Head of Information Security / Identity and Access ManagementPosition Summary: The Head of Information Security / Identity and Access Management will serve as a strategic and technically deep leader responsible for the execution and continuous improvement of our enterprise-wide information Security Management (ISM) team within the Protect Pillar. This leader will be responsible for ensuring that identity is treated as a core security control and will oversee capabilities spanning authentication, authorization, privileged access management, identity governance, access certification, and modern Zero Trust principles.
The ideal candidate combines strong technical expertise with executive leadership experience and has a proven track record of building and operating identity-centric security programs within highly regulated environments, preferably in financial services. The ideal candidate will also have experience transforming and modernizing identity operations through automation, workflow redesign and implementing scalable processes that improve effectiveness, efficiency, and user experience and serving as a trusted advisor to drive a security-first culture focused on protecting people, systems, data and critical assets.
This role reports to the Head of the Protect Pillar in Systems. The Protect Pillar is a unique BBH-construct designed for clear, centralized and coordinated accountability: to protect against physical and logical security risks; to safeguard stakeholder assets; and to detect, prepare for, and respond effectively to security events. To that end, the Protect Pillar encompasses the following areas:
- Cybersecurity;
- Enterprise Data Protection and Data Governance;
- Information Security Management (“ISM”);
- Business Continuity / Disaster Recovery;
- Protect Program, Strategy and Automation; and
- Global Security (Physical Security).
Key Responsibilities:
- Define and execute the enterprise Identity and Access Management strategy aligned with business objectives, security priorities, and regulatory requirements
- Establish and implement a multi-year vision and roadmap to further mature identity security, authentication, authorization, privileged access and identity governance capabilities
- Assess and lead enhancements relating to:
- Identity lifecycle management
- Authentication capabilities
- Authorization and entitlement management
- Privileged Access Management
- Identity Governance and Administration
- Role-based and attribute-based access controls
- Evaluate access protocols and ensure protocols are consistent with least privilege, just-in-time (JIT), just-enough (JEA) as appropriate to the level of access
- Ensure appropriate authorization controls and entitlement management across cloud, on-premise and non-human IDs
- Lead the modernization of identity governance processes. Identify opportunities to eliminate manual processes and improve the user experience while maintaining strong security and regulatory compliance
- Develop and implement a roadmap for modernizing identity governance and administration capabilities, with particular focus on lifecycle management, attestations, access reviews, and privileged access workflows
- Partner with technology and business stakeholders to redesign legacy processes and implement scalable solutions that support organizational growth and evolving security requirements
- Develop and execute a sustainable workforce strategy that attracts, develops and retains talent with skills needed to support a modern identity security program and evolving technologies
- Oversee and coordinate responses to Internal Audit, external audit / SOC1/SOC2 exams, regulatory reviews, client due diligence and other assurance activities relating to identity and access management
Qualifications:
- Minimum 15 years of experience in information security, including leadership of identity and access management programs
- Deep expertise in:
- Identity and Access Management
- Privileged Access Management
- Authentication technologies and protocols
- Authorization models and entitlement management
- Identity governance and lifecycle management
- Cloud identity platforms and hybrid identity architectures
- Strong understanding of:
- MFA, FIDO2 and modern authentication standards
- Microsoft Entra ID, Active Directory, Sailpoint, Ping
- Zero Trust security principles
- Least privilege access models
- Just-in-Time (JIT) access
- Just-Enough-Access (JEA)
- Familiarity with DFS Part 500, NIST Cybersecurity Framework, ISO 27001/27002, FFIEC guidance and other relevant industry standards
- Experience leading enterprise-wide transformations involving IAM modernization and security control enhancements
- Demonstrated ability to influence executive stakeholders and drive organizational change
- Experience with SailPoint, One Identity Safeguard (OIS), mainframe system, mainframe security program (z/OS and RACF)
- Excellent analytical and communication skills
- Strong PowerPoint and Excel skills
Salary Range
$200,000-$260,000 base salary + annual target bonus
BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck—providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.
We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn’t followed a traditional path, includes alternative experiences, or doesn’t meet every qualification or skill listed in the job description, please do go ahead and apply.