> Markdown version of [/jobs/ext/2986048-iam-engineering-operations-lead-vp](https://www.wearedevelopers.com/jobs/ext/2986048-iam-engineering-operations-lead-vp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineering & Operations Lead, VP - **Company:** State Street - **Location:** Burlington, MA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $202,500.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Microsoft Azure, Client Access Licensing, Software as a Service, Cloud Engineering, Cyber Security, Information Systems, Databases, Domain Name System (DNS), Identity and Access Management, Lightweight Directory Access Protocols (LDAP), Log Analysis, Windows Servers, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Kusto Query Language, Software Systems, Data Logging, Remote Desktop Protocol (RDP), Cyberark, Grafana, Information Technology, Windows Security, SailPoint - **Published:** September 18, 2026 - **Apply:** https://www.jofdav.com/jobs/59769030-iam-engineering-operations-lead-vp ## About the Role * Bachelor's degree in computer science, engineering, information systems, cybersecurity, or a related technical field, or equivalent professional experience. * 10+ years of experience in IAM, directory services, cybersecurity engineering, infrastructure operations, or related technology functions, including experience leading engineers or operational teams. * Deep hands-on expertise with Active Directory, Microsoft Entra ID, Windows Server, Group Policy, identity lifecycle management, RBAC, LDAP, DNS, and hybrid identity integration. * Practical experience with SailPoint or another identity governance and administration platform, and CyberArk or another enterprise privileged access management platform. * Strong PowerShell automation skills; experience with KQL, Azure Log Analytics, security-event analysis, or comparable observability tools is highly desirable. * Experience governing service accounts, gMSA, non-human identities, password rotation, credential vaulting, access certifications, and segregation-of-duty controls. * Experience operating IAM services in a regulated financial-services, SaaS, or other high-control environment, including audit evidence and remediation responsibilities. * Demonstrated ability to manage production incidents, prioritize competing operational demands, communicate with senior stakeholders, and lead cross-functional delivery. * CyberArk Defender, Microsoft identity or Azure certification, CISSP, CISM, or comparable industry certification is preferred. ## Description The ideal candidate is a technically credible IAM leader who can direct engineers, resolve complex production access issues, translate enterprise standards into reliable operating practices, and modernize high-volume identity services through automation and measurable controls. The successful candidate will work closely with cybersecurity, infrastructure, cloud engineering, product, operations, risk, compliance, audit, client-facing teams, and enterprise IAM partners. Why is this role important to us. The team you will join is part of Charles River Development (CRD), which became part of State Street in 2018. CRD creates enterprise investment management software solutions for large institutions in institutional investment, wealth management, and hedge funds. Together we have created the first open front-to-back platform, State Street Alpha, launched in 2019. Identity services are foundational to the secure and resilient operation of client-facing SaaS environments. This role is accountable for dependable access administration, least-privilege enforcement, privileged-access controls, identity lifecycle operations, evidence-ready controls, and the transformation of legacy account and group-management practices. The role will also help reduce operational risk by expanding automation, improving service-account hygiene, strengthening segregation of duties, and moving suitable workloads toward passwordless authentication. What you will be responsible for IAM Operations Leadership and Service Delivery * Lead and mentor a global team of IAM engineers and administrators delivering identity operations, access administration, directory services, privileged access, and production support. * Own operational performance for IAM services, including service health, ticket queues, escalations, incident response, problem management, change execution, runbooks, and stakeholder communications. * Provide Level 3 technical leadership for complex authentication, authorization, directory, provisioning, and access issues affecting internal teams and client environments. * Set clear priorities, delivery plans, support coverage, quality expectations, and operational metrics; drive timely resolution while protecting security and control requirements. * Coordinate recurring working sessions with operational partners to resolve cross-team dependencies and improve end-to-end access request fulfillment. Directory Services, Entra ID, and Access Administration * Engineer, administer, and support enterprise Active Directory and Microsoft Entra ID environments, including users, groups, organizational units, Group Policy, directory synchronization, connected organizations, and privileged roles. * Lead joiner, mover, and leaver processes and ensure access is provisioned, changed, disabled, or removed through approved workflows and within required service levels. * Design and maintain