Information Security Solution Architect - Identity & Access Management (m/f/d)

Job Level:  Professional
Location: 

Barcelona, B, ES, 08005 Lisbon, Lisbon, PT, 1000-236

Area of Expertise:  IT & Tech Engineering
Unit:  Allianz Services
Employing Entity:  Allianz Services GmbH Sucursal en España
Job Type:  Full-Time
Remote Job:  Hybrid working
Employment Type:  Permanent
ID:  103378
Position Cluster: 

130 years of trust, time to shape what's next. Allianz Group is one of the world's leading insurers and asset managers - built on over a century of stability, expertise, and financial strength. Allianz Services is where that legacy meets the future. 8,200+ people. Eight countries. Three continents. We deliver specialized services to clients within Allianz Group, powered by AI, advanced analytics, and a mindset that refuses to stand still. From core insurance operations to engineering and consulting services, we reimagine how insurance works. What truly sets us apart are our people and the trusted partnerships we build, anchored in our values of expertise, integrity, and empowerment. We don't support the business. We shape it.

 

Role Overview:

We are looking for an experienced IS Solution Architect – Identity & Access Management Security to drive the design, governance, and evolution of enterprise IAM architectures. The role combines deep technical expertise in identity lifecycle management, privileged access, and access governance with strong security governance capabilities — ensuring robust identity controls, Zero Trust adoption, and regulatory compliance across complex, multi-geography environments.

 

What you do:

  • Design and maintain enterprise IAM architectures: identity lifecycle management, access governance, authentication/authorization frameworks, directory services, and Privileged Access Management (PAM) — aligned with Zero Trust Identity principles including least privilege, continuous verification, and adaptive authentication.
  • Provide architectural guidance on enterprise IAM platforms (Microsoft Entra ID, SailPoint, CyberArk, Okta, Ping Identity, ForgeRock) and modern authentication protocols (SAML, OAuth 2.0, OpenID Connect, FIDO2/passkeys), ensuring secure identity federation and SSO across the enterprise.
  • Draft, review, and maintain identity security policies, access governance standards, and technical baselines; support formal governance processes for IAM architecture decisions, access exception approvals, privilege escalation sign-off workflows, and time-bound access derogations.
  • Define and track KPIs/KRIs for IAM posture (privileged account coverage, MFA adoption rates, orphaned account metrics, access certification completion rates) and present governance reporting to security committees and senior leadership.
  • Contribute to or lead IAM design authority and architecture review board (ARB) processes — ensuring IAM security requirements are embedded at design phase across infrastructure, application, and cloud projects; act as identity security advisor to IT and business teams.

 

What you bring:

  • Higher education degree in Information Security, Computer Science, Engineering, or related technical field.
  • 5+ years of experience in Identity & Access Management Architecture or IAM Engineering in enterprise environments.
  • Hands-on experience designing and implementing enterprise IAM architectures: identity lifecycle management, access governance, authentication/authorization frameworks, and directory services.
  • Strong understanding of Zero Trust Identity principles: least privilege, continuous verification, conditional access, and adaptive authentication.
  • Experience with enterprise IAM platforms (Microsoft Entra ID, SailPoint, CyberArk, Okta, Ping Identity, ForgeRock, One Identity) and Privileged Access Management (PAM) strategy, implementation, and operational governance.
  • Knowledge of identity federation, SSO, and modern authentication protocols: SAML, OAuth 2.0, OpenID Connect, FIDO2/passkeys, and certificate-based authentication.
  • Experience with access governance: RBAC, ABAC, access reviews, and segregation of duties (SoD).
  • Familiarity with DORA, NIS2, ISO 27001, NIST CSF, and GDPR (data access controls).
  • Excellent English skills (written and spoken).
  • We highly welcome candidates with a genuine interest and affinity for Information Technology (IT) and Generative Artificial Intelligence (GenAI), as these attributes are considered valuable assets to our team.

 

What we offer:

  • We offer a hybrid work model which recognizes the value of striking a balance between in-person collaboration and remote working incl. up to 25 days per year working from abroad
  • We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location)
  • From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered
  • Flexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach

 

 

About Allianz 

Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges is what makes us a unique employer.
We are united by a shared commitment: to put our customers first and at the center of everything we do. Their needs inspire our thinking and guide our actions.
Together, we can build an environment where everyone feels empowered and confident to explore, grow and shape a better future – for our customers and for the world around us. At Allianz, we stand for unity: we believe that a united world is a more prosperous world, and we are dedicated to consistently advocating for equal opportunities for all. The foundation for this is our inclusive workplace, where people and performance both matter, and where integrity, fairness, inclusion and trust are at the heart of our culture.
We therefore welcome applications regardless of ethnicity or cultural Internal background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations.


Join us. Let's care for tomorrow.

#LI-RV1