> Markdown version of [/jobs/ext/2791929-head-of-information-security-identity-and-access-management](https://www.wearedevelopers.com/jobs/ext/2791929-head-of-information-security-identity-and-access-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security / Identity and Access Management - **Company:** Brown Brothers Harriman & Co. - **Location:** Jersey City, NJ, United States - **Experience:** Expert - **Salary:** $200,000.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Excel, Active Directory, User Authentication, Cyber Security, Data Governance, Disaster Recovery, Identity and Access Management, Information Security Management, Intrusion Detection Systems, Logical Security, Ping (Networking Utility), Microsoft PowerPoint, IBM Resource Access Control Facility, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Z/OS, Enterprise Data Management, SailPoint - **Published:** September 8, 2026 - **Apply:** https://bbh.wd5.myworkdayjobs.com/BBH/job/Jersey-City/Head-of-Information-Security---Identity-and-Access-Management_72631 ## About the Role * Minimum 15 years of experience in information security, including leadership of identity and access management programs * Deep expertise in: + Identity and Access Management + Privileged Access Management + Authentication technologies and protocols + Authorization models and entitlement management + Identity governance and lifecycle management + Cloud identity platforms and hybrid identity architectures * Strong understanding of: + MFA, FIDO2 and modern authentication standards + Microsoft Entra ID, Active Directory, Sailpoint, Ping + Zero Trust security principles + Least privilege access models + Just-in-Time (JIT) access + Just-Enough-Access (JEA) * Familiarity with DFS Part 500, NIST Cybersecurity Framework, ISO 27001/27002, FFIEC guidance and other relevant industry standards * Experience leading enterprise-wide transformations involving IAM modernization and security control enhancements * Demonstrated ability to influence executive stakeholders and drive organizational change * Experience with SailPoint, One Identity Safeguard (OIS), mainframe system, mainframe security program (z/OS and RACF) * Excellent analytical and communication skills * Strong PowerPoint and Excel skills ## Description Position Summary: The Head of Information Security / Identity and Access Management will serve as a strategic and technically deep leader responsible for the execution and continuous improvement of our enterprise-wide information Security Management (ISM) team within the Protect Pillar. This leader will be responsible for ensuring that identity is treated as a core security control and will oversee capabilities spanning authentication, authorization, privileged access management, identity governance, access certification, and modern Zero Trust principles. The ideal candidate combines strong technical expertise with executive leadership experience and has a proven track record of building and operating identity-centric security programs within highly regulated environments, preferably in financial services. The ideal candidate will also have experience transforming and modernizing identity operations through automation, workflow redesign and implementing scalable processes that improve effectiveness, efficiency, and user experience and serving as a trusted advisor to drive a security-first culture focused on protecting people, systems, data and critical assets. This role reports to the Head of the Protect Pillar in Systems. The Protect Pillar is a unique BBH-construct designed for clear, centralized and coordinated accountability: to protect against physical and logical security risks; to safeguard stakeholder assets; and to detect, prepare for, and respond effectively to security events. To that end, the Protect Pillar encompasses the following areas: * Cybersecurity; * Enterprise Data Protection and Data Governance; * Information Security Management ("ISM"); * Business Continuity / Disaster Recovery; * Protect Program, Strategy and Automation; and * Global Security (Physical Security)., * Define and execute the enterprise Identity and Access Management strategy aligned with business objectives, security priorities, and regulatory requirements * Establish and implement a multi-year vision and roadmap to further mature identity security, authentication, authorization, privileged access and identity governance capabilities * Assess and lead enhancements relating to: + Identity lifecycle management + Authentication capabilities + Authorization and entitlement management + Privileged Access Management + Identity Governance and Administration + Role-based and attribute-based access controls * Evaluate access protocols and ensure protocols are consistent with least privilege, just-in-time (JIT), just-enough (JEA) as appropriate to the level of access * Ensure appropriate authorization controls and entitlement management across cloud, on-premise and non-human IDs * Lead the modernization of identity governance processes. Identify opportunities to eliminate manual processes and improve the user experience while maintaining strong security and regulatory compliance * Develop and implement a roadmap for modernizing identity governance and administration capabilities, with particular focus on lifecycle management, attestations, access reviews, and privileged access workflows * Partner with technology and business stakeholders to redesign legacy processes and implement scalable solutions that support organizational growth and evolving security requirements * Develop and execute a sustainable workforce strategy that attracts, develops and retains talent with skills needed to support a modern identity security program and evolving technologies * Oversee and coordinate responses to Internal Audit, external audit / SOC1/SOC2 exams, regulatory reviews, client due diligence and other assurance activities relating to identity and access management ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The top 200 passwords of 2024 can be cracked in less than a second](https://www.wearedevelopers.com/magazine/502-the-top-200-passwords-of-2024-can-be-cracked-in-less-than-a-second) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)