Logo for The Voleon Group

IAM Architect

Role overview

Qualifications

  • 8+ years of experience in identity and access management, security engineering, or infrastructure engineering with focus on authentication/authorization
  • Deep expertise in hybrid identity architectures bridging on-premise and cloud identity platforms
  • Strong understanding of modern authentication protocols: OIDC, SAML, OAuth2, LDAP, Kerberos
  • Hands-on experience implementing identity solutions in Linux-heavy environments with POSIX requirements

Responsibilities

  • Design and implement IAM strategy across hybrid infrastructure - Linux, Kubernetes, Windows, AWS, Azure, and cloud identity providers
  • Architect identity solutions that bridge POSIX-based authentication with modern cloud platforms
  • Implement privileged access management - just-in-time access, least privilege, periodic reviews, and accountability for shared service accounts
  • Extend zero-trust capabilities beyond current SASE remote access to broader infrastructure

About the company

The Voleon Group logo

The Voleon Group

Investment Management

Founded in 2007 by two machine learning scientists, The Voleon Group is a quantitative hedge fund headquartered in Berkeley, CA. We are committed to solving large-scale financial prediction problems with statistical machine learning. The Voleon Group combines an academic research culture with an emphasis on scalable architectures to deliver technology at the forefront of investment management. Many of our employees hold doctorates in statistics, computer science, and mathematics, among other quantitative disciplines. Voleon's CEO holds a Ph.D. in Computer Science from Stanford and previously founded and led a successful technology startup. Our Chief Investment Officer and Head of Research is Statistics faculty at UC Berkeley, where he earned his Ph.D. Voleon prides itself on cultivating an office environment that fosters creativity, collaboration, and open thinking. We are committed to excellence in all aspects of our research and operations, while maintaining a culture of intellectual curiosity and flexibility. The Voleon Group is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law.

Company details

Company typeSME
IndustryInvestment Management
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Voleon is a technology company that applies state-of-the-art machine learning techniques to real-world problems in finance. For more than a decade, we have led our industry and worked at the frontier of applying machine learning to investment management. We have become a multibillion-dollar asset manager, and we have ambitious goals for the future.

In addition to our enriching and collegial working environment, we offer highly competitive compensation and benefits packages, technology talks by our experts, a beautiful modern office, catered lunches, and more.

As an IAM Architect, you will define and execute our identity and access management strategy across our hybrid infrastructure. Reporting directly to the CISO, you will be responsible for designing and implementing modern identity solutions that protect our critical intellectual property while enabling our research, engineering, and operations teams to move quickly. Initially working as a senior individual contributor, you will architect solutions across on-premise Linux environments, Kubernetes clusters, Windows systems, cloud identity providers, and public cloud platforms. As our IAM program matures, you will build and lead a team to scale our identity management capabilities. This role is a means to make a difference: you will establish credibility with senior technical leaders and transform identity management by focusing on high-risk areas while being mindful of production requirements.

Responsibilities

  • Design and implement IAM strategy across hybrid infrastructure - Linux, Kubernetes, Windows, AWS, Azure, and cloud identity providers

  • Architect identity solutions that bridge POSIX-based authentication with modern cloud platforms (OIDC, SAML, federation), migrating from legacy models

  • Implement privileged access management - just-in-time access, least privilege, periodic reviews, and accountability for shared service accounts

  • Extend zero-trust capabilities beyond current SASE remote access to broader infrastructure

  • Partner cross-functionally with Security Engineering, Infrastructure, DevOps, and Corp IT to integrate identity controls without disrupting production

  • Define the IAM roadmap β€” prioritize high-risk areas, translate business requirements into technical solutions, and establish credibility with senior engineering and research leaders

  • Build the IAM team - hire, mentor, and lead IAM engineers as the program scales

Requirements

  • 8+ years of experience in identity and access management, security engineering, or infrastructure engineering with focus on authentication/authorization

  • Deep expertise in hybrid identity architectures bridging on-premise (LDAP, FreeIPA, Active Directory) and cloud identity platforms (AWS IAM, Azure AD/Entra, Google Workspace)

  • Strong understanding of modern authentication protocols: OIDC, SAML, OAuth2, LDAP, Kerberos

  • Hands-on experience implementing identity solutions in Linux-heavy environments with POSIX requirements

  • Experience with cloud IAM platforms (AWS IAM / Identity Center, Azure AD, GCP IAM) including roles, policies, federation, and service accounts

  • Knowledge of privileged access management (PAM) tools and patterns (CyberArk, HashiCorp Vault, AWS Secrets Manager, or similar)

  • Understanding of zero-trust architecture principles and implementation patterns

  • Demonstrated ability to balance security requirements with operational workflows and production stability

  • Proven track record working with senior technical leaders and building organizational trust

  • Strong communication skills to explain complex identity concepts to both technical and non-technical stakeholders

  • Experience or strong interest in building and leading technical teams

Preferred Qualifications

  • Experience with Kubernetes service account management and pod identity patterns

  • Familiarity with infrastructure-as-code (Terraform, Ansible) for identity provisioning

  • Experience implementing SCIM for automated user lifecycle management

  • Background in financial services, hedge funds, or high-security research environments

  • Experience with compliance frameworks (SOC 2, ISO 27001) as they relate to identity

  • Certifications such as CISSP, CCSP, or vendor-specific identity certifications

  • Bachelor's or Master's degree in Computer Science, Information Security, or related field

β€œFriends of Voleon” Candidate Referral Program

If you have a great candidate in mind for this role and would like to have the potential to earn $15,000 if your referred candidate is successfully hired and employed by The Voleon Group, please use this form to submit your referral. For more details regarding eligibility, terms and conditions please make sure to review the Voleon Referral Bonus Program.

Equal Opportunity Employer

The Voleon Group is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
Β·

Related jobs

Other jobs at The Voleon Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.