Jobs · OTHR

Director, Identity & Access Management

DataSpring · Washington, DC · 4 wk ago
RemoteRemoteOTHRFull-time

Position Summary

The Director of Identity and Access Management (IAM) is a senior technical and strategic leadership position responsible for designing, governing, and continuously maturing the organization's IAM program across a 100% cloud-native, fully remote environment. This leader serves as the company's authoritative voice on all matters of identity — spanning human identities (employees, consultants, customers, and partners) and the rapidly expanding population of non-human identities (NHIs) including service accounts, API keys, workload credentials, and agentic AI systems.

Specific Responsibilities

  • IAM Strategy & Program Leadership

    • Define and own the multi-year IAM strategy, roadmap, and investment plan aligned with business objectives, Zero Trust principles, and healthcare regulatory requirements.
    • Establish governance frameworks for all identity types: workforce, partner/customer (CIAM), privileged (PAM), and non-human/machine identities including AI agents and ML workloads.
    • Develop and maintain IAM policies, standards, and procedures across the organization and enforce adherence through governance processes.
    • Lead annual and continuous access certification and entitlement review programs covering employees, contractors, and third parties.
    • Own the IAM risk register; identify, assess, prioritize, and remediate access-related risks in collaboration with the broader security and risk teams.
  • Non-Human Identity & Agentic AI Governance

    • Establish a comprehensive Non-Human Identity (NHI) governance program covering service accounts, API tokens, certificates, OAuth clients, workload identities, and agentic AI identities.
    • Design and enforce identity controls for agentic AI and ML pipeline workflows, ensuring least-privilege, just-in-time (JIT) access, and dynamic permission scoping for autonomous agents that chain actions across systems.
    • Implement continuous discovery and inventory of all NHIs across cloud platform (Azure) and SaaS applications; eliminate shadow credentials and unmanaged secrets.
    • Define AI agent identity lifecycle standards: provisioning, scoping, monitoring, credential rotation, and decommissioning.
    • Partner with AI/ML Engineering and Product to embed identity governance requirements into the SDLC for all agentic and automated systems.
  • Architecture & Technical Oversight

    • Oversee architecture, integration, and operations of IAM platforms including IdP (Okta, Azure Entra ID), IGA, PAM, and secrets management.
    • Lead the design and enforcement of authentication standards: MFA, passwordless, FIDO2/WebAuthn, SAML 2.0, OAuth 2.0/OIDC, and SCIM-based provisioning.
    • Govern cloud entitlement management (CIEM) to enforce least-privilege and prevent privilege sprawl.
    • Own directory services strategy; oversee user provisioning, de-provisioning, role lifecycle, and RBAC/ABAC model design.
    • Ensure cryptographic asset management (PKI, certificate lifecycle, key management) is operationally sound and audit-ready.
  • Customer & Partner Identity (CIAM)

    • Lead the Customer Identity and Access Management (CIAM) strategy for external users including healthcare customers, partners, and integration endpoints.
    • Ensure CIAM solutions deliver secure, low-friction authentication experiences.
    • Define partner federation standards and govern third-party access lifecycle from onboarding through offboarding.
  • Compliance, Audit & Risk

    • Ensure IAM program compliance with HIPAA/HITECH, SOC 2 Type II, HITRUST CSF, NIST 800-63 (Digital Identity Guidelines), ISO 27001, and applicable state privacy laws (CCPA, etc.).
    • Serve as the IAM subject-matter expert during audits, assessments, and regulatory examinations; own audit evidence collection and remediation of findings.
    • Partner with Legal and Privacy teams on access-related data governance, breach response procedures, and regulatory reporting obligations.
    • Monitor threat intelligence and ITDR (Identity Threat Detection & Response) signals; drive timely response to identity-based attack indicators.
  • Team Leadership & Culture

    • Recruit, develop, and retain a high-performing team of IAM engineers, analysts, and architects; build a culture of ownership, continuous learning, and operational excellence.
    • Define and track team KPIs, OKRs, and SLA/SLO metrics tied to identity program health and security posture improvements.
    • Act as an IAM evangelist internally, educating stakeholders across the business on identity risk and enabling security-conscious behavior.

    Skills

    • Deep expertise in at least two major IAM platforms
    • Hands-on knowledge of IGA platforms
    • PAM platform experience
    • Secrets management and NHI tooling
    • Proficiency in authentication protocols and standards: OAuth 2.0, OIDC, SAML 2.0, SCIM, LDAP, Kerberos, FIDO2/WebAuthn
    • CIEL and cloud identity posture management experience (Wiz CIEM or native cloud tooling)
    • Familiarity with IAM considerations for AI/ML workloads, agentic architectures, and machine-to-machine identity patterns
    • Scripting and automation capability in Python, PowerShell, Bash, or similar; ability to review and direct infrastructure-as-code (Terraform, CloudFormation) with IAM implications
    • Solid understanding of Zero Trust architecture principles and their application to identity

    Experience & Education

    • 10+ years of progressive experience in Identity and Access Management, cybersecurity, or adjacent disciplines.
    • 4+ years in a senior leadership role managing IAM teams, programs, or practices.
    • Demonstrated experience in a cloud-native or 100% cloud-based environment (AWS, Azure, or GCP at scale).
    • Prior experience in a healthcare, life sciences, or similarly regulated industry strongly preferred.
    • Proven track record designing or governing IAM in environments serving multiple user populations (workforce, customers, partners, third parties, automated systems).
    • Bachelor’s degree preferred.
    • Relevant industry certifications in – CISSP, CISM, CCSP certifications preferred.

Similar jobs