Director, IAM Engineering Lead

CLS Group

Woodbridge Township (NJ)

Hybrid

USD 200,000 - 230,000

Full time

3 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Variable compensation
401(k) match
Comprehensive benefits

Job summary

CLS Group is seeking an IAM Engineering Lead to steer the design, implementation, and governance of a comprehensive identity and access management program across workforce, customers, and machines. This hybrid executive/technical role bridges security, compliance, and business enablement within a regulated financial services context.

You will scale IAM onboarding, automate provisioning and access reviews, and expand PAM coverage to include devices and cloud infrastructure, leveraging AI-assisted

Qualifications

  • Senior leadership in security engineering in complex, regulated environments.
  • Delivery of large-scale security platforms end-to-end.
  • Deep experience identity & privileged access engineering.
  • Strong regulatory/audit engagement and assurance.

Responsibilities

  • Lead design, implementation, and governance of an IAM program.
  • Scale IAM across workforce, customers, and machine identities.
  • Expand PAM scope to network devices and non-traditional endpoints.
  • Automate provisioning and access reviews.
  • Deploy AI-assisted automation to reduce manual burden while ensuring auditability.
  • Onboard devices and infrastructure accounts to PAM and implement JEP/JIT controls.

Skills

Senior leadership
Security engineering
IAM engineering
Regulatory/audit experience

Tools

SailPoint IGA
Delinea PAM
AWS IAM

Job description

CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.

Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.

CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.

Job information:
  • Functional title – IAM Engineering Lead
  • Department - CISO
  • Report to – Head of Security Architecture, Design and Engineering
  • Expected full-time salary range between $200,000 - $230,000 + variable compensation + 401(k) match + benefits.

Note: Disclosure as required by NY Pay Transparency Law of the expected salary compensation range for this role.

What you will be doing:

As Head of IAM Engineering, you will lead the strategic design, implementation, and governance of a comprehensive identity and access management program that protects CLS Services' most critical asset: trusted digital identity. This is a hybrid executive and technical role that bridges security, compliance, and business enablement in a highly regulated financial services environment.

You will be responsible for architecting and scaling identity systems across our workforce, customers, and machine identities—each with distinct risk profiles and regulatory demands. This includes accelerating onboarding of applications and infrastructure into our IGA platform, expanding our PAM scope to network devices and non-traditional endpoints, building a comprehensive secrets management capability, and embedding AI-assisted automation to reduce manual operational burden while maintaining security and auditability.

Key Responsibilities:
  • Scale application and infrastructure onboarding to IAG through a phased, iterative deployment strategy, prioritizing critical systems and expanding coverage over time to maximize early wins while managing complexity.
  • Automate provisioning and access reviews using IAG connectors, role-based access control (RBAC) frameworks, and AI-driven workflows to reduce manual errors and accelerate user lifecycle management.
  • Implement self-service capabilities and identity workflow automation to automate and accelerate onboarding to the IAG platform.
  • Maintain data quality and integration governance by establishing rigorous data cleansing practices, continuous syncing with authoritative HR systems, and monitoring to ensure accurate, consistent identity and entitlement data.
  • Where possible Leverage AI and machine learning to generate role recommendations, detect over-permissioning, and automate access certification workflows at scale.
  • Govern machine identities (workloads, services, future AI agents) through IAG lifecycle management, ensuring all identity types are managed through a unified access governance framework.
  • Deploy behavioral anomaly detection using AI/ML to identify unauthorized or suspicious IAM activities, including potential abuse by rogue AI agents operating at machine velocity.
  • Onboard critical device and infrastructure accounts to PAM, including network devices, databases, and cloud infrastructure, implementing just-enough-privilege (JEP) and just-in-time (JIT) access models to reduce standing privileges and blast radius.
  • Expand PAM scope beyond Linux/Windows to include network devices, databases, cloud infrastructure (AWS), and non-traditional endpoints (operational technology etc.) where applicable to CLS Services' infrastructure.
  • Where possible Implement JIT and zero standing privileges (ZSP) across PAM-managed resources, restricting privilege duration and scope to specific use cases and time-bound sessions.
AI-Assisted IAM Operations
  • Redistribute high-volume, low-risk IAM tasks to AI agents, such as routine provisioning, deprovisioning, access reviews, and anomaly detection, while maintaining human oversight, exception handling, and strategic decision-making.
  • Implement AI-driven intelligent recommendations for access reviews, vulnerability remediation, and role engineering to accelerate decision cycles and improve accuracy.
  • Design and monitor AI agent identity lifecycle management, including provisioning, fine-grained authorization, token monitoring, and continuous audit of AI agent activities to prevent privilege escalation or unauthorized data access.
Vendor and Technology Management
  • Negotiate and manage vendor relationships to ensure technical roadmaps align with CLS Services' strategy, support regulatory requirements, and deliver value.
Measurement and Governance
  • Define and track outcome-driven metrics aligned with business objectives, such as:
  • IGA onboarding cycle time and application/infrastructure coverage expansion
  • Reduction in identity-related security incidents and unauthorized access events
  • PAM scope expansion and just-in-time privilege adoption rates
  • User experience and self-service adoption metrics
  • AI recommendation accuracy and agent behaviour anomaly detection rates
Engineering Leadership & Operating Model
  • Build and lead a high-performing security engineering function, aligned to product-based delivery.
  • Help define the target operating model for security engineering, including platform ownership, DevSecOps integration, and automation-first principles.
  • Establish clear engineering standards, patterns, and reusable security services.
  • Experience with tooling selection, deployment and vendor management.
  • Integration of tooling with downstream and upstream systems
  • Platform Health Monitoring
  • Remediation Engineering
Stakeholder Engagement & Strategy
  • Work closely and partner with the ED, Head of Identity and Access Management.
  • Partner with CIO, CISO, heads of technology and senior business leaders to align security engineering initiatives with organizational priorities.
  • Work closely with the enterprise security architects and solution architects on control gaps, control maturity and business cases.
  • Translate risk and threat insights into practical engineering outcomes.
  • Manage vendor relationships and strategic technology partnerships.
What we’re looking for:
  • Senior leadership in security engineering / cyber engineering in complex, regulated environments (markets technology / investment banking / FMI strongly preferred).
  • Proven delivery of large-scale security platforms end-to-end (design → build → run), including multi-system integration.
  • Deep experience identity & privileged access engineering.
  • Strong track record of regulatory/audit engagement and evidence-based assurance.
  • Engineering mindset: able to go deep on architecture, automation, telemetry, and operational resilience.
  • Strategic thinker with the ability to translate vision into execution.
  • Strong communicator, able to influence at executive level.
  • Data-driven and outcome-focused, with a bias toward measurable security improvements.
  • Comfortable operating in fast-paced, evolving environments.
Desirable Skills and Experience
  • SailPoint IGA platform administration and customization (roles, policies, workflows, connectors)
  • Delinea PAM platform expertise (credential management, session recording, just-in-time workflows)
  • Cloud infrastructure security (AWS IAM)
  • Identity and access intelligence (IAI) or AI/ML analytics applied to IAM use cases.
Our commitment to employees:

