Dir, Identity & Access Mgmt (IAM)
Role details
Job location
Tech stack
Job description
The Director of Identity & Access Management (IAM) is accountable for the delivery, effectiveness, and ongoing maturity of enterprise workforce identity, secrets, and certificate management platforms. This role ensures secure, reliable, and automated access to systems, applications, and collaboration tools across a hybrid cloud, multi affiliate environment.
Aligned to the Infrastructure & Operations Platform vision, this leader transforms legacy, fragmented and manual identity practices into standardized, policy driven, and automated enterprise services that reduce operational toil, improve resilience, and strengthen regulatory compliance. The role partners closely with Platform Engineering, Security, HR, and Application teams to ensure identity related capabilities are engineered as scalable, consumable, and reliable platforms.
This position drives both technical modernization and enterprise change, standardizing identity practices across historically decentralized affiliates while balancing local regulatory and operational needs., 1. Enterprise IAM Strategy & Transformation
- Define and execute a multiyear IAM modernization roadmap aligned with I&O Platform priorities for reliability, automation, toil reduction, and cost efficiency.
- Lead the transition from affiliatespecific identity practices to a standardized enterprise workforce identity platform.
- Drive organizational and cultural change required to adopt consistent identity standards across decentralized affiliates.
- Establish workforce identity, secrets, and certificate services as foundational shared capabilities supporting enterprise operations and modernization initiatives.
- Workforce Identity, Secrets & Certificate Platform Ownership
- Accountable for enterprise workforce identity services, including:
- Identity lifecycle management (Joiner / Mover / Leaver)
- Directory services (e.g., Entra ID, Active Directory)
- IAM services (Saviynt, SailPoint, MIM)
- Single SignOn (SSO) and MultiFactor Authentication (MFA)
- Privileged access management (PAM)
- Own enterprise secrets and certificate management platforms as they relate to workforce identity and shared enterprise services, including lifecycle management, rotation, availability, and monitoring.
- Establish enterprise standards and guardrails for secrets and certificate usage in partnership with Platform Engineering for workload and runtime use cases.
- Ensure HRdriven identity is the authoritative source for workforce provisioning and deprovisioning.
- Ensure platforms are engineered for high availability, disaster recovery, and operational continuity.
- EngineeringFirst Identity & Automation
- Drive APIfirst and eventdriven identity architecture enabling integration with enterprise platforms and developer workflows.
- Promote infrastructureascode and policyascode approaches for identity, access, secrets, and certificates.
- Integrate IAM capabilities into CI/CD pipelines and application delivery processes where appropriate.
- Replace ticketdriven operations with automated, selfservice workflows.
- Define and track metrics such as timetoprovision, automation coverage, and reduction in manual access handling.
- Governance, Risk & Control Effectiveness
- Design and operate scalable identity governance capabilities including access certifications, role governance, and segregationofduties controls.
- Ensure IAM capabilities support SOX, NERCCIP, and other regulatory requirements.
- Accountable for the design, effectiveness, and continuous improvement of workforce identity access controls.
- Partner with Security and Internal Audit on control testing, regulatory examinations, and remediation activities.
- Platform Operating Model & Affiliate Alignment
- Establish a centralized IAM platform with federated execution across affiliates.
- Align affiliates to enterprise identity, secrets, and certificate standards through policies, patterns, and approved configurations.
- Serve as the primary IAM point of integration for leadership, HR, and application owners.
- Partnership with Platform Engineering
- Partner with Platform Engineering on shared identity architecture principles and integration standards.
- Clearly define and maintain ownership boundaries:
- IAM owns workforce identity and enterprise secrets/certificate platforms
- Platform Engineering owns workload and runtime identity
- Coordinate roadmaps and architectural decisions to prevent fragmentation.
- Operational Resilience & Incident Support
- Participate in major incident response when identityrelated failures impact critical systems or restoration activities.
- Ensure incidents result in rootcause analysis and durable platform improvements.
- Team Leadership & Capability Development
- Lead and evolve an IAM organization currently consisting of engineers and administrators to support modern IAM and maturing platform capabilities.
- Shift team culture from operationscentric execution to platform ownership and engineering excellence.
- Build skills in automation, integration, and modern workforce identity practices.
- Own IAM vendor relationships, budgets, and investment planning.
Requirements
- Bachelor's degree in information systems, computer science or related technical field; or equivalent work experience.
- 10+ years in identity, security, or enterprise infrastructure
- 5+ years leading IAM, security, or platform teams in complex enterprises
- Proven success modernizing IAM in federated or multientity organizations
- Experience in regulated or criticalinfrastructure environments preferred
Technical & Domain Expertise
- Workforce identity lifecycle management
- Cloud and hybrid directory platforms
- SSO, MFA, PAM, and access governance
- Secrets and certificate management platforms
- Identity integration patterns (APIs, SCIM, eventdriven architectures)
- Infrastructureascode and automation concepts
- Working knowledge of Zero Trust principles
Experience with modern IAM and access platforms such as Entra ID, SailPoint, Saviynt, CyberArk, HashiCorp Vault, or similar is preferred.