The Lead Information Security Operations Specialist leads the organization's IAM Access Certification program, ensuring that user access across applications and platforms adheres to the principle of least privilege. Working under limited supervision, this individual contributor role serves as the subject matter expert for access governance, driving the design, implementation, and continuous improvement of certification campaigns, Segregation of Duties (SoD) controls, and Role Based Access Control (RBAC) frameworks. This role partners closely with application teams, Lines of Business, and enterprise IAM leadership to ensure consistent, high-quality access governance across both centralized and decentralized applications, including support for the organization's transition from SailPoint IdentityIQ to Saviynt.
Key Responsibilities and Duties- Leads the end-to-end strategy and execution of the IAM Access Certification program, ensuring certification campaigns are conducted with consistent cadence and rigor across both centralized (IGA-onboarded) and decentralized applications.
- Leads application scoping efforts to determine onboarding eligibility to the centralized IGA platform and, where applicable, identifies the appropriate integration type.
- Oversees the build-out, implementation, and ongoing operational health of Segregation of Duties (SoD) rules and Role Based Access Control (RBAC) profiles, partnering with application teams and Lines of Business who are responsible for defining the underlying SoD and RBAC requirements.
- Leads user access review campaigns to enforce the principle of least privilege, ensuring individuals retain only the access required to perform their job responsibilities.
- Applies the same access certification standards, cadence, and rigor to decentralized applications not onboarded to the centralized IGA platform, including those currently managed through manual, email, or spreadsheet-based processes, and drives improvements to standardize and streamline these processes over time.
- Identifies and implements opportunities to leverage AI-enabled capabilities, including those native to Saviynt, to improve certification efficiency and accuracy through outlier detection, access recommendations, and other intelligent review mechanisms.
- Establishes and matures certification practices for Non-Human Identities (NHIs), including service accounts and AI agents, ensuring appropriate ownership, review, and governance controls are in place.
- Serves as the subject matter expert on IAM access governance, providing mentorship and guidance to other IT security team members supporting the certification program.
- Supports the organization's migration from SailPoint IdentityIQ to Saviynt, including validating that access certification, SoD, and RBAC capabilities are properly configured and operational within the new platform.
- Coordinates with internal audit and information security assessment teams to identify weaknesses in access governance processes and strengthens existing controls accordingly.
- Conducts analysis of organizational needs and goals to guide the ongoing development of access certification, SoD, and RBAC capabilities.
- Identifies and evaluates emerging data access control technologies, techniques, and safeguards relevant to identity governance and access certification.
Educational Requirements- University (Degree) Preferred
Work Experience- 5+ Years Required; 7+ Years Preferred
Physical Requirements- Physical Requirements: Sedentary Work
Career Level8IC
Required Skills- 5+ years of IT or information security experience
- 3+ years of experience leading or supporting Identity Governance and Administration (IGA) programs, including access certification campaigns
- Hands-on experience with Saviynt and/or SailPoint IdentityIQ
- Demonstrated experience implementing or overseeing Segregation of Duties (SoD) rules and Role Based Access Control (RBAC) frameworks
- Strong understanding of the principle of least privilege and its application within enterprise access governance programs
- Experience partnering with cross-functional teams, including application owners and Lines of Business, to gather and translate access governance requirement
Preferred Skills- Direct hands-on experience with Saviynt strongly preferred, given the organization's active migration from SailPoint IdentityIQ
- Experience leading application scoping and onboarding processes for an enterprise IGA platform
- Experience applying access certification controls to decentralized or manually managed applications outside of a centralized IGA tool
- Experience leveraging AI or machine learning capabilities to streamline access reviews, including outlier detection and access recommendation engines
- Experience governing access for Non-Human Identities (NHIs), such as service accounts, bots, or AI agents
- Bachelor's degree in Information Security, Computer Science, or a related field
Related Skills
Accountability, Adaptability, Business Continuity Planning, Cloud Computing Security, Collaboration, Communication, Compliance, Consultative Communication, Cybersecurity, Detail-Oriented, General Risk Management, Network Security, Prioritizes Effectively
Anticipated Posting End Date:2026-09-15
Base Pay Range: $108,000/yr - $130,000/yr
Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location. In addition to base salary, the competitive compensation package may include, depending on the role, participation in an incentive program linked to performance (for example, annual discretionary incentive programs, non-annual sales incentive plans, or other non-annual incentive plans).