The Director, Identity and Technology Operations is responsible for the strategy, design, engineering, and day-to-day operations of the enterprise identity and access management (IAM) program, including identity governance and administration, birthright and role-based access design, joiner-mover-leaver lifecycle automation, authentication and multi-factor authentication, privileged access, and access certification. Provides leadership oversight of the identity operations function and is accountable for the accuracy, timeliness, and auditability of new hire provisioning, transfers, terminations, and access request fulfillment. Serves as the senior technical leader and owner of the identity roadmap, partnering with internal stakeholders (e.g., Information Security, Human Resources, Internal Audit, application teams, etc.) to ensure least privilege is enforced and identity controls satisfy audit and regulatory requirements. Provides technical and delivery leadership for select technology operations initiatives outside of identity.
Responsibilities:
- Owns the identity and access management strategy, architecture, and multi-year roadmap. Designs the enterprise identity model, including directory and tenant architecture, standards for service, application, and other non-human identities. Evaluates and selects identity platforms and integration approaches, and establishes the technical standards, patterns, and reference architectures adopted across Information Technology (IT).
- Designs and governs the enterprise access model to include birthright role definitions, role-based and attribute-based access control, entitlement catalogs, segregation of duties rules, and access request and approval workflows. Partners with internal stakeholders (e.g., Human Resources, business owners, etc.) to map job functions, departments, and organizational attributes to birthright entitlements, and maintains the role model over time through recertification, and remediation of orphaned, excessive, and stale access.
- Leads technical identity automation and engineering. Directs the build and maintenance of automated joiner-mover-leaver provisioning and deprovisioning, HR-driven identity lifecycle workflows, application onboarding via SCIM, APIs, and connectors, scripting and workflow development, and integration of applications into single sign-on and governance. Establishes monitoring, error handling, testing, and change control for identity automation, and partners with identity operations to automate repetitive access tasks so the team can focus on higher-value and exception work.
- Provides leadership and accountability for the identity operations function. Sets operational direction, service level targets, quality and accuracy standards, escalation paths, and coverage expectations for new hire and contractor provisioning, transfers and role changes, terminations and emergency deprovisioning, and access request fulfillment. Reviews volume, aging, and performance metrics with the manager, resolves cross-functional escalations with Human Resources and business leaders, approves staffing and capacity plans, and ensures procedures and runbooks remain current and audit-ready.
- Owns identity-related control and compliance operations to include access controls in scope for audit, periodic user and privileged access reviews and certification campaigns, termination and transfer evidence, and remediation of control deficiencies. Serves as the primary technical point of contact for internal and external auditors on identity controls, and reports identity risk, control coverage, and program metrics to IT and Information Security leadership.
- Provides technical and delivery leadership for general technology initiatives outside of identity, including leading cross-functional software implementations, upgrades, and integrations, evaluating vendors and solutions, and supporting broader IT operations programs as assigned.
Requirements:
- Bachelor’s degree in computer science, information technology, cybersecurity, relative field or an equivalent combination of education and experience required.
- Minimum eight (8) years of experience in identity and access management, including hands-on engineering, administration, or architecture of enterprise identity platforms.
- Minimum three (3) years of experience leading technical teams, programs, or projects, including direct supervision of staff.
- Experience leading an operational support or service delivery function accountable to service level agreements.
- Experience designing and operating identity governance and administration capabilities, including birthright roles, role-based access control, access request workflows, and access certification campaigns.
- Experience implementing automated identity lifecycle.
- Experience with enterprise directory, single sign-on, governance, and privileged access technologies such as Microsoft Entra ID (Azure AD), SailPoint or comparable platforms.
- Experience supporting identity and access controls in an audited or regulated environment preferred.
- Experience in supporting Public Cloud and SAAS technologies.
- Strong knowledge of identity and access management concepts including authentication, authorization, federation, single sign-on, multi-factor authentication, least privilege, and Zero Trust principles.
- Must have working knowledge of identity automation and scripting technologies such as PowerShell, Microsoft Graph API, REST APIs, and workflow or integration platforms.
- Strong ability to design role and entitlement models and translate business job functions into technical access definitions.
- Must have working knowledge of segregation of duties concepts and access control requirements associated with financial, security, and privacy audits.
- Must have working knowledge of SaaS products and integration applications.
- Must have working knowledge of IT service management practices and ticketing platforms, including service level agreement management, queue triage, and operational reporting.
- Strong verbal and written communication, documentation planning, analysis and organizing skills, including the ability to explain identity concepts to non-technical stakeholders, executives, and auditors.
- Advanced and resourceful in troubleshooting, problem-solving, and solution development to identify areas for improvement and create an action plan.
Compensation
The anticipated pay range/scale for this position is $134,922.00 to $174,093.00 Annually. Actual starting base pay within this range will depend on factors including geographic location, education, training, skills, and relevant experience.
Additional Compensation
This position is eligible to receive a discretionary annual bonus.
Perks and Benefits
Employees have the opportunity to participate in medical, dental and vision insurance; flexible spending accounts and/or health savings accounts; dependent savings accounts; 401(k) with company matching contributions; employee stock purchase plan; and a tuition reimbursement program. The Company provides 9 paid holidays per year, and, upon hire, new employees will accrue paid time off (PTO) at a rate of 0.0577 hours of PTO per hour worked, up to a maximum of 120 hours per year.
#LI-PH1