Skip to content

Principal Architect, Security Architecture

Innomar Strategies

Conshohocken PA

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today! Job Details Job Description Summary The Principal IAM Architect serves as the senior technical authority for Identity and Access Management (IAM) architecture across the enterprise. This role is responsible for defining the strategic direction, architecture standards, and technology roadmap for identity services that protect critical business assets while enabling secure and efficient workforce, partner, and customer access. The Principal IAM Architect partners with cybersecurity, infrastructure, application development, cloud engineering, and business leaders to design scalable identity solutions that support business growth, regulatory compliance, and Zero Trust security objectives. Operating with significant autonomy, this role drives enterprise-wide identity transformation initiatives, establishes architectural standards, and serves as the organization's subject matter expert for modern identity technologies and access governance. Key Responsibilities Serves as the enterprise lead architect for Identity and Access Management (IAM), providing strategic and technical leadership for identity-related initiatives across the organization. Defines and maintains the enterprise IAM architecture roadmap, standards, reference designs, and implementation patterns supporting workforce, privileged, third-party, and customer identities. Designs scalable and secure identity solutions that align with business objectives, cybersecurity strategy, regulatory requirements, and operational needs. Leads architectural decisions related to Identity Governance and Administration (IGA), Privileged Access Management (PAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), Passwordless Authentication, Identity Federation, and Access Governance. Establishes enterprise identity architecture standards supporting cloud, hybrid, and on-premises environments, including Microsoft Entra ID, Active Directory, SaaS platforms, and business-critical applications. Partners with application owners, infrastructure teams, cybersecurity leadership, and enterprise architects to integrate identity controls into technology initiatives and business processes. Evaluates and recommends IAM technologies, platforms, and vendors to improve security, operational efficiency, user experience, and scalability. Leads architecture reviews for major projects and strategic initiatives, ensuring solutions adhere to established identity standards and security requirements. Provides expert guidance on authentication protocols and standards, including OAuth 2.0, OpenID Connect (OIDC), SAML, SCIM, Kerberos, and modern federation technologies. Supports the organization's Zero Trust strategy by designing identity-centric controls that enable secure access decisions based on risk, context, and continuous verification. Analyzes emerging cybersecurity threats, identity attack vectors, technology trends, and industry best practices to continuously improve the organization's IAM capabilities. Partners with risk management, audit, compliance, and governance teams to ensure identity architectures support regulatory and internal control requirements. Leads architecture governance processes, technical reviews, and design boards to ensure consistency across IAM implementations. Mentors IAM engineers, architects, and technical leaders while promoting best practices, knowledge sharing, and architectural excellence throughout the organization. Influences strategic investment decisions and provides senior leadership with technical recommendations regarding identity modernization and security transformation initiatives. Required Qualifications Bachelor's degree in Computer Science, Information Technology, Information Security, Cybersecurity, Systems Engineering, or a related field, or equivalent professional experience. 8+ years of experience in Identity and Access Management, Cybersecurity Architecture, Security Engineering, Infrastructure Architecture, or a related technical discipline. Demonstrated experience designing and implementing enterprise IAM solutions across cloud and hybrid environments. Deep expertise in identity technologies including: Identity Governance and Administration (IGA) Privileged Access Management (PAM) Single Sign-On (SSO) Multi-Factor Authentication (MFA) Federation Services Directory Services Access Certification and Governance Strong knowledge of modern authentication and authorization standards, including OAuth 2.0, OpenID Connect (OIDC), SAML, SCIM, JWT, and FIDO2. Experience developing enterprise architecture standards, reference architectures, and technical governance processes. Proven ability to influence senior stakeholders and drive cross-functional alignment on complex technology initiatives. Preferred Qualifications Master's degree in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a related field. Industry certifications such as: CISSP CCSP SABSA TOGAF Microsoft Cybersecurity Architect Expert SailPoint, Okta, CyberArk, or Microsoft Identity certifications Experience leading IAM modernization programs, cloud identity transformations, or Zero Trust initiatives. Experience within highly regulated industries such as healthcare, pharmaceutical, financial services, or critical infrastructure. Familiarity with DevSecOps, cloud security architecture, and API security frameworks. Leadership Competencies Enterprise-wide strategic thinking. Strong architecture and systems design expertise. Executive-level communication and stakeholder management. Ability to influence without direct authority. Exceptional problem-solving and analytical skills. Mentorship and technical leadership capabilities. Strong understanding of balancing security, usability, compliance, and operational efficiency. What Cencora offers We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora Full time Equal Employment Opportunity Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law. The company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory. Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email [email protected]. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned Affiliated Companies Affiliated Companies: AmerisourceBergen Services Corporation Cencora is a leading global pharmaceutical solutions company that is committed to improving the lives of people and animals everywhere. We connect manufacturers, providers, and patients to ensure that anyone can get the therapies they need, where and when they need them. We’re a purpose-driven organization, where all of our team members around the world are united in our responsibility to create healthier futures. We work together every day to help our partners bring their innovations to patients worldwide, creating unparalleled access and impact at the center of health. Recruitment scams are on the rise and the intent is to target individuals looking for employment opportunities. To protect yourself, we urge you to be vigilant and follow these guidelines. 1.) Research the Company: Thoroughly research any company before applying or sharing personal information, check their website, read reviews, and verify their legitimacy. 2.) Be Wary of Unrealistic Promises: Exercise caution If a job posting offers high salaries and minimal qualifications. Legitimate jobs will have realistic expectations and provide detailed job requirements. Jobs at Cencora can be found on Cencora.com/careers 3.) Guard Your Personal Information: Only share sensitive information after vetting the employer’s credibility. Avoid sharing your Social Security number, bank account details, or identification documents during the application process. Cencora does not request this information as part of the employment application. 4.) Avoid Upfront Payments: Legitimate employers do not require payment during the hiring process. Be suspicious if you are asked to pay for training materials, processing fees, or background checks before securing a job offer. Cencora will never ask you for payment information during the hiring or onboarding process. 5.) Verify Communication Channels: Scammers often use free email services or chat platforms without providing an official company contact information. Cencora recruiters will have an email address ending in @cencora.com, @alliance-healthcare.net, @alliance-healthcare.co.uk, alliance-healthcare.fr or alliance-healthcare.ro Remember to stay vigilant and informed about common scam tactics to reduce the risk of falling victim to fraudulent employment schemes. If you believe you have encountered a job scam posing as a Cencora opportunity, please report it immediately to: [email protected]

Seen 21 days ago.

Original posting on Innomar Strategies's site ↗

Posting text belongs to the employer. Removal requests: contact us.

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

One job at a time

One posting. One CV. $25.

Pick the job you actually want and we write for it.

Get my CV for this job