role-based access control models, group structures, entitlement mappings, and least-privilege patterns for SaaS operational and client-support use cases. * Perform and oversee access fulfillment through SailPoint and approved ticketing workflows, including remediation of failed or manually fulfilled provisioning activities. * Partner with infrastructure and application teams on directory integrations, authentication patterns, domain migrations, and identity-related production changes. Privileged Access and Segregation of Duties * Operate and expand privileged access management using CyberArk, Azure PIM, and approved enterprise controls for administrative, database, RDP, service, and emergency access. * Ensure privileged access is time-bound where required, supported by approved incident or change records, appropriately authorized, logged, monitored, and periodically reviewed. * Maintain separation between access administration, approval, system administration, and functional access; identify, escalate, and remediate segregation-of-duty conflicts. * Coordinate onboarding of privileged accounts, safes, access groups, and client-agnostic operational groups into approved PAM solutions. * Support break-glass and emergency-access processes, including evidence, review, and post-use validation. Service Account Governance and Passwordless Modernization * Lead governance and operational controls for service and other non-human accounts, including inventory, ownership, naming, organizational-unit placement, password age, vaulting, certification, and decommissioning. * Drive phased migration of suitable service accounts to group Managed Service Accounts (gMSA) or other approved passwordless and key-based authentication patterns. * Coordinate password-rotation notifications, escalations, change execution, exception handling, and evidence retention for all internal and client owned non-human accounts. * Partner with SaaS Operations, Product Engineering, Global Operations, and client-facing teams to address dependencies that prevent secure rotation or passwordless conversion. * Improve monitoring for account changes, stale identities, interactive-logon exposure, and other service-account hygiene risks. Access Governance, Certifications, and Client Access Controls * Lead periodic user, privileged, group, guest, and non-human account reviews across CRD SaaS domains and identity platforms. * Develop scalable methods to analyze direct and nested group membership, cross-domain access, client-domain mismatches, dormant access, and excessive entitlements. * Ensure remediation from access reviews is completed through approved workflows and that evidence supports internal control, SOC, client, and regulatory requirements. * Partner with client-facing teams to establish defensible approval patterns for production and non-production access, including start and end dates, business justification, and risk acceptance where required. * Maintain clear procedures for guest-account inactivity, access recertification, leaver processing, and client identity segregation. Automation, Engineering, and Continuous Improvement * Develop and maintain PowerShell and related automation for identity reporting, lifecycle activities, group analysis, access validation, inactive-account controls, and evidence generation. * Reduce manual effort and operational risk by embedding validation, exception handling, logging, and human approval gates into IAM workflows. * Use Azure Log Analytics, KQL, Windows security events, and other monitoring capabilities to investigate account activity and support proactive control monitoring. * Improve IAM architecture and operating practices through maturity assessments, gap analysis, root-cause reviews, roadmap development, and measurable remediation plans. * Maintain accurate SOPs, procedures, knowledge articles, support documentation, and technical control narratives. Risk, Audit, Compliance, and Reporting * Serve as an IAM control owner or delegate for applicable access administration, privileged access, segregation-of-duty, service-account, and identity lifecycle controls. * Support internal audit, external audit, regulatory examinations, client due diligence, and control testing through complete, accurate, and timely evidence. * Identify control gaps and operational risks, define sustainable corrective actions, track remediation, and escalate issues through established governance channels. * Translate enterprise IAM policies and technical standards into actionable CRD operational requirements and implementation plans. * Provide concise executive reporting on service performance, access risk, control effectiveness, audit commitments, automation progress, and modernization outcomes. ## Related Videos - [5 steps for running a Kubernetes environment at scale](https://www.wearedevelopers.com/videos/88-5-steps-for-running-a-kubernetes-environment-at-scale) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [All your telemetry data from any source in one place](https://www.wearedevelopers.com/videos/57-all-your-telemetry-data-from-any-source-in-one-place) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Keycloak case study: Making users happy with service level indicators and observability](https://www.wearedevelopers.com/videos/1599-keycloak-case-study-making-users-happy-with-service-level-indicators-and-observability) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)