Director, Identity & Access Management

DataSpring

$190K — $220K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in IAM or related fields
  • 4+ years in senior leadership roles
  • Experience in 100% cloud environments
  • Preferred experience in healthcare or regulated industries
  • Relevant certifications (CISSP, CISM, CCSP) preferred

Responsibilities

  • Define and own multi-year IAM strategy and roadmap
  • Establish governance frameworks for all identity types
  • Develop and enforce IAM policies and procedures
  • Lead access certification and entitlement review programs
  • Own IAM risk register and collaborate on risk remediation
  • Design and enforce identity controls for agentic AI
  • Oversee IAM platform architecture and operations
  • Ensure IAM compliance with industry regulations

Benefits

  • Medical, dental, and vision coverage
  • 401(k) plan with company contributions
  • Paid parental leave
  • Tuition assistance
  • Generous paid time off
Full Job Description
Position Summary
The Director of Identity and Access Management (IAM) is a senior technical and strategic leadership position responsible for designing, governing, and continuously maturing the organization's IAM program across a 100% cloud-native, fully remote environment. This leader serves as the company's authoritative voice on all matters of identity - spanning human identities (employees, consultants, customers, and partners) and the rapidly expanding population of non-human identities (NHIs) including service accounts, API keys, workload credentials, and agentic AI systems.

This is a full-time, exempt, remote position and reports to the CISO.

Specific Responsibilities

IAM Strategy & Program Leadership

  • Define and own the multi-year IAM strategy, roadmap, and investment plan aligned with business objectives, Zero Trust principles, and healthcare regulatory requirements.
  • Establish governance frameworks for all identity types: workforce, partner/customer (CIAM), privileged (PAM), and non-human/machine identities including AI agents and ML workloads.
  • Develop and maintain IAM policies, standards, and procedures across the organization and enforce adherence through governance processes.
  • Lead annual and continuous access certification and entitlement review programs covering employees, contractors, and third parties.
  • Own the IAM risk register; identify, assess, prioritize, and remediate access-related risks in collaboration with the broader security and risk teams.


Non-Human Identity & Agentic AI Governance

  • Establish a comprehensive Non-Human Identity (NHI) governance program covering service accounts, API tokens, certificates, OAuth clients, workload identities, and agentic AI identities.
  • Design and enforce identity controls for agentic AI and ML pipeline workflows, ensuring least-privilege, just-in-time (JIT) access, and dynamic permission scoping for autonomous agents that chain actions across systems.
  • Implement continuous discovery and inventory of all NHIs across cloud platform (Azure) and SaaS applications; eliminate shadow credentials and unmanaged secrets.
  • Define AI agent identity lifecycle standards: provisioning, scoping, monitoring, credential rotation, and decommissioning.
  • Partner with AI/ML Engineering and Product to embed identity governance requirements into the SDLC for all agentic and automated systems.


Architecture & Technical Oversight

  • Oversee architecture, integration, and operations of IAM platforms including IdP (Okta, Azure Entra ID), IGA, PAM, and secrets management.
  • Lead the design and enforcement of authentication standards: MFA, passwordless, FIDO2/WebAuthn, SAML 2.0, OAuth 2.0/OIDC, and SCIM-based provisioning.
  • Govern cloud entitlement management (CIEM) to enforce least-privilege and prevent privilege sprawl.
  • Own directory services strategy; oversee user provisioning, de-provisioning, role lifecycle, and RBAC/ABAC model design.
  • Ensure cryptographic asset management (PKI, certificate lifecycle, key management) is operationally sound and audit-ready.


Customer & Partner Identity (CIAM)

  • Lead the Customer Identity and Access Management (CIAM) strategy for external users including healthcare customers, partners, and integration endpoints.
  • Ensure CIAM solutions deliver secure, low-friction authentication experiences
  • Define partner federation standards and govern third-party access lifecycle from onboarding through offboarding.


Compliance, Audit & Risk

  • Ensure IAM program compliance with HIPAA/HITECH, SOC 2 Type II, HITRUST CSF, NIST 800-63 (Digital Identity Guidelines), ISO 27001, and applicable state privacy laws (CCPA, etc.).
  • Serve as the IAM subject-matter expert during audits, assessments, and regulatory examinations; own audit evidence collection and remediation of findings.
  • Partner with Legal and Privacy teams on access-related data governance, breach response procedures, and regulatory reporting obligations.
  • Monitor threat intelligence and ITDR (Identity Threat Detection & Response) signals; drive timely response to identity-based attack indicators.


Team Leadership & Culture

  • Recruit, develop, and retain a high-performing team of IAM engineers, analysts, and architects; build a culture of ownership, continuous learning, and operational excellence.
  • Define and track team KPIs, OKRs, and SLA/SLO metrics tied to identity program health and security posture improvements.
  • Act as an IAM evangelist internally, educating stakeholders across the business on identity risk and enabling security-conscious behavior.


Skills

  • Deep expertise in at least two major IAM platforms
  • Hands-on knowledge of IGA platforms
  • PAM platform experience
  • Secrets management and NHI tooling
  • Proficiency in authentication protocols and standards: OAuth 2.0, OIDC, SAML 2.0, SCIM, LDAP, Kerberos, FIDO2/WebAuthn.
  • CIEM and cloud identity posture management experience (Wiz CIEM or native cloud tooling).
  • Familiarity with IAM considerations for AI/ML workloads, agentic architectures, and machine-to-machine identity patterns.
  • Scripting and automation capability in Python, PowerShell, Bash, or similar; ability to review and direct infrastructure-as-code (Terraform, CloudFormation) with IAM implications.
  • Solid understanding of Zero Trust architecture principles and their application to identity


Experience & Education

  • 10+ years of progressive experience in Identity and Access Management, cybersecurity, or adjacent disciplines.
  • 4+ years in a senior leadership role managing IAM teams, programs, or practices.
  • Demonstrated experience in a cloud-native or 100% cloud-based environment (AWS, Azure, or GCP at scale).
  • Prior experience in a healthcare, life sciences, or similarly regulated industry strongly preferred.
  • Proven track record designing or governing IAM in environments serving multiple user populations (workforce, customers, partners, third parties, automated systems).
  • Bachelor's degree preferred.
  • Relevant industry certifications in - CISSP, CISM, CCSP certifications preferred.


What You Get

At DataSpring, you will do meaningful work at the intersection of healthcare, data, and technology, helping solve complex problems that make the healthcare system work better. You will collaborate with experienced professionals who care deeply about accuracy, trust, and meaningful impact in a fully remote environment.

DataSpring offers competitive compensation and a comprehensive benefits package for full-time employees, including medical, dental, and vision coverage, a 401(k) with company contributions and matching, paid parental leave, tuition assistance, and generous paid time off. We are committed to investing in our people and supporting professional growth over time.

The pay range for this role is:

190,000 - 220,000 USD per year (Remote (United States))

Similar Jobs

More Jobs at DataSpring

More Information Technology Jobs

Find similar Director, Identity & Access Management jobs: