Job DescriptionAs Senior Manager, Identity and Access Management, you own the strategy, architecture, governance, and daily operation of the enterprise IAM program within Information Security. The scope is the full program: identity governance and administration, access management and federation, privileged access management, identity threat detection and security posture management, and enterprise certificate lifecycle services. It spans every population the university serves - workforce, students and learners, external partners, and the fast-growing set of non-human identities, including service accounts, enterprise secrets, and AI agents.
You will lead a team of identity engineers and analysts, set the technical standards other teams build against, and partner with Human Resources, Legal, Privacy, Internal Audit, Infrastructure, and Application Development. You will also be accountable for the reliability of authentication and other IAM services, which the university treats as tier-one dependencies.
What You'll Own - Program strategy and direction. The IAM strategy, capability roadmap, and program priorities, along with the business case and executive sponsorship behind them.
- Team leadership. Leading, coaching, and developing a team of identity engineers and analysts, including hiring, goal setting, and performance management.
- Identity governance and lifecycle. Automated joiner, mover, and leaver processes driven by authoritative human resources, student, and affiliate systems of record; the enterprise identity data model and registry of record; role and entitlement design; separation-of-duties policy; and access certification through closed-loop remediation.
- Authentication and federation. Single sign-on, multi-factor and passwordless authentication, federation with partners and peer institutions, and accessible authentication and account recovery paths for every population the university serves.
- Privileged and non-human identity. Credential vaulting, session control, just-in-time elevation, break-glass procedures, and reduction of standing privilege - extended to service accounts, enterprise secrets, and the authorization boundaries of AI agents and autonomous workloads.
- Identity security operations. Identity threat detection and response, identity security posture management, remediation of permission drift and orphaned accounts, and the identity lead role during security incident response.
- Service reliability. Availability, resilience, and disaster recovery for authentication and other IAM services, including defined service levels and tested failover.
- Policy, compliance, and audit. Access control policy and standards, identity governance and exception adjudication, least-privilege access under FERPA, GLBA, and PCI DSS, control mapping against the NIST Cybersecurity Framework and NIST SP 800-53, and audit and assessor response.
- Architecture and standards. IAM reference architecture, technical standards, and integration patterns, including review and approval of new identity designs proposed by project and application teams.
What You'll Bring - A bachelor's degree in a related field and 7 years of information security or identity and access management experience, or 10 years of industry experience working in security.
- Hands-on experience in identity and access management, including developing or leading an IAM program.
- 3+ years of people leadership experience.
- One or more industry security certifications (CISSP, CISM, or a recognized identity and access management certification).
- Depth in identity governance and administration: lifecycle automation, provisioning, role and entitlement design, access certification, and separation of duties.
- Command of identity and access standards, including SAML, OpenID Connect, OAuth 2.0, SCIM, and LDAP, and of multi-factor and passwordless authentication.
- Experience with privileged access management, including credential vaulting, session control, and privilege reduction.
- Experience governing non-human identities, service accounts, and enterprise secrets.
- Experience with certificate lifecycle management and the public key infrastructure supporting service, device, and workload identity.
- Working knowledge of enterprise directory services and how they integrate with identity platforms.
- Knowledge of NIST, HIPAA, FERPA, GLBA, ISO, PCI DSS, and other regulatory and industry standards.
- The ability to explain complex security problems to business partners in terms they can act on.
What Will Set You Apart - A master's degree in a related field.
- Certification in an identity-focused discipline or an enterprise identity platform.
- Identity and access management experience in higher education, or another environment with overlapping workforce, student, and affiliate populations.
- Experience with identity threat detection and response or identity security posture management.
#LI-Aw2
Position & Application DetailsFull-Time Regular Positions (classified as regular and working 40 standard weekly hours): This is a full-time, regular position (classified for 40 standard weekly hours) that is eligible for bonuses; medical, dental, vision, telehealth and mental healthcare; health savings account and flexible spending account; basic and voluntary life insurance; disability coverage; accident, critical illness and hospital indemnity supplemental coverages; legal and identity theft coverage; retirement savings plan; wellbeing program; discounted WGU tuition; and flexible paid time off for rest and relaxation with no need for accrual, flexible paid sick time with no need for accrual, 11 paid holidays, and other paid leaves, including up to 12 weeks of parental leave.
How to Apply: If interested, an application will need to be submitted online. Internal WGU employees will need to apply through the internal job board in Workday.
Additional InformationDisclaimer: The job posting highlights the most critical responsibilities and requirements of the job. It's not all-inclusive.