Director, Identity & Access Management

AssetMark, Inc.

• $190K — $220K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in technology, cybersecurity, or identity management, with a focus on enterprise IAM.
  • 5+ years leading technical teams with a demonstrated ability to develop and mentor engineers.
  • Experience in building or transforming IAM programs in complex or regulated environments, particularly in financial services.
  • Familiarity with IGA platforms like SailPoint or Microsoft Entra ID Governance, and PAM solutions such as CyberArk or HashiCorp Vault.
  • Relevant certifications such as CISSP, CISM, or Microsoft Identity certifications preferred.

Responsibilities

  • Build and lead AssetMark's centralized enterprise IAM function with a focus on strategy and governance.
  • Define target-state identity architecture and multi-year roadmap, emphasizing Zero Trust and least privilege principles.
  • Lead the development of Identity Governance capabilities and lifecycle management processes.
  • Provide strategic and technical leadership for Microsoft Entra ID and Active Directory architecture.
  • Establish governance standards for Active Directory and oversee Group Policy management.
  • Set secure authentication patterns for enterprise applications and SaaS platforms, utilizing various protocols.
  • Champion an engineering-first approach for automating IAM processes and managing lifecycle events.

Benefits

  • Hybrid work schedule option with some flexibility.
  • Comprehensive benefits package offered.
  • Opportunities for professional development and certification support.
  • Supportive team environment focused on mentoring and innovation.
Full Job Description
Job Description:

AssetMark is establishing a centralized Enterprise Identity & Access Management (IAM) function to strengthen access controls, reduce risk, improve audit and regulatory readiness, and create scalable identity services across the enterprise.

The Director of Identity & Access Management will build and lead this function and own the IAM strategy, operating model, architecture, engineering, governance, delivery, and service roadmap. The Director will lead identity services across on-premises Active Directory, Microsoft Entra ID, Azure, Microsoft 365, business applications, endpoints, collaboration platforms, and data services.

The Job/What You'll Do:

This is a hands-on technical leadership role for a leader who can establish strategy while remaining close enough to the technology to guide architecture, solve complex identity challenges, challenge designs, lead major implementations, and help the team deliver. The Director will initially lead a focused team of three IAM Engineers and one IAM Compliance/Controls resource and will partner extensively with Cybersecurity, Infrastructure, HR, Risk & Compliance, Internal Audit, application teams, and business/data owners.

The successful Director will transform IAM from distributed access activities into a centralized enterprise capability. Early priorities include establishing the IAM operating model, strengthening lifecycle and termination controls, defining identity, group, role, permission, SharePoint, and data-classification standards, establishing Purview governance and control evidence, and prioritizing the technology roadmap.

We can only consider candidates for this position who are able to accommodate a hybrid work schedule and are close to our Charlotte, NC office.

