GI Alliance is seeking an experienced Director of Identity & Access Management.
Position Summary The Identity and Access Management Director directs the strategy, governance, and operational execution of the enterprise Identity and Access Management (IAM) program to ensure secure, reliable, and compliant access to critical business systems, applications, and data. Leads the evolution of identity services, access governance, privileged access management, and authentication technologies to support organizational growth, regulatory requirements, and cybersecurity objectives. Partners with executive leadership, business stakeholders, infrastructure teams, application owners, and security functions to align identity capabilities with business priorities while enabling a secure and frictionless user experience. Drives the adoption of modern identity principles, including Zero Trust, automation, and cloud-based identity services, to strengthen the organization's security posture and operational efficiency.
Responsibilities/Duties/Functions/Tasks:
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Key Responsibilities - Lead enterprise-scale Identity Access Management (IAM) transformation programs, providing strategic direction for Identity Governance Administration (IGA) and Privileged Access Management (PAM) initiatives across complex client environments
- Oversee the design, architecture, and governance of IAM solutions leveraging Identity technologies to address identity lifecycle management, privileged access controls, compliance, and security requirements
- Serve as the executive technical advisor and escalation point for complex identity governance, privileged access, application onboarding, and modernization challenges, driving successful outcomes and mitigating security and operational risks
- Lead and mentor cross-functional teams of technical specialists while fostering delivery excellence, innovation, and growth across IAM programs
- Partner with executive stakeholders, security leaders, application owners, and business executives to develop IAM roadmaps, align identity security strategies with business objectives, and establish leading practices for governance and risk management
- Support business development efforts through solution development, proposal creation, thought leadership, and identification of opportunities to expand identity security, governance, and privileged access services within existing and prospective accounts
- Act with integrity, professionalism, and personal responsibility to uphold a respectful and courteous work environment
- Establish IAM frameworks, security policies, standards, and procedures aligned with organizational objectives.
Regulatory Compliance - Lead compliance initiatives as they relate to IMA in the context of healthcare regulations, including HIPAA Privacy, Security, and Breach Notification Rules.
- Ensure IAM compliance with applicable federal, state, and industry regulations affecting healthcare organizations.
- Participate in internal and external compliance audits.
- Participate in regulatory examinations and respond to audit findings.
- Monitor regulatory changes and assess organizational impact.
Security Frameworks & Controls - Develop and maintain security controls aligned with:
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53
- NIST SP 800-171
- SOC 2 Trust Services Criteria
- Sarbanes-Oxley (SOX) IT General Controls (ITGCs)
- Evaluate control effectiveness and recommend improvements in the context of IAM
- Partner with IT and Security teams to ensure technical controls support regulatory and business requirements.
Audit & Assurance - Participate and assist TSA GRC in internal and external audits including HIPAA, SOC 2, SOX, and customer security assessments.
- Track remediation efforts through completion.
Qualifications - Bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, Risk Management, Healthcare Administration, or a related field.
- 10+ years of progressive experience in Governance, Risk & Compliance, Information Security, Internal Audit, or Cybersecurity.
- 5+ years of leadership experience managing GRC, Compliance, Risk, or Security teams.
- Experience within the healthcare, medical device, healthcare technology, payer, provider, or life sciences industry.
- Demonstrated experience leading enterprise compliance and risk management programs.
Candidates must possess strong working knowledge of:
- HIPAA Privacy Rule, Security Rule, and Breach Notification Rule
- NIST Cybersecurity Framework (CSF)
- NIST Special Publication 800-53
- SOC 2 Trust Services Criteria and audit readiness
- Sarbanes-Oxley (SOX), including IT General Controls (ITGCs)
- Security governance and policy development
- Audit management and regulatory examinations
- Incident response governance
Preferred Qualifications - Master's degree in Cybersecurity, Information Systems, Business Administration, Healthcare Administration, or related discipline.
- Professional certifications such as:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
- Certified in Healthcare Privacy and Security (CHPS)
- Healthcare Information Security and Privacy Practitioner (HCISPP)
Key Competencies - Executive communication and presentation skills
- Strategic leadership
- Regulatory interpretation and implementation
- Enterprise risk management
- Analytical problem-solving
- Cross-functional collaboration
- Program and project management
- Audit readiness and remediation
- Policy development and governance
- Change management
Equipment Operated: This role routinely uses standard office equipment such as computers, phones, and fax machines.
Work Environment: This job operates in professional office environments.
Physical Requirements: While performing the duties of this job, the employee is occasionally required to stand; walk; sit; use hands to finger, handle, or feel objects, tools or controls; reach with hands and arms; climb stairs; balance; stoop, kneel, crouch or crawl; talk or hear; and taste or smell. The employee must occasionally lift or move up to 50 pounds. Specific vision abilities required by the job include close vision, distance vision, color vision, peripheral vision, depth perception and the ability to adjust focus.
Qualifications Education/Experience: - Bachelor s degree in computer science or other technical/scientific discipline.
- 10+ years related work including 5+ years as in security.
- 2+ years in a dedicated information security role at a senior level including cybersecurity experience specializing in enterprise security optimization
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, and NIST.
- CISSP or equivalent certification required.
Essential Skills and Experience: - Leadership: a demonstrated ability to lead people and get results through others.
- Strategy and planning: an ability to think ahead and plan over a 12-24 month time span.
- Demonstrated understanding of Information Security best practices.
- Problem analysis and problem resolution at both a strategic and functional level.
- Experience in developing and deploying security specific solutions including the automation of repeatable security tasks and controls
- Experience with security vulnerability and penetration tools, remediation, and processes.
- Strong customer orientation.
- Must be willing to travel
Performance Requirements: - Excellent communication skills, both written and verbal.
- Proficient technical (computer) skills.
- Ability to multi-task and prioritize.
- Self-motivated with initiative.
- Strong sense of ethics.
- Ability to manage conflict and resolve problems.
Equipment Operated: This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines.
Work Environment: This job operates in professional office environments.
- Physical Requirements: While performing the duties of this job, the employee is occasionally required to stand; walk; sit; use hands to finger, handle, or feel objects, tools or controls; reach with hands and arms; climb stairs; balance; stoop, kneel, crouch or crawl; talk or hear; and taste or smell. The employee must occasionally lift or move up to 30 pounds. Specific vision abilities required by the job include close vision, distance vision, color vision, peripheral vision, depth perception and the ability to adjust focus.
No phone calls or agencies, please.