We are a small company with a big mandate, so every person is essential to our success. We are also committed to employing and retaining the most talented and dedicated people.

What makes us interesting goes beyond our competitive salaries and great benefits. Our work environment is designed around quality outcomes, not output. The FX market would cease to function without our services, and we take pride in being responsible for keeping it running smoothly.

We are different from other financial institutions in that we have a flatter and more transparent structure, with accessible leadership. You will be seen, heard and empowered to develop your career.

We are a purpose-driven organization, with an inclusive culture that focuses on doing what is right. The well-being of our people is as important to us as the resilience of our systems. In addition to encouraging our people to ‘locate for your day,’ we run a range of initiatives that support a sense of belonging, as well as physical, emotional and mental well-being.

Our extensive benefits for employees typically include:

  • Vacation/annual leave: 25 days in UK/Asia + 3 life days, 23 in US + 3 life days
  • Private medical and dental cover and life insurance
  • Generous pension contributions in the UK and Asia; matching 401(k) in the US
  • ‘Locate for your day’ hybrid working - 2 days a week in office
  • Access to Discover – our learning platform with 1000+ courses from LinkedIn Learning
  • Paid parental leave / Coaching and support services
  • ‘Heads down days’ with no meetings on the last Friday of every month
  • Employee Networks (Black Employee Network, Parents & Caregivers Network, Pride Network, Sustainability Network, Veterans Network, Women’s Forum)
  • Social events
Awards:
  • The Sunday Times Best Places to Work 2023, 2024, 2025 / Big Company / The Sunday Times Awards
  • Third place in Britain’s Healthiest Workplace 2022 / Medium Company / Vitality Awards
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, Application Security Specialist
Vice President, Application Security Specialist

CLS-Group • Iselin (PA)

Hybrid
USD 140,000 - 180,000
Hybrid work model
Private medical insurance
401(k) match
+1
Assistant Vice President - Business Risk and Control
Assistant Vice President - Business Risk and Control

CLS-Group • Iselin (PA)

On-site
USD 125,000 - 145,000
401K match
Private medical insurance
Generous pension provision
+1
Staff IAM Engineer
Staff IAM Engineer

Ironclad • San Francisco (CA)

Hybrid
USD 160,000 - 190,000
Health coverage
Parental leave
401(k) plan
+2
Assistant Vice President, Test Analyst
Assistant Vice President, Test Analyst

CLS Group • Woodbridge Township (NJ)

Hybrid
USD 130,000 - 150,000
25 days vacation/annual leave + 3 life days
Private medical and dental cover
Generous pension and 401(k) contributions
+2
Staff IAM Engineer
Staff IAM Engineer

Ironclad, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 160,000 - 190,000
Health coverage for employees
Parental leave
Maven family forming support
+6
Senior IAM Engineer - (Entra ID/AD)
Senior IAM Engineer - (Entra ID/AD)

CLA (CliftonLarsonAllen) • Austin (TX)

On-site
USD 120,000 - 180,000
Health benefits
Wellness program
401k matching
Senior IAM Engineer - (Entra ID/AD)
Senior IAM Engineer - (Entra ID/AD)

CLA (CliftonLarsonAllen) • Houston (TX)

On-site
USD 120,000 - 170,000
Health benefits
Dental benefits
401k plan
Senior IAM Engineer - (Entra ID/AD)
Senior IAM Engineer - (Entra ID/AD)

CLA (CliftonLarsonAllen) • Charlotte (NC)

On-site
USD 110,000 - 150,000
Health insurance
Dental
Vision
+1
Senior IAM Engineer - (Entra ID/AD)
Senior IAM Engineer - (Entra ID/AD)

CLA (CliftonLarsonAllen) • Orlando (FL)

On-site
USD 110,000 - 160,000
Health benefits
401(k) retirement plan
Wellness programs
Identity and Access Management (IAM) Sr. Specialist (Cloud Security required)
Identity and Access Management (IAM) Sr. Specialist (Cloud Security required)

Koitecc Solutions • Boston (MA), Northern (KY)

On-site
USD 135,000 - 182,000
Industry-leading benefits
Annual discretionary incentive plan
Paid time off