Key Responsibilities

  • Build and lead AssetMark's centralized enterprise IAM function, including its strategy, operating model, service catalog, technology roadmap, engineering standards, governance practices, budget, vendors, and delivery partners. Establish clear ownership across IAM Engineering, Directory Services, Identity Governance, Privileged Access, IAM Automation, and Compliance/Controls.
  • Define the target-state identity architecture and multi-year roadmap for hybrid identity modernization, Zero Trust, least privilege, secure-by-design access, SSO, federation, MFA, passwordless authentication, identity governance, and application integration. Reduce legacy dependencies and create consistent identity patterns across the enterprise.
  • Lead the design and maturation of Identity Governance & Administration capabilities, including joiner, mover, leaver, contractor, partner, rehire, and non-person identity lifecycle processes; authoritative-source integration; access requests and approvals; birthright access; provisioning and deprovisioning; certifications; entitlement governance; role management; segregation of duties; and automated workflows using standards such as SCIM where appropriate.
  • Provide strategic and technical leadership for Microsoft Entra ID and Active Directory, including directory architecture, identity synchronization through Entra Connect Sync or Cloud Sync, authentication, authorization, Conditional Access, MFA, passwordless authentication, Windows Hello for Business, self-service password reset, federation, external identities, identity protection, and identity governance.
  • Establish governance and operating standards for Active Directory organizational units, naming conventions, delegation, administrative boundaries, directory roles, domain controllers, trusts, DNS dependencies, and lifecycle management. Oversee Group Policy design, management, testing, documentation, exception handling, recovery, and change control.
  • Establish secure authentication and authorization patterns for enterprise applications and SaaS platforms. Govern application registrations, enterprise applications, app roles, consent, federation, and SSO using protocols such as SAML, OAuth 2.0, OpenID Connect, WS-Fed, LDAP, Kerberos, and SCIM, and create repeatable onboarding standards for application teams.
  • Oversee enterprise identity and access administration for Microsoft 365 and SharePoint, including role assignments, licensing-related access, administrative controls, security groups, collaboration settings, information architecture, site and hub structure, permission levels, sharing settings, external collaboration, inheritance, ownership, lifecycle, and access-review practices.
  • Establish least-privilege standards and governance for permissions across applications, infrastructure, SaaS, cloud, file shares, SharePoint, and collaboration platforms. Ensure access is approved by appropriate business or data owners, periodically reviewed, traceable, and promptly removed when no longer required. Use RBAC, ABAC, role engineering, and access analytics where appropriate.
  • Lead the strategy and governance for privileged accounts, vaulting, credential management, session controls, emergency access, tiered administration, privileged access workstations, service accounts, application identities, APIs, secrets, certificates, cloud workloads, managed identities, service principals, and just-in-time elevation. Establish controls for break-glass access and administrative separation.
  • Define identity and access standards across Azure management groups, subscriptions, resource groups, and resources. Govern Azure RBAC, managed identities, workload identities, service principals, application registrations, role assignments, secrets, certificates, keys, and credentials using Azure Key Vault and related services.
  • Establish governance for Microsoft Purview data classification, sensitivity labels, Data Loss Prevention, retention, records management, insider-risk integrations, and related policies. Promote awareness of personally identifiable information, sensitive-data handling requirements, and the relationship between data sensitivity and access decisions.
  • Champion an engineering-first approach using PowerShell, Python, Microsoft Graph, REST APIs, reusable patterns, Git, CI/CD, Terraform or other Infrastructure as Code, testing, monitoring, logging, reconciliation, runbooks, recovery procedures, and disciplined change management. Automate lifecycle events, application onboarding, access reviews, evidence collection, reporting, and credential rotation.
  • Establish monitoring and reporting for Entra sign-in, audit, provisioning, and privileged-activity logs. Partner with Security Operations on Microsoft Sentinel, Log Analytics, KQL, Defender for Identity, risky users, risky sign-ins, compromised accounts, workload-identity threats, and identity-related incident response and remediation.
  • Own the IAM service catalog, service health, operating procedures, service levels, incident and problem management partnership, change governance, documentation, continuity planning, and recovery testing. Establish metrics and executive reporting for service health, risk reduction, control effectiveness, certification completion, privileged access, lifecycle performance, PII policy coverage, excessive permissions, unmanaged sharing, audit findings, and program maturity.
  • Align IAM capabilities to AssetMark security policies and applicable requirements such as SOX, NIST, ISO 27001, and financial-services expectations. Establish clear accountability across IAM, HR, application and platform owners, Cybersecurity, Infrastructure, Risk, Compliance, Privacy, and Internal Audit, and partner with these groups to deliver secure, scalable, automated, and adopted IAM services.


