Manager - IAM Engineering and Integration
About the role
Innovation isn’t just a talking point at GM Financial, it’s how we operate. From generative AI and cloud-native technologies to peer-led learning and hackathons, our tech teams are building real solutions that make a difference. We’re committed to AI-powered transformation, using advanced machine learning and automation to help us reimagine customer interactions and modernize operations, positioning GM Financial as a leader in digital innovation within a dynamic industry. Join us and discover a workplace where your ideas matter, your development is prioritized, and you can truly make a global impact.
Flexible hybrid work environment (onsite 2 days a week/3 days remote) at our Arlington (AOC1), TX office.
Please note: We are unable to provide any type of sponsorship for this position at this time.
Responsibilities
- IAM Platform Engineering & Integration
- Lead engineering, configuration, and lifecycle management of IAM platforms including Active Directory, SailPoint (IIQ and ISC), Okta, CyberArk, and PKI Services
- Oversee platform integrations with HR systems, ServiceNow, enterprise applications, cloud services, and third party vendors
- Ensure resilient, highly available, and scalable IAM architectures across on prem and cloud environments
- Establish reference architectures, integration patterns, and technical standards for IAM services
- Active Directory
- Provide technical and operational leadership for enterprise Active Directory services, including on premises and hybrid directory environments
- Own AD architecture, design standards, and operational patterns, ensuring alignment with Zero Trust, least privilege, and identity centric security models
- Oversee directory hygiene and lifecycle management, including user objects, service accounts, groups, and delegated administration models
- Lead AD group and service account governance, ensuring alignment with SailPoint driven identity lifecycle (Joiner Mover Leaver) processes and access certifications
- Partner with Identity Governance teams to ensure AD entitlements are authoritative, well modeled, and auditable within SailPoint
- Ensure secure integration between Active Directory and Okta, including federation, authentication flows, and directory synchronization
- Support and enhance privileged access controls for AD in coordination with CyberArk, including protection of domain level and Tier 0 privileged accounts
- Lead AD remediation and risk reduction efforts, including cleanup of legacy groups, orphaned accounts, excessive permissions, and insecure configurations
- Establish and maintain monitoring, alerting, and operational metrics for directory services availability, security posture, and access integrity
- Act as the escalation point for directory related incidents, audits, and compliance inquiries, ensuring timely remediation and root cause resolution
- Collaborate with Infrastructure, Endpoint, Cloud, and Security Architecture teams to ensure AD remains a foundational identity control plane for enterprise services
- Identity Governance & Lifecycle Management
- Own Joiner Mover Leaver (JML) automation, role based access control (RBAC), entitlement modeling, and access request workflows using SailPoint
- Ensure consistent execution of access certifications
- Partner with application owners and engineers to onboard applications into IAM governance and provisioning frameworks to ensure completeness and accuracy and entitlement metadata
- Assist in testing of lower environments
- Privileged Access & Authentication Services
- Lead implementation and ongoing enhancement of CyberArk for privileged account management, credential vaulting, and session monitoring
- Oversee Okta services including SSO, MFA, and API authentication for workforce and application access
- Ensure authentication services meet enterprise security, user experience, and regulatory requirements
- PKI & Certificate Services
- Manage enterprise PKI services, including certificate issuance, automation, renewal, and lifecycle management
- Ensure certificates are properly governed and integrated across applications, infrastructure, and security platforms
- Support certificate compliance requirements across the enterprise
- Security, Risk & Compliance
- Ensure IAM controls meet regulatory and audit requirements (e.g., SOX, internal cybersecurity standards)
- Support internal and external audits by providing evidence, walkthroughs, and remediation plans
- Understanding of look back efforts
- Proactively identify IAM risks and lead remediation of control gaps and vulnerabilities
- Lead the engineering, maintenance, and modernization of IAM platforms
- Identify mitigating controls to reduce risk
- Ensure compliance with internal policies, audit requirements, and regulatory frameworks
Qualifications
- Knowledge and Skills
- Deep knowledge of Identity and Access Management technologies across Active Directory, PKI, SailPoint, Okta, CyberArk, and modern authentication standards
- Strong understanding of identity governance frameworks, privileged access controls, certificate-based authentication, and directory services
- Ability to architect and guide the implementation of secure, scalable IAM solutions
- Experience leading complex engineering teams, including roadmapping, prioritization, and resource planning
- Solid understanding of Zero Trust principles, identity security best practices, audit requirements, and regulatory controls
- Ability to embed security-by-design into all IAM engineering processes
- Demonstrated experience managing high-performing technical teams and developing engineering talent
- Effective stakeholder communication and coordination across security, infrastructure, and application teams
- Strong problem-solving skills and ability to lead incident response related to IAM platforms
- Vendor relationship and contract management experience (particularly with SailPoint, Okta, CyberArk, and certificate authorities)
- Hands on experience with Active Directory/Azure AD, SailPoint IdentityIQ & ISC, Okta (SSO, MFA), CyberArk (PAM), PKI/Certificate Services
- Experience and Education
- 5-7 years in Identity and Access Management or related experience at a medium-to-large company required
- 3-5 years of experience in an IT leadership role preferred
- High School Diploma or equivalent required
- Bachelor’s Degree in related field or equivalent experience required
Benefits
- Generous benefits package available on day one to include: 401K matching
- Bonding leave for new parents (12 weeks, 100% paid)
- Tuition assistance
- Training
- GM employee auto discount
- Community service pay
- Nine company holidays
Culture
Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.
Compensation
Competitive pay and bonus eligibility
Work Life Balance
Flexible hybrid work environment, 2-days a week in office