Own the security and identity architecture for CDW’s MyCDW ServiceNow platform. Lead consolidation of Entra, Okta, and ServiceNow authentication; architect SailPoint-to-Entra IGA migration; define RBAC, lifecycle, certification, governance, and compliance controls; and guide threat modeling, monitoring, risk reduction, and remediation. Partner across technology and compliance teams, lead IAM and security engineers, manage vendors, and develop strategic roadmaps for secure, cost-effective platform transformation.
Description
The Principal Security & IAM Architect is responsible for designing and supporting the implementation of the security and identity architecture of the MyCDW platform - CDW Managed Services' unified ServiceNow environment serving thousands of customers and coworkers. This role owns the future-state access management model, the consolidation of fragmented identity platforms (Entra, Okta, and native ServiceNow authentication), and the security controls that protect customer and coworker access across the Managed Services estate. It ensures the security and identity architecture aligns with the organization's business strategy, regulatory obligations, and enterprise hardening standards, and drives the strategic planning, governance, and risk reduction required to operate MyCDW securely at scale.
What you will do
* Define and own the future-state security and access management architecture for the MyCDW ServiceNow platform, covering authentication, authorization, and identity lifecycle management for both customer and coworker users.
* Lead the consolidation of fragmented identity platforms (Entra, Okta, and native ServiceNow authentication) toward a unified, future-state identity model that reduces attack surface, duplicative controls, and licensing cost.
* Architect the SailPoint → Microsoft Entra ID Governance (IGA) migration and the RBAC and access-tier model for ServiceNow, aligning coworker identity to Entra IGA standards.
* Design access request, approval, certification, and lifecycle (joiner / mover / leaver) workflows with clear ownership and auditable controls.
* Ensure the platform and identity model meet security and compliance requirements, including PCI DSS v4.0.1 access-control requirements, SOC 2, and corporate security policies.
* Establish identity and security governance - decision rights, ownership frameworks, and standards - across ITSM processes and the MyCDW platform.
* Define a staged transition that decouples coworker identity (Entra IGA-aligned) from customer identity, minimizing customer disruption and avoiding repeated identity changes for the same customers.
* Partner with the Principal Applications Architect and the Integration & Automation Architect to ensure identity and security designs align to the platform's target-state architecture.
* Evaluate identity, security, and IGA technologies and products to determine their suitability and cost-effectiveness, including benchmarking, proof-of-concept projects, and risk/cost trade-off analysis.
* Implement security monitoring, threat detection, and identity analytics for predictive risk insights and platform health.
* Conduct security and identity risk assessments, threat modeling, and design reviews, and provide remediation guidance for technical debt carried forward from legacy environments.
* Lead, mentor, and set standards for the Managed Services security and IAM engineering team, including security engineers and IAM analysts.
* Effectively communicate and collaborate with development, engineering, infrastructure, compliance, and product stakeholders to ensure the security and identity vision is understood and implemented.
* Create and maintain documentation related to the security and identity architecture, roadmaps, design decisions, control mappings, and technical specifications.
* Resolve complex security and identity issues that arise during design, migration, and operations, providing guidance and solutions to overcome obstacles.
* Balance security requirements with budget and experience constraints to make cost-effective, risk-based decisions.
* Interact with identity and security technology vendors, negotiate contracts, and manage relationships to ensure the organization gets the best value.
* Anticipate and keep up with emerging security and identity threats, standards, and industry trends to recommend innovative, defensible solutions.
What we expect of you
* Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field and 10 years' experience in IT, including security architecture and identity & access management, OR 14 years' experience in IT, security, and IAM.
* Deep, hands-on expertise designing enterprise security and IAM architectures, including authentication, authorization, federation (SAML / OAuth / OIDC), SSO, MFA, and privileged access management.
* Strong, demonstrated experience with Microsoft Entra ID and Entra ID Governance (IGA), and with identity governance platforms such as SailPoint, ideally including migrations between them.
* Expertise in RBAC / ABAC design, access certification, and joiner / mover / leaver identity lifecycle automation.
* Strong knowledge of regulatory and compliance frameworks, particularly PCI DSS v4.0.1, SOC 2, and corporate security and hardening standards, with the ability to map controls to architecture.
