Security Architect
The Security Architect will own and continuously develop the group-wide Identity and Access Management strategy, target architecture, standards, and roadmap. This role acts as the main technical authority and escalation point for all IAM-related questions and architectural decisions.
The Security Architect is responsible for the technical architecture and security development of JumpCloud as the central Identity Provider across the business group. This includes designing and maintaining integrations between JumpCloud, cloud platforms, infrastructure systems, business applications, and internal services.
- Own and continuously develop the group-wide Identity and Access Management strategy, target architecture, standards, and roadmap.
- Act as the main technical authority and escalation point for all IAM-related questions and architectural decisions.
- Own the technical architecture and security development of JumpCloud as the central Identity Provider across the business group.
- Design and maintain integrations between JumpCloud, cloud platforms, infrastructure systems, business applications, and internal services.
- Define standards for SSO, MFA, federation, identity lifecycle management, and authentication assurance.
- Improve Joiner, Mover, and Leaver processes together with IT, HR, and Access Management teams.
- Define and govern access architecture for AWS, GCP, OpenStack, Kubernetes, Linux systems, databases, and internal infrastructure components.
- Establish secure access models for developers, DevOps engineers, SRE, infrastructure administrators, support teams, contractors, and third parties.
- Ensure that accounts, groups, roles, policies, and permissions comply with least privilege and segregation of duties principles.
- Define standard role models and access profiles for technical and business functions.
- Own the access architecture for Cloudflare Zero Trust and access to internal applications, administrative interfaces, and infrastructure resources.
- Develop Zero Trust access policies based on identity, device trust, risk level, resource sensitivity, and business need.
- Define secure privileged access standards, including separate administrative accounts, time-limited access, maker-checker approval workflows, and emergency access.
- Develop Just-in-Time and Just-Enough-Access capabilities where technically feasible.
- Own the group-wide strategy and governance model for non-human identities.
- Extend identity governance to AI agents and LLM-based tools, including authentication, scoped permissions, and access control for agent-to-system and agent-to-tool interactions.
- Define standards for service accounts, machine identities, API credentials, workload identities, CI/CD identities, automation accounts, and cloud service accounts.
- Ensure that non-human identities have documented owners, justified permissions, secure authentication methods, monitoring, rotation, and decommissioning processes.
- Reduce the use of static credentials, long-lived access keys, shared accounts, and unmanaged service accounts.
- Promote workload identity federation, short-lived credentials, and centrally managed secrets.
- Support the Access Management team with complex access requests, technical investigations, role design, and escalations.
- Establish periodic access reviews for critical systems, privileged roles, service accounts, and high-risk permissions.
- Identify and coordinate remediation of excessive, dormant, orphaned, conflicting, or unauthorized access.
- Define logging and monitoring requirements for authentication, authorization, privileged activity, and identity changes.
- Ensure that relevant IAM events are available to central security monitoring systems.
- Support investigations of identity-related incidents, suspicious authentication, privilege escalation, and unauthorized access.
- Promote automation of provisioning, deprovisioning, access assignment, access review, and permission analysis.
- Maintain IAM architecture diagrams, technical standards, identity flows, access models, procedures, and implementation guidelines.
- Review IAM-related designs and changes for new systems, cloud environments, infrastructure components, and business initiatives.
- 5+ years designing and implementing IAM solutions in complex, multi-entity environments (required)
- Hands-on experience with enterprise Identity Providers and directory services (required)
- JumpCloud experience (preferred)
- Strong knowledge of authentication and authorization models (SSO, MFA, RBAC, ABAC, least privilege, segregation of duties, privileged access) and protocols (SAML 2.0, OAuth 2.0, OpenID Connect, SCIM, LDAP) (required)
- Experience with IAM in AWS and GCP (roles, policies, service accounts, cross-account access) and designing access models for developers, DevOps, SRE, administrators, contractors, and third parties (required)
- Experience with Zero Trust access solutions, preferably Cloudflare Zero Trust (required)
- Understanding of access controls across Kubernetes, OpenStack, Linux, LDAP-based environments (e.g. FreeIPA), and databases (MongoDB, PostgreSQL) (required)
- Strong understanding of non-human identities (service accounts, machine/API/workload identities, CI/CD and automation accounts) including AI agents and LLM-based tools (required)
- Experience with secrets management, short-lived credentials, credential rotation, and workload identity federation (required)
- Ability to analyze complex permission structures and identify excessive, inherited, conflicting, or unused access (required)
- Experience automating IAM through APIs, scripting, Infrastructure as Code, or policy as code (required)
- English level sufficient for technical documentation and communication with distributed teams (required)
- Hands-on experience with Terraform, Python, Bash, or similar automation tools (required)
- Experience with AWS IAM Identity Center, permission boundaries, Organizations, and cross-account role architecture (required)
- Experience with GCP organization-level IAM and Workload Identity Federation (required)
- Experience with OpenStack Keystone (required)
- Experience with Privileged Access Management or Identity Governance and Administration platforms (required)
- Understanding of identity and access control for AI agents and LLM-based tools (required)
- Experience with HashiCorp Vault, AWS SSM Parameter Store, or similar secrets management solutions (required)
- Knowledge of Kubernetes RBAC and cloud-native workload identities (required)
- Experience with GitLab, GitHub Actions, Jenkins, or other CI/CD platforms (required)
- Knowledge of Open Policy Agent or other policy-as-code technologies (required)
- Experience working in iGaming, fintech, payments, or another security-sensitive environment (required)
- Understanding of IAM requirements related to ISO 27001 and PCI DSS (required)
- Strong ownership and accountability (required)
- Ability to combine strategic thinking with hands-on technical work (required)
- Structured and risk-based decision-making (required)
- Strong analytical and troubleshooting skills (required)
- Ability to challenge insecure or unnecessarily complex access models (required)
- Ability to communicate complex IAM topics clearly to technical and non-technical stakeholders (required)
- Strong collaboration skills across Security, IT, Infrastructure, DevOps, Engineering, and business teams (required)
- Ability to influence teams without relying only on formal authority (required)
- Focus on scalable, automated, and maintainable solutions (required)
- Ability to prioritize risks and deliver improvements in a complex environment (required)
- An exciting and challenging job in a fast-growing business group.
- The opportunity to be part of a multicultural team of top professionals in Development, Architecture, Management, Operations, Marketing, Legal, Finance and more.
- A great working atmosphere with passionate experts and leaders, sharing a friendly culture and a success-driven mindset is guaranteed.
- Modern corporate equipment based on macOS or Windows and additional equipment are provided.
- Paid vacations, sick leave, personal events days, and days off.
- Corporate healthcare program for your well-being.
- Referral program - enjoy cooperation with your colleagues and get the bonus.
- Educational support by our L&D team: internal and external trainings and conferences, courses on Udemy.
- Free internal English courses.
- Sport benefit.
- Multiple internal activities: online platform with newsletters, quests, gamification, and presents for collecting bonuses, RedCore talks club for movie and book lovers, board games cozy evenings, special office days dedicated to holidays, etc.
- Company events, team buildings.
PIN-UP Global is an international holding company that develops technologies, B2B solutions and products for the iGaming industry. Headquartered in Warsaw, the group brings together businesses spanning product development, technology and marketing services for online gaming. It supports a portfolio of companies and brands operating across multiple markets. PIN-UP Global focuses on building advanced technology and products for the gambling sector.
