Logo
TKO

Global Identity Architect

TKO, Stamford

Save Job

3 days ago Be among the first 25 applicants

This range is provided by TKO. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.

Base pay range

$150,000.00/yr - $160,000.00/yr

OVERVIEW

The Identity Architect will serve as the technical lead for designing, building, and delivering novel and greenfield enterprise identity services as part of M&A lifecycle and other strategic programs. This role is responsible for architecting a secure, scalable, and operationally sound Okta, Microsoft Entra ID, on-premises Active Directory, and identity access governance & automated identity lifecycle management to support the TKO operations for global brands such as UFC, WWE, IMG, OLE, PBR, and more. The architect will ensure seamless integration with cloud platforms, identity providers, and core business systems while maintaining alignment with security, compliance, and operational requirements.

TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world’s premier bull riding organization. Together, these properties reach 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.

KEY RESPONSIBILITIES

  • Lead the design and execution of identity services across Okta, Active Directory, and Microsoft Entra ID, supporting the stand-up of TKO’s greenfield IT environment.
  • Lead and drive complex cross-enterprise identity migrations as part of M&A or divestiture programs, leveraging tools such as Quest Migration Manager, Quest OnDemand Migration (ODM), BitTitan MigrationWiz, or equivalent platforms to ensure secure, phased transitions across forests, tenants, and domains.
  • Architect and deploy secure, scalable directory structures, trust relationships, and authentication flows across on-prem and cloud systems.
  • Own configuration and integration of Okta Identity Cloud as the primary identity provider, including SSO, MFA (e.g., Verify + Fastpass), SCIM provisioning, API provisioning, and directory integrations.
  • Design and operate Identity Lifecycle Management (ILM) workflows integrated with Workday, ensuring automated joiner/mover/leaver processes are secure, scalable, and auditable.
  • Architect, lead, and drive the development of automated identity lifecycle workflows using Workday, Okta Workflows, and Okta Identity Governance, including access certifications and entitlement reviews.
  • Design and implement AD forest/domain strategy, including OU structure, GPO hierarchy, DNS, and replication models.
  • Manage and maintain Microsoft Entra ID joined devices, with accountability for device compliance, enrollment, and configuration policies via Microsoft Intune.
  • Oversee synchronization and federation patterns between Active Directory (AD), Okta, and Entra ID, ensuring high availability and alignment with security and compliance requirements.
  • Ensure architectural decisions and implementations meet or exceed identity governance requirements aligned with SOX, PCI DSS, and other relevant compliance standards.
  • Collaborate with Infrastructure, Security, and Application teams to ensure frictionless integration with enterprise systems and SaaS platforms.
  • Proactively identify risks and blockers in identity architecture or execution, and drive solutions forward.
  • Maintain tight alignment with TKO stakeholders and cross-functional delivery teams.
  • Occasionally, you may be requested to travel and work long days and weekends during critical change events to support identity orchestration and migration efforts architecturally.

CERTIFICATIONS

  • Okta Certified Developer / Okta Certified Professional / Okta Certified Consultant
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure Solutions Architect Expert
  • Certified Information Systems Security Professional (CISSP) or GIAC certifications (IAM/GRC)
  • Training or certification in Zero Trust Architecture, PIM/PAM Design, IAM Governance

SKILLS & ABILITIES

  • Architectural Leadership: Able to design, articulate, and defend identity architecture decisions across hybrid environments (Okta, AD, Entra ID).
  • Extreme Ownership: adopts the leadership philosophy that means taking accountability for failures, setbacks, and results within your sphere of influence, even those caused by others on your team.
  • Execution-Focused: Operates with urgency and accountability; drives deliverables forward without constant oversight.
  • Cross-Platform Expertise: Strong understanding of identity federation, SCIM provisioning, authentication protocols (SAML, OIDC, OAuth), and lifecycle automation.
  • Analytical Thinking: Able to break down complex technical problems and deliver practical, scalable solutions.
  • Documentation Excellence: Produces clear, detailed, and professional HLDs, LLDs, runbooks, and process diagrams.
  • Mentorship & Collaboration: Capable of guiding junior engineers and collaborating effectively across infrastructure, security, and application teams.
  • Communication: Strong written and verbal communication skills; able to influence stakeholders and explain complex concepts to technical and non-technical audiences.
  • Comfort with Ambiguity: Thrives in environments where direction is still forming and able to bring structure and clarity to grey areas.
  • Resilience: Maintains focus and composure under pressure in fast-moving, high-visibility environments.
  • Customer Orientation: Keeps business impact front of mind; balances technical excellence with pragmatic execution

Required:

  • Bachelor’s degree in computer science, Information Technology, Engineering, or a related field, or equivalent hands-on experience.
  • 8+ years of experience in identity and access management, enterprise infrastructure
  • Demonstrated experience leading identity architecture and delivery for large-scale, hybrid environments.

Hands-on, expert-level proficiency with:

  • Okta Identity Cloud (SSO, MFA, Workflows, Lifecycle Management, Identity Governance)
  • Microsoft Entra ID / Azure AD (hybrid join, conditional access, identity federation)
  • Development and operationalization of an automated identity lifecycle management (ILM) processes, using Workday, Okta Workflows, Active Directory, Microsoft Entra ID / Azure AD, and Identity Governance tools.
  • Successful implementation of a greenfield Okta environment, including directory integration, policy configuration, and application onboarding.
  • Experience supporting identity and access projects in regulated industries with alignment to compliance frameworks such as SOX, PCI DSS, or NIST.
  • End-to-end participation in enterprise IAM modernization efforts such as privileged access management (PAM), privileged identity management (PIM), and phishing-resistant MFA (e.g., Microsoft Passkey, FastPass, Yubikey, FIDO2).
  • Cross-functional leadership in M&A or divestiture-driven identity migrations, including TSA exit planning.

TKO unites and brings people together in our love of sport, culture, and entertainment. We understand this can only be accomplished when we lead with a lens of diversity, equity, and inclusion in everything we do. As a global company that drives culture, we strive to reflect the world’s diverse voices.

TKO is an equal opportunities employer and encourages applications from suitably qualified and eligible candidates regardless of sex, race, disability, age, sexual orientation, or religion or belief.

Seniority level

  • Seniority level

    Mid-Senior level

Employment type

  • Employment type

    Full-time

Job function

  • Job function

    Information Technology
  • Industries

    Entertainment Providers and Spectator Sports

Referrals increase your chances of interviewing at TKO by 2x

Sign in to set job alerts for “Architect” roles.

White Plains, NY
$60,000.00
-
$100,000.00
3 days ago

Planning, Design and Construction Project Manager - Architect

Bronx, NY
$110,000.00
-
$127,000.00
3 weeks ago

Managing Architect - A (A/E In-House Design Studio)

Planning, Design and Construction Project Manager - Landscape Architect

Bronx, NY
$110,000.00
-
$127,000.00
3 weeks ago

Facility Architect Assessor (ACP Sponsor Engagement)

White Plains, NY $127,446.73 - $191,159.28 5 months ago

Facility Architect Assessor (ACP Sponsor Engagement)

Stamford, CT $106,600 - $186,500 1 week ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr