IAM Architect
Voleon is a technology company that applies state-of-the-art machine learning techniques to real-world problems in finance. For more than a decade, we have led our industry and worked at the frontier of applying machine learning to investment management. We have become a multibillion-dollar asset manager, and we have ambitious goals for the future.
In addition to our enriching and collegial working environment, we offer highly competitive compensation and benefits packages, technology talks by our experts, a beautiful modern office, catered lunches, and more.
As an IAM Architect, you will define and execute our identity and access management strategy across our hybrid infrastructure. Reporting directly to the CISO, you will be responsible for designing and implementing modern identity solutions that protect our critical intellectual property while enabling our research, engineering, and operations teams to move quickly. Initially working as a senior individual contributor, you will architect solutions across on-premise Linux environments, Kubernetes clusters, Windows systems, cloud identity providers, and public cloud platforms. As our IAM program matures, you will build and lead a team to scale our identity management capabilities. This role is a means to make a difference: you will establish credibility with senior technical leaders and transform identity management by focusing on high-risk areas while being mindful of production requirements.
Responsibilities
Design and implement IAM strategy across hybrid infrastructure - Linux, Kubernetes, Windows, AWS, Azure, and cloud identity providers
Architect identity solutions that bridge POSIX-based authentication with modern cloud platforms (OIDC, SAML, federation), migrating from legacy models
Implement privileged access management - just-in-time access, least privilege, periodic reviews, and accountability for shared service accounts
Extend zero-trust capabilities beyond current SASE remote access to broader infrastructure
Partner cross-functionally with Security Engineering, Infrastructure, DevOps, and Corp IT to integrate identity controls without disrupting production
Define the IAM roadmap — prioritize high-risk areas, translate business requirements into technical solutions, and establish credibility with senior engineering and research leaders
Build the IAM team - hire, mentor, and lead IAM engineers as the program scales
Requirements
8+ years of experience in identity and access management, security engineering, or infrastructure engineering with focus on authentication/authorization
Deep expertise in hybrid identity architectures bridging on-premise (LDAP, FreeIPA, Active Directory) and cloud identity platforms (AWS IAM, Azure AD/Entra, Google Workspace)
Strong understanding of modern authentication protocols: OIDC, SAML, OAuth2, LDAP, Kerberos
Hands-on experience implementing identity solutions in Linux-heavy environments with POSIX requirements
Experience with cloud IAM platforms (AWS IAM / Identity Center, Azure AD, GCP IAM) including roles, policies, federation, and service accounts
Knowledge of privileged access management (PAM) tools and patterns (CyberArk, HashiCorp Vault, AWS Secrets Manager, or similar)
Understanding of zero-trust architecture principles and implementation patterns
Demonstrated ability to balance security requirements with operational workflows and production stability
Proven track record working with senior technical leaders and building organizational trust
Strong communication skills to explain complex identity concepts to both technical and non-technical stakeholders
Experience or strong interest in building and leading technical teams
Preferred Qualifications
Experience with Kubernetes service account management and pod identity patterns
Familiarity with infrastructure-as-code (Terraform, Ansible) for identity provisioning
Experience implementing SCIM for automated user lifecycle management
Background in financial services, hedge funds, or high-security research environments
Experience with compliance frameworks (SOC 2, ISO 27001) as they relate to identity
Certifications such as CISSP, CCSP, or vendor-specific identity certifications
Bachelor's or Master's degree in Computer Science, Information Security, or related field
The base salary range for this position is $280,000 to $310,000 in the location(s) of this posting. Individual salaries are determined through a variety of factors, including, but not limited to, education, experience, knowledge, skills, and geography. Base salary does not include other forms of total compensation such as bonus compensation and other benefits. Our benefits package includes medical, dental and vision coverage, life and AD&D insurance, 20 days of paid time off, 9 sick days, and a 401(k) plan with a company match.
“Friends of Voleon” Candidate Referral Program
If you have a great candidate in mind for this role and would like to have the potential to earn $15,000 if your referred candidate is successfully hired and employed by The Voleon Group, please use this formto submit your referral. For more details regarding eligibility, terms and conditions please make sure to review the Voleon Referral Bonus Program.
Equal Opportunity Employer
The Voleon Group is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law.
We may use artificial intelligence (AI) tools to support parts of the hiring process. These tools assist our recruitment team but do not replace human judgement. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Recommended Jobs
Child Care Center Assistant
Description The Semel Institute for Neuroscience and Human Behavior is seeking to hire a Child Care Center Assistant to join the Department of Psychiatry. You will assist Program Nurses with unit …
Travel Registered Nurse NICU Job
Job Overview TLC Nursing Associates, Inc. is seeking an experienced RN – NICU for travel assignments . This role involves providing critical care to premature and ill newborns , collaborati…
Production Lead 1st Shift
Connect Staffing is hiring a Production Lead for the Press Department at an aluminum forging manufacturer in Santa Ana, CA. This is a temp-to-hire position paying $21–$25/hr with approximately 8 hour…
Relationship Manager - EGP (FP)
Merrill Wealth Management is a leading provider of comprehensive wealth management and investment products and services for individuals, companies, and institutions. Merrill Wealth Management i…
Director of Engineering
Director of Engineering Location: Onsite – Sunnyvale, CA Salary Range: Up to $120,000 (depending on experience) About M Social Sunnyvale At M Social Sunnyvale , we don’t just host g…
Postdoctoral Researcher
Lab Overview Dr. Lisa Ellerby's laboratory at the Buck Institute for Research on Aging investigates the molecular mechanisms underlying age-related neurodegenerative diseases and develops novel …
Caregiver for Mon to Fri Early Morning
Hourly Pay Rate: $20 - $23 per hour Are you ready to make a real difference while working with a team that truly values you? At Cheer Home Care, we don’t just offer competitive pay — we care about…
Porter
INDIAN PREFERENCE POLICY: Preference in filling vacancies is given to qualified Indian candidates in accordance with the Indian Preference Act of 1934 (Title 25, USC. Section 472) POSITION: PORTER …
Production Lead 2nd Shift
Connect Staffing is hiring a Production Lead for an aluminum forging manufacturer in Santa Ana, CA. This is a temp-to-hire second-shift position paying $20–$25/hr, with approximately 8 hours of overt…
HVAC Preconstruction Manager / Design/Engineer
HVAC Preconstruction Manager / Design/Engineer – Orange County, CA Responsibilities: Review all contract project requirements Ensure client satisfaction in early phase of upcoming projects …