Description of PositionTPG has an exciting opportunity for an Identity Governance and Administration (IGA) Principal to join TPG's Cybersecurity team. The number one focus of this role is the ground-up redesign and ongoing maturity of the firm's IGA program. This is a hands-on, high-impact role for a senior practitioner who wants to shape an identity program rather than inherit one. TPG's Cybersecurity team protects the firm's applications, data, and clients across a fast-moving technology landscape. Identity is at the center of that mission - the firm's access management platform serves as the hub connecting every business application, and getting identity governance right is foundational to everything else we do.
Principal Responsibilities- Serve as a senior leader and subject-matter expert for the firm's IGA program, helping to drive its strategy, roadmap, and day-to-day operation
- Play a key role in the ground-up redesign of TPG's IGA program - partnering with our third-party advisory firm to reimagine identity tools, processes, and governance, and ensuring the resulting design reflects TPG's business requirement
- Lead the implementation or migration effort for the selected IGA platform, including solution design, configuration, application onboarding, connector and integration development, and cutover planning
- Design and operate core IGA processes - joiner/mover/leaver lifecycle management, access requests and approvals, access certifications and reviews, role-based access control and role mining, segregation of duties, and governance of privileged access
- Serve as a liaison between technical and business teams - communicating effectively with system owners, data owners, and business managers to gather requirements, resolve issues, and drive adoption of new identity processes
- Develop a deep understanding of the identity and access structure of each supported business application - most importantly Microsoft Entra ID - and integrate those applications into the IGA platform
- Automate identity lifecycle and governance workflows through scripting, APIs, and platform-native capabilities to reduce manual effort and error
- Define metrics, reporting, and key performance indicators that demonstrate program maturity, audit readiness, and risk reduction; support internal and external audit requests
- Mentor and develop junior members of the IGA team, and help build identity governance expertise across the broader Cybersecurity organization
- Contribute to enterprise identity and access management standards, policies, and governance documentation
Requirements- Minimum 5 years of experience focused on identity governance and administration
- Hands-on experience implementing and administering one or more enterprise IGA platforms (e.g., Saviynt, SailPoint), with experience leading a platform evaluation, migration, or greenfield deployment strongly valued
- Deep understanding of core identity governance concepts, including identity lifecycle management, provisioning and deprovisioning, access certification, role-based access control, and segregation of duties
- Strong working knowledge of Microsoft Entra ID and modern identity architectures, including federation and authentication standards such as SAML, OAuth 2.0, OpenID Connect, and SCIM
- Software programming or scripting experience (e.g., PowerShell, Python) and comfort working with REST APIs and application connectors
- Communicate effectively with system owners, data owners, business managers, and senior leadership - including the ability to explain identity risk to non-technical audiences and influence without direct authority
- Experience working with or managing third-party consultants, advisors, or implementation partners
- Be comfortable and capable swinging between efforts that are broad and strategic in scope to tasks that are tedious and require strict attention to detail
- Critically assess existing processes and systems, and drive constructive, evidence-based improvements while keeping current operations running
- Invite and provide evidence-based feedback in a timely and constructive manner
- Possess an ownership attitude as it relates to identifying errors, process inconsistencies, or security weaknesses
Preferred Qualifications- Bachelor's degree or higher in Computer Science, Information/Cyber Security, or a related field, or equivalent work experience
- Experience leading an IGA platform selection, replacement, or re-implementation, including RFP development and proof-of-concept evaluation
- Platform certifications such as Saviynt IGA Professional or SailPoint Identity Security certifications, or broader credentials such as CISSP, CISM, or CIAM
- Familiarity with privileged access management (PAM) tools and their integration with IGA platforms
- Experience securing cloud and SaaS identity environments (e.g., Microsoft 365, AWS, Azure) and integrating SaaS applications into governance workflows
- Experience in financial services or another regulated industry, including supporting SOX, SOC, or similar audit and compliance requirements