* Experience securing SaaS and ITSM platforms (ServiceNow strongly preferred), including platform authentication models and integration security.
* Experience/research in Artificial Intelligence principles as applied to security - identity analytics, anomaly and threat detection, and the access governance of AI agents and automated workflows.
* Ability to develop and implement security and identity strategies that support organizational objectives while reducing risk and cost.
* Experience leading project teams from an architecture perspective, collaborating with stakeholders across departments, and influencing decision-making at a strategic level.
* Demonstrated ability to lead security transformation initiatives, drive risk reduction, and manage change effectively.
* Extensive and demonstrated understanding of network architecture, security principles, infrastructure management, and cloud security.
* Exceptional problem-solving skills and the ability to think strategically, anticipating threats and translating them into actionable, defensible plans aligned with enterprise-wide goals.
* Strong communication and interpersonal skills, including collaboration, leadership, influencing, and conflict resolution.
* Ability to work in a fast-paced, dynamic environment and manage multiple projects simultaneously.
* Proven track record designing and implementing large-scale, complex security and identity solutions.
* Extensive experience in multiple IT domains, such as applications, data, infrastructure, security, and cloud services.
* Relevant certifications such as CISSP, CISM, SailPoint, or Microsoft Identity & Access Administrator (SC-300), a plus.
* Master's degree, a plus. Pay range: $156,400 - $218,920 depending on experience and skill set Annual bonus target of 10% subject to terms and conditions of plan Benefits overview: https://cdw.benefit-info.com/ Salary ranges may be subject to geographic differentials
* CDW is committed to being an AI-fluent organization
* We're looking for people who bring curiosity, a learner's mindset, and a willingness to engage with ever-evolving technology and tools. We value adopting AI as a partner, openness to experimentation, and a shared interest in learning together on AI. Our goal is to create a culture where AI enhances- not replaces- human creativity and decision-making. You don't need to be an expert today; what matters is your readiness to explore, adapt, and grow with us as we integrate AI responsibly and effectively into our work.Additionally, CDW is committed to fostering an equitable, transparent, and respectful hiring process for all applicants. During our application process, our goal is to understand your experience, strengths, skills, and qualifications. As an AI forward company, we see AI not just as a tool, but as a catalyst for new ways of thinking, creating, and communicating. We encourage candidates to embrace an AI mindset, one that's curious, adaptive, and ready to explore what's possible. We welcome thoughtful use of AI to expand your perspective and elevate how you share your story, while ensuring your application remains rooted in your own background, judgment, and voice.
* About Us
* CDW is a Fortune 500 technology solutions provider that helps businesses, government, education, and healthcare organizations achieve what's possible through technology. What makes CDW different isn't just what we do- it's how we do it. At CDW we act as one- building trust, speaking candidly, and working together to achieve more. We play to win- focusing on what matters most and delivering for our customers. And we think forward- staying curious, moving fast, and continuously learning. We believe meaningful work happens when people feel supported, heard, and empowered to contribute. That's why we think of ourselves as coworkers, not just employees- working together to solve complex challenges and deliver real impact for our customers and communities. As a full-stack, full-lifecycle technology partner, CDW brings deep expertise, strong relationships, and broad industry knowledge to help turn ideas into outcomes. When you join CDW, you become part of a collaborative environment where your work matters, your growth is supported, and your contributions help shape what's next. Together, we deliver the full promise of what technology can do.
* Together, we Make Amazing Happen.
* CDW is an equal opportunity employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status or any other basis prohibited by state and local law.
The Principal Security & IAM Architect is responsible for designing and supporting the implementation of the security and identity architecture of the MyCDW platform - CDW Managed Services' unified ServiceNow environment serving thousands of customers and coworkers. This role owns the future-state access management model, the consolidation of fragmented identity platforms (Entra, Okta, and native ServiceNow authentication), and the security controls that protect customer and coworker access across the Managed Services estate. It ensures the security and identity architecture aligns with the organization's business strategy, regulatory obligations, and enterprise hardening standards, and drives the strategic planning, governance, and risk reduction required to operate MyCDW securely at scale.
What you will do
* Define and own the future-state security and access management architecture for the MyCDW ServiceNow platform, covering authentication, authorization, and identity lifecycle management for both customer and coworker users.
* Lead the consolidation of fragmented identity platforms (Entra, Okta, and native ServiceNow authentication) toward a unified, future-state identity model that reduces attack surface, duplicative controls, and licensing cost.
* Architect the SailPoint → Microsoft Entra ID Governance (IGA) migration and the RBAC and access-tier model for ServiceNow, aligning coworker identity to Entra IGA standards.
* Design access request, approval, certification, and lifecycle (joiner / mover / leaver) workflows with clear ownership and auditable controls.
* Ensure the platform and identity model meet security and compliance requirements, including PCI DSS v4.0.1 access-control requirements, SOC 2, and corporate security policies.
* Establish identity and security governance - decision rights, ownership frameworks, and standards - across ITSM processes and the MyCDW platform.
* Define a staged transition that decouples coworker identity (Entra IGA-aligned) from customer identity, minimizing customer disruption and avoiding repeated identity changes for the same customers.
* Partner with the Principal Applications Architect and the Integration & Automation Architect to ensure identity and security designs align to the platform's target-state architecture.
* Evaluate identity, security, and IGA technologies and products to determine their suitability and cost-effectiveness, including benchmarking, proof-of-concept projects, and risk/cost trade-off analysis.
* Implement security monitoring, threat detection, and identity analytics for predictive risk insights and platform health.
* Conduct security and identity risk assessments, threat modeling, and design reviews, and provide remediation guidance for technical debt carried forward from legacy environments.
* Lead, mentor, and set standards for the Managed Services security and IAM engineering team, including security engineers and IAM analysts.
* Effectively communicate and collaborate with development, engineering, infrastructure, compliance, and product stakeholders to ensure the security and identity vision is understood and implemented.
* Create and maintain documentation related to the security and identity architecture, roadmaps, design decisions, control mappings, and technical specifications.
* Resolve complex security and identity issues that arise during design, migration, and operations, providing guidance and solutions to overcome obstacles.
* Balance security requirements with budget and experience constraints to make cost-effective, risk-based decisions.
* Interact with identity and security technology vendors, negotiate contracts, and manage relationships to ensure the organization gets the best value.
* Anticipate and keep up with emerging security and identity threats, standards, and industry trends to recommend innovative, defensible solutions.
What we expect of you
* Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field and 10 years' experience in IT, including security architecture and identity & access management, OR 14 years' experience in IT, security, and IAM.
* Deep, hands-on expertise designing enterprise security and IAM architectures, including authentication, authorization, federation (SAML / OAuth / OIDC), SSO, MFA, and privileged access management.
* Strong, demonstrated experience with Microsoft Entra ID and Entra ID Governance (IGA), and with identity governance platforms such as SailPoint, ideally including migrations between them.
* Expertise in RBAC / ABAC design, access certification, and joiner / mover / leaver identity lifecycle automation.
* Strong knowledge of regulatory and compliance frameworks, particularly PCI DSS v4.0.1, SOC 2, and corporate security and hardening standards, with the ability to map controls to architecture.
* Experience securing SaaS and ITSM platforms (ServiceNow strongly preferred), including platform authentication models and integration security.
* Experience/research in Artificial Intelligence principles as applied to security - identity analytics, anomaly and threat detection, and the access governance of AI agents and automated workflows.
* Ability to develop and implement security and identity strategies that support organizational objectives while reducing risk and cost.
* Experience leading project teams from an architecture perspective, collaborating with stakeholders across departments, and influencing decision-making at a strategic level.
* Demonstrated ability to lead security transformation initiatives, drive risk reduction, and manage change effectively.
* Extensive and demonstrated understanding of network architecture, security principles, infrastructure management, and cloud security.
* Exceptional problem-solving skills and the ability to think strategically, anticipating threats and translating them into actionable, defensible plans aligned with enterprise-wide goals.
* Strong communication and interpersonal skills, including collaboration, leadership, influencing, and conflict resolution.
* Ability to work in a fast-paced, dynamic environment and manage multiple projects simultaneously.
* Proven track record designing and implementing large-scale, complex security and identity solutions.
* Extensive experience in multiple IT domains, such as applications, data, infrastructure, security, and cloud services.
* Relevant certifications such as CISSP, CISM, SailPoint, or Microsoft Identity & Access Administrator (SC-300), a plus.
* Master's degree, a plus. Pay range: $156,400 - $218,920 depending on experience and skill set Annual bonus target of 10% subject to terms and conditions of plan Benefits overview: https://cdw.benefit-info.com/ Salary ranges may be subject to geographic differentials
* CDW is committed to being an AI-fluent organization
* We're looking for people who bring curiosity, a learner's mindset, and a willingness to engage with ever-evolving technology and tools. We value adopting AI as a partner, openness to experimentation, and a shared interest in learning together on AI. Our goal is to create a culture where AI enhances- not replaces- human creativity and decision-making. You don't need to be an expert today; what matters is your readiness to explore, adapt, and grow with us as we integrate AI responsibly and effectively into our work.Additionally, CDW is committed to fostering an equitable, transparent, and respectful hiring process for all applicants. During our application process, our goal is to understand your experience, strengths, skills, and qualifications. As an AI forward company, we see AI not just as a tool, but as a catalyst for new ways of thinking, creating, and communicating. We encourage candidates to embrace an AI mindset, one that's curious, adaptive, and ready to explore what's possible. We welcome thoughtful use of AI to expand your perspective and elevate how you share your story, while ensuring your application remains rooted in your own background, judgment, and voice.
* About Us
* CDW is a Fortune 500 technology solutions provider that helps businesses, government, education, and healthcare organizations achieve what's possible through technology. What makes CDW different isn't just what we do- it's how we do it. At CDW we act as one- building trust, speaking candidly, and working together to achieve more. We play to win- focusing on what matters most and delivering for our customers. And we think forward- staying curious, moving fast, and continuously learning. We believe meaningful work happens when people feel supported, heard, and empowered to contribute. That's why we think of ourselves as coworkers, not just employees- working together to solve complex challenges and deliver real impact for our customers and communities. As a full-stack, full-lifecycle technology partner, CDW brings deep expertise, strong relationships, and broad industry knowledge to help turn ideas into outcomes. When you join CDW, you become part of a collaborative environment where your work matters, your growth is supported, and your contributions help shape what's next. Together, we deliver the full promise of what technology can do.
* Together, we Make Amazing Happen.
* CDW is an equal opportunity employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status or any other basis prohibited by state and local law.
Similar Jobs at CDW
Information Technology
Own the end-to-end integration and automation architecture for the MyCDW platform. Design ServiceNow integrations, APIs, event-driven patterns, middleware, data contracts, AI-agent guardrails, automated workflows, and observability. Establish governance, security, coding standards, testing, documentation, and reusable architecture patterns. Evaluate platforms, lead prototypes, resolve complex issues, manage vendors, influence stakeholders, and align solutions with business strategy, compliance requirements, scalability, resilience, and cost objectives.
Top Skills:
Agentic AiAPIsArtificial IntelligenceBoomiCloud ServicesETLEvent-Driven ArchitectureIpaasMachine LearningMessage-Based IntegrationMid ServerMiddlewareMulesoftNetwork ArchitectureOrchestrationPredictive AnalyticsRestServicenowServicenow Integration HubSoapStreaming IntegrationsWebhooksWorkflow Automation
Information Technology
Work as an on-campus liaison between CDW sales, university departments, and technology partners. Build relationships, research campus technology trends, educate stakeholders about CDW offerings, and support customer-facing activities. Participate in six-week paid training and ongoing mentorship while working 15–25 hours/week during the academic year.
Top Skills:
AILivemeeting
Information Technology
Sell CDW Security services and products through full sales lifecycle management: strategic account planning, opportunity qualification, relationship building, partnering with services and OEMs, pipeline forecasting, and closing. Mentor junior team members, engage partners and marketing, maintain Salesforce, represent CDW at industry events, and drive revenue, bookings, and gross profit targets.
Top Skills:
Salesforce
What you need to know about the Los Angeles Tech Scene
Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.
Key Facts About Los Angeles Tech
- Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
- Key Industries: Artificial intelligence, adtech, media, software, game development
- Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
- Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

