Director, IAM Engineering Lead

Cls Group

Iselin (PA)

Hybrid

USD 180,000 - 230,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid working
Private medical insurance
Pension provision/401K match
Generous paid time off

Job summary

CLS is seeking an IAM Engineering Lead in Iselin, NJ, reporting to the Head of Security Architecture. This hybrid executive and technical role focuses on designing, implementing, and governing a comprehensive identity and access management program across workforce, customers, and machines.

You will scale onboarding to IAG, expand PAM, embed AI-assisted automation, and drive data-driven governance while balancing risk, security, and business enablement in a highly regulated financial services

Qualifications

  • Senior leadership experience in security engineering in regulated environments.
  • Proven delivery of large-scale security platforms end-to-end.
  • Deep expertise in identity & privileged access engineering.
  • Strong track record with regulatory audits and assurance.
  • Engineering mindset with architecture, automation, telemetry focus.
  • Strategic thinker who can translate vision into execution.
  • Strong communicator able to influence executives.
  • Data-driven with a focus on measurable security improvements.
  • Experience in fast-paced, evolving environments.

Responsibilities

  • Scale IAM onboarding and RBAC across systems using phased deployment.
  • Automate provisioning, access reviews, and AI-driven workflows.
  • Implement self-service identity capabilities and governance.
  • Ensure data quality with HR system integration and auditability.
  • Leverage AI/ML for role recommendations and anomaly detection.
  • Govern machine identities and PAM across networks and devices.
  • Deploy AI-assisted anomaly detection for IAM activities.
  • Onboard devices and infrastructure accounts to PAM with JIT access.
  • Expand PAM scope to cloud, databases, and non-traditional endpoints.
  • Establish zero standing privileges and reduced blast radius.

Job description

About CLS:

CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.

Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.

CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.

Our ambition to make a positive difference starts with our people. Our values underpin everything that we do at CLS and define our working environment:

  • Pivotal purpose
  • Trusted guardian
  • Targeted innovation
  • Facilitate connections
  • Delivering excellence
  • Inclusive culture
Job information:
  • Functional title – IAM Engineering Lead
  • Department - CISO
  • Corporate level - Director
  • Report to – Head of Security Architecture, Design and Engineering
  • Location – Iselin, New Jersey. Onsite 2 days per week
What you will be doing:

As Head of IAM Engineering, you will lead the strategic design, implementation, and governance of a comprehensive identity and access management program that protects CLS Services’ most critical asset: trusted digital identity. This is a hybrid executive and technical role that bridges security, compliance, and business enablement in a highly regulated financial services environment.

You will be responsible for architecting and scaling identity systems across our workforce, customers, and machine identities—each with distinct risk profiles and regulatory demands. This includes accelerating onboarding of applications and infrastructure into our IGA platform, expanding our PAM scope to network devices and non-traditional endpoints, building a comprehensive secrets management capability, and embedding AI-assisted automation to reduce manual operational burden while maintaining security and auditability.

Key Responsibilities:
  • Scale application and infrastructure onboardingto IAG through a phased, iterative deployment strategy, prioritizing critical systems and expanding coverage over time to maximize early wins while managing complexity.
  • Automate provisioning and access reviewsusing IAG connectors, role-based access control (RBAC) frameworks, and AI-driven workflows to reduce manual errors and accelerate user lifecycle management.
  • Implement self-service capabilitiesand identity workflow automation to automate and accelerate onboarding to the IAG platform.
  • Maintain data quality and integration governanceby establishing rigorous data cleansing practices, continuous syncing with authoritative HR systems, and monitoring to ensure accurate, consistent identity and entitlement data.
  • Where possible Leverage AI and machine learning to generate role recommendations, detect over-permissioning, and automate access certification workflows at scale.
  • Govern machine identities (workloads, services, future AI agents) through IAG lifecycle management, ensuring all identity types are managed through a unified access governance framework.
  • Deploy behavioral anomaly detection using AI/ML to identify unauthorized or suspicious IAM activities, including potential abuse by rogue AI agents operating at machine velocity.
  • Onboard critical device and infrastructure accounts to PAM, including network devices, databases, and cloud infrastructure, implementing just-enough-privilege (JEP) and just-in-time (JIT) access models to reduce standing privileges and blast radius.
  • Expand PAM scope beyond Linux/Windowsto include network devices, databases, cloud infrastructure (AWS), and non-traditional endpoints (operational technology etc.) where applicable to CLS Services’ infrastructure.
  • Where possible Implement JIT and zero standing privileges (ZSP)across PAM-managed resources, restricting privilege duration and scope to specific use cases and time-bound sessions.
AI-Assisted IAM Operations
  • Redistribute high-volume, low-risk IAM tasks to AI agents, such as routine provisioning, deprovisioning, access reviews, and anomaly detection, while maintaining human oversight, exception handling, and strategic decision-making.
  • Implement AI-driven intelligent recommendations for access reviews, vulnerability remediation, and role engineering to accelerate decision cycles and improve accuracy.
  • Design and monitor AI agent identity lifecycle management, including provisioning, fine-grained authorization, token monitoring, and continuous audit of AI agent activities to prevent privilege escalation or unauthorized data access.
Vendor and Technology Management
  • Negotiate and manage vendor relationships to ensure technical roadmaps align with CLS Services’ strategy, support regulatory requirements, and deliver value.
Measurement and Governance
  • Define and track outcome-driven metricsaligned with business objectives, such as:
    • IGA onboarding cycle time and application/infrastructure coverage expansion
    • Reduction in identity-related security incidents and unauthorized access events
    • PAM scope expansion and just-in-time privilege adoption rates
    • User experience and self-service adoption metrics
    • AI recommendation accuracy and agent behaviour anomaly detection rates
Engineering Leadership & Operating Model
  • Build and lead a high-performing security engineering function, aligned to product-based delivery.
  • Help define the target operating model for security engineering, including platform ownership, DevSecOps integration, and automation-first principles.
  • Establish clear engineering standards, patterns, and reusable security services.
  • Experience with tooling selection, deployment and vendor management.
  • Integration of tooling with downstream and upstream systems
  • Tooling automation development
  • Continuous Tooling Optimization
  • Platform Health Monitoring
  • Remediation Engineering
  • Resiliency Engineering
Stakeholder Engagement & Strategy
  • Work closely and partner with the ED, Head of Identity and Access Management.
  • Partner with CIO, CISO, heads of technology and senior business leaders to align security engineering initiatives with organizational priorities.
  • Work closely with the enterprise security architects and solution architects on control gaps, control maturity and business cases.
  • Translate risk and threat insights into practical engineering outcomes.
  • Manage vendor relationships and strategic technology partnerships.
What we’re looking for:
  • Senior leadership in security engineering / cyber engineering in complex, regulated environments (markets technology / investment banking / FMI strongly preferred).
  • Proven delivery of large-scale security platforms end-to-end (design → build → run), including multi-system integration.
  • Deep experience identity & privileged access engineering.
  • Strong track record of regulatory/audit engagement and evidence-based assurance.
  • Engineering mindset: able to go deep on architecture, automation, telemetry, and operational resilience.
  • Strategic thinker with the ability to translate vision into execution.
  • Strong communicator, able to influence at executive level.
  • Data-driven and outcome-focused, with a bias toward measurable security improvements.
  • Comfortable operating in fast-paced, evolving environments.
Desirable Skills and Experience
  • SailPoint IGA platform administration and customization(roles, policies, workflows, connectors)
  • Delinea PAM platform expertise(credential management, session recording, just-in-time workflows)
  • Cloud infrastructure security(AWS IAM)
  • Identity and access intelligence (IAI) or AI/ML analytics applied to IAM use cases.
Professional qualifications / certifications
  • Extensive experience in security engineering and architecture (~10 years), including ~5-7+ years in a senior leadership role.
  • Experience in:
    • Working in highly regulated operations and complex organizational structures.
    • Reporting to senior leadership supporting executive level decision-making and prioritization.
    • Engaging in complex governance, contributing to multi-layered committees or forums.
  • Understand, interpret and apply regulatory requirements, compliance and industry standards.
Our commitment to employees:

At CLS, we celebrate inclusion and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including:

  • Holiday - UK/Asia: 25 holiday days and 3 ‘life days’ (in addition to bank holidays). US: 23 holiday days.
  • 2 paid volunteer days so that you can actively support causes within your community that are important to you.
  • Generous parental leave policies to ensure you can enjoy valuable time with your family.
  • Parental transition coaching programmes and support services.
  • Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
  • Employee Networks (including our Women’s Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about inclusivity.
  • Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don’t.
  • Active support of flexible working for all employees where possible.
  • Monthly ‘Heads Down Days’ with no meetings across the whole company.
  • Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
  • Private medical insurance and dental coverage.
  • Social events that give you opportunities to meet new people and broaden your network across the organisation.
  • Annual flu vaccinations.
  • Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
  • Discounted Gym membership – Complete Body Gym Discount/Sweat equity program for US employees.
  • All employees have access to Discover – our comprehensive learning platform with 1000+ courses from LinkedIn Learning.
  • Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, IAM Engineering Lead
Director, IAM Engineering Lead

CLS Group • Woodbridge Township (NJ)

Hybrid
USD 200,000 - 230,000
Variable compensation
401(k) match
Comprehensive benefits
Data Security Director
Data Security Director

CLS-Group • Iselin (PA)

On-site
USD 225,000 - 235,000
Hybrid working
Private medical insurance
Dental coverage
+4
Vice President, Cyber & Network Security Engineer
Vice President, Cyber & Network Security Engineer

CLS Group • Woodbridge Township (NJ)

On-site
USD 170,000 - 190,000
401(k) match
Benefits
Vice President, Cyber Business Management
Vice President, Cyber Business Management

CLS Group • Woodbridge Township (NJ)

Hybrid
USD 165,000 - 185,000
Hybrid working
Private medical insurance
401K match
+2
Assistant Vice President, SOC Analyst
Assistant Vice President, SOC Analyst

CLS Group • Woodbridge Township (NJ)

On-site
USD 135,000 - 160,000
401(k) match
Hybrid working
Medical and dental cover
Assistant Vice President - Business Risk and Control
Assistant Vice President - Business Risk and Control

CLS-Group • Iselin (PA)

On-site
USD 125,000 - 145,000
401K match
Private medical insurance
Generous pension provision
+1
Vice President, Internal Audit – Business Audit
Vice President, Internal Audit – Business Audit

Cls Group • Woodbridge Township (NJ)

Hybrid
USD 180,000 - 210,000
Hybrid working
401(k) match
Private medical & dental insurance
+2
Associate, Due Diligence
Associate, Due Diligence

Cls Group • New Jersey

On-site
USD 81,000 - 93,000
Hybrid working
401K match
Private medical insurance
+2
Director, Remediation Management
Director, Remediation Management

Cls Group • Iselin (PA)

On-site
USD 210,000 - 240,000
Hybrid working
Private medical insurance
401K match
+1
Associate, Operations, Due Diligence
Associate, Operations, Due Diligence

CLS Group • Woodbridge Township (NJ)

Hybrid
USD 81,000 - 93,000
Hybrid working - 2 days in office
401(k) match
Comprehensive benefits