About AbbVie
AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people’s lives across several key therapeutic areas including immunology, oncology and neuroscience, and products and services in our Allergan Aesthetics portfolio.
Job Description
This position is part of AbbVie's Information Security & Risk Management (ISRM) team within Business Technology Solutions. The Identity & Access Management (IAM) team develops, implements, and oversees the organization’s IAM strategy, ensuring secure, efficient, and compliant access to systems and data. The role focuses on the fastest-growing attack surface in enterprise security: machine identities. It is the IAM team’s authoritative voice on how AI agents and cloud platforms must integrate with identity governance, ensuring no non-human identity operates outside of AbbVie's visibility or control.
In this role, you’ll be responsible for:
- Define and drive the enterprise Non-Human Identity (NHI) strategy—rapidly assess in-flight initiatives, rationalize overlapping efforts, and establish a centralized governance program for all machine identities across on-premises, cloud, and agentic environments.
- Build and maintain a comprehensive NHI registry encompassing service accounts, APIs, bots, application identities, robotic process automation (RPA), and AI agents—discover, inventory, classify, and continuously govern within IAM systems.
- Own AbbVie's identity governance posture for AI agents—integrate AI agent platforms with IAM so every agent is inventoried, mapped to its owning identity, governed through appropriate controls, and visible for security monitoring.
- Proactively discover and identify new AI agents and agentic workloads as they are introduced—partner with AI platform, cloud, and business teams to on-board into the NHI governance framework and drive remediations where gaps exist.
- Serve as the IAM point of accountability for all agent-related identity questions—define authentication standards, credential usage and security, and observable activity.
- Establish centralized NHI observability—drive integration between IAM platforms and external systems (AWS, Azure, GCP, and agentic platforms) so IAM maintains an authoritative view of all non-human identities.
- Design and implement modern NHI credential security controls (just-in-time access, dynamic secrets, short-lived certificates, automated rotation, runtime authentication) to reduce standing privilege for machine identities to near zero.
- Assess the current tooling landscape for NHI and cloud IAM; determine extension or new capability needs and build a phased modernization roadmap.
- Own and evolve the Cloud IAM and IGA strategy, closing the integration gap between cloud-native identity platforms (AWS IAM, Azure Entra ID, GCP IAM) and AbbVie's central IAM/IGA tools.
- Design cloud identity governance frameworks including role-based access models, entitlement management, access certifications, and least-privilege enforcement.
- Drive cross-functional alignment across IAM, AI Platform, Cloud, Security Architecture, Compliance, Audit, and business teams—translate requirements into executable roadmap priorities and hold partners accountable.
- Establish KPIs and maturity metrics for the NHI and Cloud IAM program, providing executive-level visibility into inventory completeness, risk posture, program progress, and gaps.
- Ensure compliance with regulatory requirements (SOX, GDPR, PCI-DSS) for machine identities and cloud access controls; respond to and remediate audit findings.
- Manage budget, resources, and vendor relationships for all NHI and Cloud IAM technologies and solutions.
- Lead and mentor a team of technical specialists, cultivating a culture of proactive governance, automation, and continuous improvement.
Qualifications
- Bachelor’s degree with 8 years experience or 7 years of relevant experience with 7 years experience or PhD with 3 years experience.
- Hands‑on experience with non-human identity management, cloud IAM, or machine identity governance in large enterprise environments.
- Demonstrated experience establishing or maturing NHI programs (service accounts, API credentials, application identities, or automated workloads).
- Strong hands‑on expertise with cloud IAM frameworks: AWS IAM, Azure Entra ID, and/or GCP IAM, including integration with central IGA platforms.
- Experience designing and implementing cloud IGA processes: entitlement management, access certifications, role-based access models, and least-privilege enforcement.
- Proven experience with secrets management platforms and modern credential security patterns (JIT access, short-lived certificates, dynamic secrets, automated rotation).
- Architecture-level understanding of identity federation, service-to-service authentication, and cloud-native identity patterns (OAuth, OIDC, SAML, workload identity).
- Strong track record of driving complex, cross-functional programs in matrixed organizations—influencing and holding accountable teams that are not direct reports.
- Demonstrated ability to proactively identify governance gaps, drive partner remediation, and establish scalable, automated processes.
- Excellent communication and executive presentation skills, translating deep technical concepts for non-technical stakeholders and building alignment across boundaries.
Beneficial
- Familiarity with AI agent platforms and their identity/credential patterns (e.g., Microsoft Copilot ecosystem, AWS Bedrock agents).
- Experience building NHI discovery and inventory capabilities, including integration with platforms not originally designed for identity governance.
- Familiarity with containerization and Kubernetes service account management.
- Hands‑on experience with IGA platforms and their cloud connectors (Saviynt, SailPoint, or equivalent).
- Scripting and automation experience (PowerShell, Python, Terraform, or other IaC tools).
- Knowledge of certificate management, PKI infrastructure, and API security platforms.
- Understanding of CIS, NIST, and other cloud security compliance frameworks.
- Industry certifications such as CISSP, CCSP, AWS/Azure/GCP security certifications, or equivalent.
- Experience in the pharmaceutical or life sciences industry.
Tools and skills you will use in this role
- Cloud IAM platforms: AWS IAM, Azure Entra ID, GCP IAM and integration with enterprise IGA.
- Secrets management platforms: HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or equivalent.
- IGA platforms with cloud connectors: Saviynt, SailPoint, or equivalent.
- NHI discovery, inventory, and governance tooling.
- Just-in-time access, dynamic secrets, and runtime authentication frameworks.
- Integration APIs and connectors for agentic platforms (e.g., Microsoft Copilot ecosystem, AWS Bedrock) for identity inventory and observability.
- Service-to-service authentication protocols: OAuth, OIDC, SAML, workload identity federation.
- Containerization and Kubernetes service account management.
- CI/CD pipeline integrations for identity and secrets (Jenkins, GitHub Actions, Azure DevOps, Terraform).
- Scripting and automation: PowerShell, Python, Infrastructure as Code.
- Certificate management and PKI.
- Audit and compliance reporting for cloud and NHI controls.
- Strong architectural thinking, cross-functional influence, and executive communication skills.
Additional Information
AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.
US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html
US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: https://www.abbvie.com/join-us/reasonable-accommodations.html