance, and enforcement.
• Own identity reference architecture, technical standards, and decision records.
Strategic Planning & Roadmap Development:
• Develop and maintain the identity domain technology roadmap in alignment with business strategies.
• Frame build/buy/retain trade-offs and estate rationalization as technical cases for executive decision.
Solution Implementation & Integration:
• Oversee implementation of identity solutions by platform teams and contracted engineering resources; accept work against specifications.
• Provide guidance and support throughout the solution development lifecycle.
Stakeholder Collaboration & Communication:
• Serve as design authority across platform teams; maintain the feedback loop from operations into architecture.
• Communicate complex technical concepts to non-technical stakeholders.
Governance & Compliance:
• Propose identity standards for CISO ratification; define the approved patterns underpinning the risk-exception process.
• Ensure identity solutions adhere to healthcare regulations and standards, including HIPAA.
Mentorship & Leadership:
• Provide technical leadership and mentorship to junior architects and platform administrators.
• Technically vet identity engineering staff, consultants, and statements of work.
Required Skills
• Bachelor’s degree in Computer Science, Information Technology, or a related field.
• 10+ years of experience in IT architecture or identity domain experience, with a focus on healthcare systems.
• Proven experience designing and implementing enterprise identity architectures.
• Deep working knowledge of at least four identity platforms (Entra ID, SailPoint, Active Directory, ServiceNow identity flows, SAML/OIDC federation) sufficient to review designs and diagnose complex cross-platform failures.
• Demonstrated ownership of platform-boundary and estate-rationalization decisions across an HCM/ITSM/directory/IGA estate.
• Proven experience leading role-mining / birthright-access design at enterprise scale.
• Proficiency in architecture frameworks such as TOGAF or C4 Model.
• Experience directing contracted engineering resources against architecture specifications.
• Knowledge of healthcare data privacy and security regulations.
End client ecosystem
• Deep Entra ID design capability (dynamic groups, access packages, access reviews, PIM, conditional access) including Duo as the MFA layer.
• SailPoint working proficiency: connector and aggregation model, provisioning plans, role and entitlement structure; defines its scope (deep application-entitlement governance) and its integration with ServiceNow and Entra ID.
• ServiceNow + Integration Hub fulfillment design: specifying flows built by ServiceNow developers.
• Workday-driven lifecycle design covering employees, contractors, and non-employee providers; hybrid AD/Entra group-mastering decisions for LDAP-bound applications.
• Epic security build preparation strongly preferred: templates/subtemplates, EMP provisioning, and the supporting role model and group hygiene.
• Stabilization phase (time-boxed): serves as Tier 2/3 escalation, maintains console currency, and converts recurring escalations into runbooks and automation.”
• Estate rationalization leadership: the technical case for SailPoint scope/keep decisions at renewal; ServiceNow-vs-Entra governance boundary ownership.
• External identity (Entra B2B) pattern definition, beginning with vendor remote-support access.
• Vendor-facing technical leadership across Microsoft, SailPoint, and ServiceNow.
Certification
• One of: Microsoft SC-300, SailPoint certification (IdentityNow/IIQ), or IDPro CIDPRO required.
• TOGAF Certification required within 1 year of hire.
• CISSP preferred.
• Additional certifications from the required list preferred.
• AWS Certified Security – Specialty preferred.
Title: Senior Domain Architect – IAM
Location: Remote
Type: Contract to Hire
Overview
A Senior Domain Architect – IAM is a subject matter expert who leads the design and governance of the enterprise identity architecture, serves as design authority across platform teams, and coaches and mentors architects and platform administrators. This role collaborates with cross-functional teams to ensure the identity estate aligns with business objectives and complies with healthcare industry standards.
Responsibilities:
Domain Architecture Design:
• Lead the design and development of the enterprise identity architecture, including platform boundaries across request intake, fulfillment, governance, and enforcement.
• Own identity reference architecture, technical standards, and decision records.
Strategic Planning & Roadmap Development:
• Develop and maintain the identity domain technology roadmap in alignment with business strategies.
• Frame build/buy/retain trade-offs and estate rationalization as technical cases for executive decision.
Solution Implementation & Integration:
• Oversee implementation of identity solutions by platform teams and contracted engineering resources; accept work against specifications.
• Provide guidance and support throughout the solution development lifecycle.
Stakeholder Collaboration & Communication:
• Serve as design authority across platform teams; maintain the feedback loop from operations into architecture.
• Communicate complex technical concepts to non-technical stakeholders.
Governance & Compliance:
• Propose identity standards for CISO ratification; define the approved patterns underpinning the risk-exception process.
• Ensure identity solutions adhere to healthcare regulations and standards, including HIPAA.
Mentorship & Leadership:
• Provide technical leadership and mentorship to junior architects and platform administrators.
• Technically vet identity engineering staff, consultants, and statements of work.
Required Skills
• Bachelor’s degree in Computer Science, Information Technology, or a related field.
• 10+ years of experience in IT architecture or identity domain experience, with a focus on healthcare systems.
• Proven experience designing and implementing enterprise identity architectures.
• Deep working knowledge of at least four identity platforms (Entra ID, SailPoint, Active Directory, ServiceNow identity flows, SAML/OIDC federation) sufficient to review designs and diagnose complex cross-platform failures.
• Demonstrated ownership of platform-boundary and estate-rationalization decisions across an HCM/ITSM/directory/IGA estate.
• Proven experience leading role-mining / birthright-access design at enterprise scale.
• Proficiency in architecture frameworks such as TOGAF or C4 Model.
• Experience directing contracted engineering resources against architecture specifications.
• Knowledge of healthcare data privacy and security regulations.
End client ecosystem
• Deep Entra ID design capability (dynamic groups, access packages, access reviews, PIM, conditional access) including Duo as the MFA layer.
• SailPoint working proficiency: connector and aggregation model, provisioning plans, role and entitlement structure; defines its scope (deep application-entitlement governance) and its integration with ServiceNow and Entra ID.
• ServiceNow + Integration Hub fulfillment design: specifying flows built by ServiceNow developers.
• Workday-driven lifecycle design covering employees, contractors, and non-employee providers; hybrid AD/Entra group-mastering decisions for LDAP-bound applications.
• Epic security build preparation strongly preferred: templates/subtemplates, EMP provisioning, and the supporting role model and group hygiene.
• Stabilization phase (time-boxed): serves as Tier 2/3 escalation, maintains console currency, and converts recurring escalations into runbooks and automation.”
• Estate rationalization leadership: the technical case for SailPoint scope/keep decisions at renewal; ServiceNow-vs-Entra governance boundary ownership.
• External identity (Entra B2B) pattern definition, beginning with vendor remote-support access.
• Vendor-facing technical leadership across Microsoft, SailPoint, and ServiceNow.
Certification
• One of: Microsoft SC-300, SailPoint certification (IdentityNow/IIQ), or IDPro CIDPRO required.
• TOGAF Certification required within 1 year of hire.
• CISSP preferred.
• Additional certifications from the required list preferred.
• AWS Certified Security – Specialty preferred.
To Apply for this Job Click Here
Equal Employment Opportunity Statement
Gravity IT Resources is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other legally protected characteristic. All employment decisions are based on qualifications, merit, and business needs.