HUB International logo

IAM Architect

HUB International

RemoteFull timeMid level$120k – $150kPosted today
Apply with JobAssist

About the role

ABOUT US

At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.

HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions

Job Description

We are seeking an experienced IAM Architect to design, build, and evolve our enterprise Identity and Access Management (IAM) program. This role oversees and drives the IAM architectural standards for authentication, authorization, provisioning, and privileged access across cloud, SaaS, and on-premises environments. You will translate business and security requirements into reference architectures, technical standards, and multi-year roadmaps that support workforce, and privileged identities.

The ideal candidate has deep hands-on experience with modern IAM/IGA platforms (e.g., SailPoint Identity Security Cloud/IdentityNow, Okta, Azure AD/Entra ID, or similar), a strong understanding of Zero Trust principles, and a track record of leading identity initiatives that reduce risk, complexity, and operational cost while improving the end-user experience.

Objectives of this Role

  • Develop and maintain the enterprise IAM framework, including authentication, authorization, provisioning, and privileged access systems.
  • Rationalize identity platforms and standardize integration patterns to reduce complexity, cost, and operational risk.
  • Ensure high availability, resilience, and audit readiness of identity services.
  • Improve onboarding/offboarding (Joiner-Mover-Leaver) efficiency and reduce identity-related security incidents such as credential compromise or orphaned accounts.
  • Serve as the technical leader for IAM initiatives, driving scalable identity architecture and governance standards across cloud and on-prem environments.
  • Ensure identity operations practices provide a sound foundation that utilizes tools and processes for rapid identification of security events to address and mitigate risks.
  • Engage with peers regularly on security operations functions, project status, activities, and achievements.
  • Lead “Continuous Improvement” efforts, in respect to HUB’s information security identity tooling and systems.
  • Lead/Assist in plan, organize, and execute multiple responsibilities to achieve project goals and provide technical leadership to move operational projects to completion.
  • Contribute to security requirements, standards, procedures, and reference architectures to comply with policies and technical standards.

Daily and Monthly Responsibilities

  • Lead the architecture, design, implementation and integration of IAM/IGA solutions (e.g., SailPoint ISC) across enterprise environments.
  • Define IAM architecture standards, governance models, and best practices.
  • Design scalable identity lifecycle processes including Joiner, Mover, and Leaver workflows.
  • Architect integrations with Active Directory, Azure AD/Entra ID, Workday, ServiceNow, LDAP, SAP, cloud platforms, and REST APIs.
  • Maintain all IAM architectural diagrams, as-built documentation, and roadmaps.
  • Lead application onboarding, provisioning, deprovisioning, and access certification initiatives.
  • Provide architecture guidance for compliance, audit readiness, and regulatory requirements (e.g., SOX, HIPAA, GDPR, PCI-DSS).
  • Collaborate with cybersecurity, infrastructure, cloud, and application teams to align IAM strategy with enterprise security goals.
  • Mentor engineers, developers, and analysts on IAM platform best practices and technical standards.
  • Participate in roadmap planning, technical governance, and solution architecture reviews.
  • Support Agile delivery, sprint planning, and technical design workshops.

Skills and Qualifications

  • Bachelor’s degree in technology, Security, or equivalent experience.
  • 7+ years of experience in identity and access management, with at least 3 years in an architecture or technical leadership role.
  • Proven experience designing and implementing enterprise IGA/IAM solutions (e.g., SailPoint ISC/IdentityNow, Saviynt, or similar).
  • Experience with access certifications, provisioning workflows, lifecycle management, and governance controls.
  • Strong understanding of Zero Trust architecture and enterprise security frameworks.
  • Expertise with IGA platforms, Active Directory, EntraID, LDAP, SSO, RBAC, Rest APIs and/or JSON / XML.
  • Expertise with SAML, OIDC, oAuth, and SCIM.
  • Experience integrating IAM platforms with HR systems (e.g., Workday), ITSM tools (e.g., ServiceNow, JIRA), business applications, and cloud platforms (AWS, Azure, GCP).
  • Solid understanding of compliance and audit requirements related to identity and access.
  • Excellent communication skills, with the ability to translate technical concepts for both technical and non-technical stakeholders.
  • Experience mentoring engineers and leading technical governance discussions.
  • Familiarity with Agile delivery methodologies.
  • Knowledge of industry security standards, guidelines, and regulatory/compliance requirements related to information security such as ISO 27001, NIST 800-53, SOC2, PCI, SOX, etc.
  • This position reports into Chicago and is hybrid.
  • Willingness to travel up to 10% of working time.

JOIN OUR TEAM

Do you believe in the power of innovation, collaboration, and transformation? Do you thrive in a supportive and client focused work environment? Are you looking for an opportunity to help build and drive change in a rapidly growing and evolving organization? When you join HUB International , you will be part of a community of learners and doers focused on our Core Values: entrepreneurship, teamwork, integrity, accountability, and service.

The expected salary range for this position is $ 120,000 to $150,000 and will be impacted by factors such as the successful candidate’s skills, experience and working location, as well as the specific position’s business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays. In addition, eligible annual bonuses, equity and commissions may be available for some positions.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at HUB International was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.