← Back to jobs

Senior Manager, IGA Architect, Cyber Technology Consulting

Company
Kroll
Location
United States
Work type
Full Time · Remote
Posted
2026-09-10

Job description

Job Description
The Senior Manager, IGA is a senior technical and client-facing leadership role focused on driving Identity Governance and Administration engagements from strategy through execution, with SailPoint and Saviynt as core platforms of expertise. This role requires the ability to lead technical architecture design sessions directly with clients – translating complex governance, compliance, and identity lifecycle requirements into scalable IGA target-state architectures. While IGA is the primary focus, the ideal candidate also brings working knowledge of adjacent IAM domains, including Privileged Access Management (PAM) and Access Management (SSO/MFA), to design cohesive, end-to-end identity solutions. The successful candidate will serve as a trusted advisor to client stakeholders, architect enterprise-grade IGA solutions, and lead cross-functional delivery teams, while also contributing to business development, proposal development, and practice growth.

Key Responsibilities:

Lead technical architecture design sessions directly with clients, translating business, security, and compliance requirements into scalable IGA target-state architectures.

Architect and oversee end-to-end implementation of Identity Governance and Administration (IGA) solutions using SailPoint and Saviynt as primary platforms.

Design and lead delivery of core IGA capabilities, including identity lifecycle management (Joiner/Mover/Leaver), access certification/attestation campaigns, role-based access control (RBAC) and role mining, Segregation of Duties (SoD) policy design, entitlement management, and access request/approval workflows.

Lead application onboarding strategy for IGA platforms, including source/target connector design, birthright and non-birthright provisioning, and integration with authoritative HR sources

Define and implement IGA governance frameworks, including policy design, audit and compliance reporting, and global configuration/data segmentation best practices.

Working knowledge of adjacent IAM domains – Privileged Access Management (PAM, e.g., CyberArk, Delinea) and Access Management (SSO/MFA via Entra ID, Okta, Ping) – to ensure IGA architectures integrate cleanly across the broader identity ecosystem.

Own end-to-end delivery for engagements, managing scope, timelines, technical quality, and client satisfaction.

Serve as the primary technical point of contact for clients, running architecture workshops, discovery sessions, and executive-level readouts.

Develop maturity assessments, governance roadmaps, and target operating models tailored to client environments and industry (e.g., healthcare, higher education, financial services).

Provide technical leadership, mentorship, and career development to IAM engineers, architects, and consultants on the delivery team.

Partner with sales and account teams on business development activities, including solution scoping, proposal/SOW development, and technical presentations for prospective clients.

Advise clients on regulatory and compliance considerations (e.g., SOX, HIPAA, GDPR) as they relate to identity governance controls, certifications, and audits.

Monitor emerging IGA trends and best practices (including AI-driven governance) and champion their adoption across client engagements.

Qualifications:

Bachelor’s degree in Computer Science, Information Security, or a related field.

10+ years of hands-on IAM experience with a strong concentration in Identity Governance and Administration (IGA), including consulting or client-facing delivery, and at least 3-5 years in a technical leadership or architecture role.

Deep, hands-on expertise architecting and implementing SailPoint and Saviynt, including certification campaigns, RBAC/SoD design, connector configuration, and workflow customization.

Strong understanding of identity lifecycle management, entitlement governance, access certification processes, and provisioning/de-provisioning across enterprise applications.

Working knowledge of PAM concepts and platforms (e.g., CyberArk, Delinea, BeyondTrust) and Access Management/SSO technologies (e.g., Entra ID, Okta, Ping) sufficient to architect integrated IAM solutions.

Proven ability to lead technical architecture discussions and design sessions directly with client stakeholders, including CISOs and IT leadership.

Solid understanding of identity protocols and standards, including SAML, OAuth 2.0, OpenID Connect, SCIM, and LDAP.

Experience managing project resources, timelines, and deliverables across multiple concurrent engagements.

Demonstrated experience mentoring and developing technical teams, with strong people leadership skills.

Excellent communication, presentation, and stakeholder management skills, with the ability to translate complex technical concepts for both technical and executive audiences.

Relevant certifications strongly preferred (e.g., CISSP, CISM, SailPoint Certified, Saviynt Certified Professional).

Original source