ForgeApply · Job listing
Workforce Identity Architect, VP
MUFG
See all 198 open roles at MUFG →
Tailor your resume for this MUFG job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for MUFG's site. Free trial, no card required.
About this role
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
Job Summary
The Workforce Identity Architect is a senior architecture role responsible for defining and governing workforce (human) identity architecture at global scale. This role designs and standardizes how employee and partner identities are created, governed, authenticated, authorized, reviewed, and retired across hybrid and cloud environments. The Workforce Identity Architect operationalizes global IAM standards for human identity, ensuring secure, scalable, and auditable access while supporting regions transitioning through different identity maturity stages. This role focuses on architecture, standards, and enablement, not day‑to‑day operations or tool administration.
Key Responsibilities:
Workforce Identity Architecture • Define and maintain global workforce identity architecture using Microsoft Entra ID in hybrid and cloud‑mastered environments. • Establish standard patterns for authentication, federation, Conditional Access, and MFA. • Design tenant‑level identity integration patterns that scale across applications and regions.
Identity Lifecycle Management • Architect and standardize Joiner / Mover / Leaver (JML) identity lifecycle patterns driven by authoritative HR sources. • Ensure consistent provisioning, modification, and deprovisioning of workforce identities. • Reduce orphaned, dormant, and over‑provisioned access through strong lifecycle design.
Identity Governance & Privileged Access • Define workforce identity governance standards, including access requests, access reviews, and separation of duties (SoD). • Architect privileged access models for workforce identities, including PIM and Just‑in‑Time access. • Ensure access models are auditable and aligned to regulatory and risk expectations.
AI‑Assisted Analytics & Access Optimization • Leverage analytics and AI‑assisted capabilities to improve role and entitlement design. • Reduce access certification noise by improving role quality, review scoping, and access rationalization. • Translate analytic insights into architectural improvements rather than one‑off reporting.
External & Partner Identity • Define B2B and partner identity patterns using Entra ID that enable collaboration while maintaining centralized governance. • Ensure third‑party access aligns with global standards and workforce identity controls.
Metrics & Continuous Improvement • Partner with IAM Governance teams to define and consume workforce identity metrics, including access quality, review effectiveness, and lifecycle hygiene. • Use metrics to continuously improve identity architecture and reduce access risk.
What This Role Is — and Is Not
This role is: • A senior architecture and standards role • Focused on workforce identity at enterprise and global scale • A bridge between architecture, security, risk, and delivery team
This role is not: • An IAM operation or helpdesk role • A single‑tool administrator position • A regional‑only identity role
What Success Looks Like • Consistent, scalable workforce identity standards adopted across regions • Reduced access risk and certification fatigue • Clear lifecycle ownership and audit‑ready access governance • Smooth regional progression toward cloud‑mastered identity
Why This Role Matters
Workforce identity is foundational to security, compliance, and user experience. This role ensures workforce identity evolves intentionally, consistently, and defensibly, enabling global scale while reducing access risk and operational friction.
Required Qualifications • 8–10+ years of experience in identity, access management, or security architecture roles. • Deep expertise in Microsoft Entra ID architecture in hybrid environments. • Strong experience designing JML lifecycle, identity governance, and privileged access controls. • Ability to design auditable, regulator‑defensible access models. • Proven ability to influence across technical and non‑technical stakeholders.
Preferred Qualifications • Experience using analytics or AI‑assisted tools for access optimization and certification improvement. • Experience supporting global or federated IAM models with regional variation. • Familiarity with regulated industries (e.g., financial services). • Relevant identity or security certifications.
Required Skills (Must Have)
These skills are essential to successfully perform the role and should be treated as non‑negotiable. • Identity Architecture & Lifecycle • Enterprise‑level experience designing workforce identity architecture at scale. • Deep understanding of Joiner / Mover / Leaver (JML) lifecycle patterns and HR‑driven identity provisioning. • Strong grounding in least privilege, access lifecycle management, and identity hygiene. • Microsoft Entra ID (Azure AD) • Hands‑on architectural experience with Microsoft Entra ID in hybrid environments. • Design and governance of: • Authentication and federation • Conditional Access and MFA • Tenant‑level architecture and integration patterns
• Identity Governance & Access Contr
Salary insight
The midpoint of this range ($179k) is about 8% above the median disclosed salary for New York roles listed on ForgeApply ($165k across 8,280 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this MUFG role before you apply.
Tailor my resume for this jobSimilar jobs
- Workforce Identity Service Lead Consultant — Allstate · Remote
- Workforce Identity and Directory Services, VP - Enterprise Technology — Blackstone · Miami
- Senior Identity & Access Management (IAM) Engineer, Workforce Identity — Acrisure · GA | MI
- Enterprise IAM Architect, VP — MUFG · Jersey City, NJ | Tampa, FL
- Sr. Enterprise Identity Architect — KLA · Milpitas, CA
- Senior Sales Director, Commercial & Workforce Identity Solutions — Idme · Remote
- Workforce IAM Senior Technology Manager — M&T Bank · Buffalo, NY
- Senior Solutions Architect, Identity Security — Keepersecurity · Remote
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)