Principal Architect - IAM Workforce
United Airlines
Come join us to create what’s next. Let’s define tomorrow, together.
Description
We’re on a path to becoming the best airline in aviation history. Join our Cybersecurity and Digital Risk (CDR) team to help lead the industry in cyber safety, security and resilience. United's CDR team plays a critical role in protecting our operations by enabling secure and resilient systems, managing threats and vulnerabilities, and ensuring swift response and recovery. Our mission is to seamlessly embed cybersecurity and digital risk management into every aspect of our business. We help drive progress and growth through trusted digital solutions, safeguarding assets and empowering our team, all while promoting a cyber-safe and secure environment that supports resilient airline operations.
Job overview and responsibilities
The Principal Architect – Workforce Identity & Access Management will design a modern workforce IAM experience that delivers secure, reliable, scalable, and performant identity platforms and systems. The Principal Architect is a senior level position that works closely with development teams, digital product teams, and other architects across security and business functions to integrate identity security into product and workforce identity lifecycles (for both human and non-human identities) and optimize experiences around risk-based authentication and authorization for our workforce customers.
This technical leader will define, craft, implement, review, advise, and guide implementation of workforce identity architecture and will take a strong hands-on role, working with diverse teams across United as well as with external partners to define and support identity innovation. On any given day, the Principal Architect can be pulled in to evaluate a new tool, contribute to short and long-term strategic Identity roadmaps, or provide guidance across United on IAM relevant standards and frameworks, authentication and authorization protocols, and how to successfully implement these across a range of capabilities.
- Leads design, technical innovation, and documentation of Workforce Identity & Access Management platform architecture and roadmap
- Translates business requirements into technical architecture
- Leads the design, definition and implementation of risk-based authentication and authorization identity security best practices and updating
- Champions Cybersecurity and Digital Risk standards and policies to ensure clarity with technology teams
- Recommends and implements products/services that support workforce identity operational needs and security requirements, considering performance, compliance, and business continuity needs that ensure performant, scalable, highly available, and resilient IAM capabilities
- Promotes and contributes to the continuous improvement of security culture and strategy based on business objectives and security priorities
- Participates in capacity planning, formulating and contributing to Objectives and Key Results
- Serves as a department Subject Matter Expert, and mentors, trains, and coaches junior members of the IAM team
Qualifications
What’s needed to succeed (Minimum Qualifications):
- Bachelor's degree (STEM field preferred)
- 7+ years of experience working with cloud/hybrid-based identity and zero-trust enablement platforms related to ForgeRock, Okta, Ping Identity
- Experience specific to Microsoft Entra and Duo preferred
- Deep expertise in identity management, authentication, authorization, and security architecture, including technologies like SSO, MFA, SAML, OAuth2, OIDC, FIDO, and Zero Trust principles
- Hands-on experience developing enterprise security architecture; Demonstrated ability to build custom IAM tooling for automation, integration, and enhanced capabilities and working with security development lifecycle processes and tools
- Strong collaborator, able to influence and build productive relationships across technical and business teams
- Ability to effectively articulate security and identity concepts to technical and non-technical audiences
- Familiarity with NIST Cybersecurity Framework, PCI and SOX requirements
- Must be legally authorized to work in the United States for any employer without sponsorship
- Successful completion of interview required to meet job qualification
- Reliable, punctual attendance is an essential function of the position
What will help you propel from the pack (Preferred Qualifications):
- Master's degree in computer science, Engineering, or Cybersecurity
- Certifications such as CISM, CISSP, CRISC, CEH
- Minimum of 10 years of experience in related field, including any combination of the following: threat modeling, secure coding, identity management and authentication, security architecture, data science, machine learning, cryptography, system administration and network security, cloud computing, governance risk and compliance
- 10+ years of experience working with an IAM platforms or technology like Oracle Access Manager, AWS IAM, Azure Active Directory, Zscaler
- Demonstrated ability to set technical direction and lead organizations through complex architectural transformations
- Proven experience effectively leveraging AI technologies for identity management, such as ML-based access anomaly detection and generative AI for governance
- Airline Industry experience
- Familiarity with transportation sector specific regulatory and compliance requirements
- Experience in leading/architecting large-scale identity transformation projects
- Security threat modeling and risk assessments
- Experience implementing Zero Trust architecture.
- Experience with large language models for security automation
- Experience leading technical teams and mentoring IAM professionals
- Experience with multi-cloud environments
The base pay range for this role is $137,275.00 to $178,670.00.
The base salary range/hourly rate listed is dependent on job-related, factors such as experience, education, and skills. This position is also eligible for bonus and/or long-term incentive compensation awards.
You may be eligible for the following competitive benefits: medical, dental, vision, life, accident & disability, parental leave, employee assistance program, commuter, paid holidays, paid time off, 401(k) and flight privileges.
United Airlines is an equal opportunity employer. United Airlines recruits, employs, trains, compensates and promotes regardless of race, religion, color, national origin, gender identity, sexual orientation, physical ability, age, veteran status and other protected status as required by applicable law. Equal Opportunity Employer - Minorities/Women/Veterans/Disabled/LGBT.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform crucial job functions. Please contact JobAccommodations@united.com to request accommodation.