Knowledge, Skills & Abilities

  • Deep knowledge of enterprise IAM architecture and program delivery, including IGA, identity lifecycle management, authentication, SSO/federation, provisioning, access governance, RBAC/ABAC, certifications, segregation of duties, PAM, Zero Trust, and least-privilege principles.
  • Advanced Microsoft identity expertise, including Microsoft Entra ID, Active Directory, OU structure, Group Policy, directory governance, delegation, synchronization, Conditional Access, MFA, passwordless and modern authentication, identity protection, and identity governance.
  • Strong knowledge of Azure, Microsoft 365, SharePoint, and cloud identity and authorization, including Azure RBAC, management groups, subscriptions, resource groups, managed identities, service principals, application registrations, Key Vault, Microsoft 365 administrative controls, SharePoint governance, and information access models.
  • Strong understanding of enterprise application and information access patterns, including SaaS, file shares, collaboration platforms, application registrations, SAML, OAuth 2.0, OpenID Connect, WS-Fed, LDAP, Kerberos, and SCIM.
  • Working knowledge of Microsoft Purview and data protection concepts, including PII, sensitive-data classification, sensitivity labels, Data Loss Prevention, retention, records management, insider-risk integrations, and control monitoring.
  • Hands-on engineering and automation capability using PowerShell, Python, Microsoft Graph, REST APIs, KQL, Git, CI/CD, Terraform or other Infrastructure as Code, testing, monitoring, logging, and reconciliation.
  • Strong understanding of privileged access, secrets and workload identities, identity monitoring, incident response, audit evidence, and cross-functional control remediation.
  • Excellent executive communication, stakeholder management, analytical, presentation, and problem-solving skills, with the ability to move between strategy, business impact, and technical detail.
  • Demonstrated ability to develop engineers, build strong technical organizations, establish clear accountability, mentor technical teams, and influence partners across business and technology functions.


Education & Experience

  • 10 or more years of progressive technology, cybersecurity, or identity experience, with significant experience focused on enterprise IAM.
  • Five or more years leading technical teams, with demonstrated success developing engineers, building strong technical organizations, and directing delivery through a roadmap.
  • Proven experience building, transforming, or significantly maturing an enterprise IAM program in a complex or regulated environment.
  • Experience within financial services or another highly regulated enterprise environment, including audit, regulatory examination, and remediation activities.
  • Experience with IGA platforms such as SailPoint Identity Security Cloud or IdentityIQ, Microsoft Entra ID Governance, Saviynt, Okta, or comparable platforms.
  • Experience with PAM and secrets-management platforms such as CyberArk, BeyondTrust, Delinea, HashiCorp Vault, or comparable technologies.
  • Relevant certifications are preferred, such as CISSP, CISM, CIAM, Microsoft Identity and Access Administrator, Microsoft Azure Security Engineer, Microsoft 365 or Purview certifications, SailPoint certification, or comparable credentials.


Compensation: The Base Salary range for this position is between $190,000-$220,000.

This information reflects a base salary range that AssetMark reasonably expects to pay for the position based on a number of factors which may include job-related knowledge, skills, education, experience, and actual work location. This position will also be eligible for additional variable incentive compensation and competitive benefits.

Candidates must be legally authorized to work in the US to be considered. We are unable to provide visa sponsorship for this position.

#LI-hybrid

#LI-TN1

Similar Jobs

More Jobs at AssetMark, Inc.

  • Channel Manager
    $120K — $135K *
    Concord, CA 94521 (Contra Costa County)
    Finance & Insurance
    Hybrid
  • Channel Manager
    $120K — $135K *
    Charlotte, NC 28269 (Mecklenburg County)
    Finance & Insurance
    Hybrid
  • Senior Product Manager
    $160K — $180K *
    Charlotte, NC 28269 (Mecklenburg County)
    Finance & Insurance
    Hybrid
  • Senior Data Engineer
    $162K — $190K *
    Charlotte, NC 28269 (Mecklenburg County)
    Finance & Insurance
    Hybrid
  • Channel Manager
    $120K — $135K *
    Concord, CA 94521 (Contra Costa County)
    Finance & Insurance
    In-Person

More Information Technology Jobs

Find similar Director, Identity & Access Management jobs: