- Location
- BRA - Sao Paulo - Cytiva Do Brasil Comercio E Servicos Para Biotecnologia LTDA, Brazil
- Type
- Full-time
- Department
- Engineering
- Education
- Bachelor
- Source
- Workday
Description
At Danaher, an Identity Security Architect is responsible for designing and implementing identity-security architecture across all Danaher digital principles. In this role, enterprise strategy is set collaboratively by business, IT, and security stakeholders. The role shapes and refines the identity-security requirements, then owns turning it into adoptable designs for authentication, authorization, lifecycle, governance, federation, conditional access, and identity threat detection. The role requires that individuals work both independently and integrates with stakeholders in HR, ITSM, infrastructure, cloud, and application teams.
This position reports to the Director, Identity Security & Privileged Access Management and is part of the enterprise-wide Danaher Information Security (DIS) Identity & Privileged Access Management team; this position is remote.
In this role, you will have the opportunity to:
Architect identity security across workforce, privileged, machine, customer, and partner identities: authentication, authorization, lifecycle, IGA, federation, conditional access, ITDR.
Design safe authenticator recovery and service-desk anti-social-engineering controls.
Engineer/prototype integration patterns (HRIS, directories, IdP, SIEM/UEBA) to validate designs.
Design the sustainability & governance model: role/entitlement models, identity analytics, and architecture review cadence.
The essential requirements of the job include:
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
9+ years of cybersecurity experience with a focus on identity and access management (GCRF P4 Bachelor's-track minimum; recommended, pending Comp sign-off).
Experience designing identity security architecture across workforce, privileged, machine, or customer identities — including authentication, authorization, Joiner-Mover-Leaver lifecycle, role/entitlement modeling, access certification, and Segregation of Duties.
Hands-on experience with enterprise identity platforms (such as Microsoft Entra ID, Okta, Ping, SailPoint, or Saviynt) and identity protocols (SAML, OIDC, OAuth, SCIM).
Experience working independently with HR, IT service management, infrastructure, and application teams to design and govern identity controls.
It would be a plus if you also possess previous experience in:
Experience with identity threat detection and response (ITDR), identity analytics/UEBA, or non-human / machine identity governance (NHI).
CISSP, CISM, Microsoft SC-300, or a relevant IAM platform certification.
Join our winning team today. Together, we’ll accelerate the real-life impact of tomorrow’s science and technology. We partner with customers across the globe to help them solve their most complex challenges, architecting solutions that bring the power of science to life.
For more information, visit www.danaher.com.