Lead Security Architect — CASB, Identity & Privileged Access Bourntec Solutions Nutley, NJ Job Details Contract From $70 an hour 8 hours ago Qualifications Cloud identity and access management (IAM) Zero Trust security Content creation for technical audiences Technical documentation CISSP Security architecture risk management Azure AD Data access controls implementation IT control testing MFA Identity and access management (IAM) architecture design Access control management Data Loss Prevention Workshop facilitation experience Technical writing experience within technology Security technology solutions implementations Security Testing Active Directory Senior leadership Identity & access management Full Job Description Lead Security Architect —
CASB, Identity & Privileged Access Client:
Insurance Location:
Onsite -
Nutley, NJ Duration:
Contract - 4 months Ideal Candidate Profile The ideal candidate is a hands-on Lead Security Architect with proven experience leading Prisma Access
CASB/ZTNA
initiatives , designing and implementing CASB, DLP, identity, and privileged access controls, conducting security assessments, developing remediation roadmaps, validating implementations, and driving technical workshops with senior stakeholders while providing end-to-end ownership from architecture and design through remediation and production sign-off. Role Overview We are seeking a Lead Security Architect to provide senior technical leadership across critical security workstreams focused on Prisma Access CASB/ZTNA, Microsoft Entra ID, Conditional Access, and Privileged Access Management (PAM) . The architect will initially lead the Prisma
CASB/DLP
workstream , while also providing technical direction across identity, privileged access, and cross-platform security remediation. This role requires strong hands-on architecture experience, the ability to design practical remediation strategies, and confidence leading technical discussions with client stakeholders. Primary Technology Coverage Palo Alto Prisma Access / CASB / ZTNA Microsoft Entra ID Conditional Access & MFA Microsoft Defender for Cloud Apps (MDCA) Delinea / Privileged Access Management (PAM) Human and non-human identities Cross-platform security controls and remediation Key Responsibilities Lead the Prisma Access
CASB/DLP
baseline assessment , policy design, sanctioned-application decisions, and enforcement strategy. Review and assess Prisma ZTNA policies and ensure alignment with privileged-access and identity security controls. Lead the Microsoft Entra ID and Conditional Access security review , including findings analysis and remediation design. Assess Delinea/PAM configurations and controls governing privileged human and non-human accounts. Identify overlaps, dependencies, control ownership issues, and potential policy conflicts across security platforms. Define structured remediation waves , including sequencing, dependencies, rollback considerations, and implementation controls. Establish testing criteria and evidence requirements for security remediation activities. Validate proposed changes before production implementation and provide technical sign-off support . Lead technical workshops with security, infrastructure, identity, application, and business stakeholders. Translate security findings into practical, implementable remediation plans while considering business and operational impact. Support validation of implemented changes through before/after evidence and control verification . Provide senior technical guidance across identity, access management, privileged access, and cloud security workstreams.
Required Qualifications & Experience Mandatory:
Strong hands-on architecture experience with Palo Alto Prisma Access, CASB, and ZTNA . Strong experience with Microsoft Entra ID (Azure AD) and Conditional Access . Strong understanding of MFA, identity security, and access-control policies . Experience with Microsoft Defender for Cloud Apps (MDCA/CASB) . Working knowledge of Delinea or comparable PAM platforms . Understanding of privileged human and non-human/service identities . Experience designing and implementing secure access policies and controlled security remediation . Experience performing security assessments, developing remediation designs, and validating implemented controls. Strong technical documentation and client-facing communication skills. Ability to lead technical workshops and work directly with senior client stakeholders. Preferred Qualifications Experience with Palo Alto Networks security architecture and enterprise security controls . Experience integrating CASB, ZTNA, IAM, PAM, and MFA controls across enterprise environments. Experience with cloud identity and access security across Azure/Microsoft 365 environments. Experience developing remediation roadmaps for complex enterprise security environments. Experience with security governance, control ownership, and evidence-based validation. Relevant security certifications such as CISSP, CCSP, or vendor-specific Palo Alto/Microsoft certifications are a plus. Key Deliverables The successful candidate will be expected to: Establish and mobilize the CASB workstream during Week 1 . Produce actionable Prisma
CASB/DLP
policy and remediation designs . Identify and prioritize critical identity and privileged-access gaps . Establish clear ownership and remediation paths for high-priority findings. Define controlled remediation waves with appropriate testing and rollback considerations. Provide technical validation and sign-off support before production changes. Ensure remediation is supported by before/after evidence and documented validation . Minimize operational disruption while improving the organization's security posture. Success Measures CASB workstream is successfully mobilized in Week 1. Security remediation designs are practical, implementable, and aligned with business impact. High-priority identity and privileged-access gaps have clearly defined owners and remediation paths. Security changes are appropriately tested and validated before production deployment. Before/after evidence demonstrates successful remediation. Security improvements are delivered with minimal operational disruption .
Pay:
From $70.00 per hour Expected hours: 40.0 per week