A leading financial services organization is seeking a Director of IAM Engineering to lead the modernization of its enterprise identity and access management environment. This position combines deep IAM engineering expertise with architecture, technical strategy, transformation leadership, and executive-level stakeholder engagement.
The Director will define the future-state roadmap for core identity platforms, expand enterprise application integration, improve identity governance and privileged-access capabilities, and introduce greater automation across IAM operations.
This is a technical leadership position for someone who can operate strategically while remaining close enough to the technology to guide complex engineering and architecture decisions.
Responsibilities
- Define and execute the technical strategy and roadmap for enterprise IAM platforms and services.
- Lead modernization across identity governance, authentication, authorization, privileged access, directories, and identity lifecycle management.
- Expand enterprise application integration with SailPoint and related identity-governance technologies.
- Provide technical direction for SailPoint architecture, connectors, workflows, custom rules, and third-party integrations.
- Guide strategy and implementation across CyberArk, PAM, SSO, enterprise directories, and access-control technologies.
- Establish scalable approaches to provisioning, deprovisioning, access certification, entitlement management, and segregation of duties.
- Lead architecture reviews, proofs of concept, product evaluations, integration planning, and enterprise deployments.
- Identify practical opportunities to use AI and automation to improve IAM efficiency and controls.
- Reduce manual identity processes and improve the reliability and scalability of IAM operations.
- Establish IAM engineering standards, governance practices, and repeatable operational processes.
- Partner with Security, Engineering, Infrastructure, Operations, application teams, business stakeholders, and vendors.
- Guide the resolution of complex identity, entitlement, authentication, and authorization issues.
- Mentor IAM engineers and provide technical direction to internal and external resources.
- Communicate IAM strategy, architecture, priorities, and recommendations to senior leadership.
- Establish metrics for IAM coverage, automation, operational efficiency, and control effectiveness.
Role Requirements
- 8+ years of experience in IAM, identity engineering, security engineering, or a related discipline.
- At least 5 years of experience with enterprise identity-management technologies.
- Experience with SailPoint connectors, workflows, custom rules, identity lifecycle processes, and third-party integrations.
- Demonstrated experience integrating enterprise applications into an identity-governance platform.
- Strong knowledge of CyberArk or another enterprise privileged-access-management platform.
- Strong understanding of SSO, authentication, authorization, RBAC, least privilege, segregation of duties, and access governance.
- Experience with Active Directory, LDAP, or comparable enterprise directory technologies.
- Experience owning complex IAM implementations and supporting production identity environments.
- Ability to evaluate architecture and troubleshoot complex identity and access problems.
- Demonstrated ownership of an IAM modernization or transformation initiative.
- Experience developing IAM strategies, architecture standards, and technical roadmaps.
- Strong executive communication and stakeholder-management capabilities.
- Ability to influence engineering teams, business stakeholders, vendors, and senior leadership.
- Ability to work onsite in Dallas-Fort Worth three days per week.
Nice to Have
- AWS identity or cloud-security experience.
- Oracle Universal Directory experience.
- PKI and certificate-management knowledge.
- Experience introducing AI or intelligent automation into IAM or security operations.
- Experience measuring and improving IAM operational efficiency.
- CISSP, CIAM, ITIL, or another relevant identity or security certification.
- Banking, financial-services, or similarly regulated-enterprise experience.