Jobs · OTHR · Massachusetts

Manager, Identity & Access Management

Digital Federal Credit Union · Marlborough, MA · 1 wk ago
On-siteOTHR$117k–$140k/yrFull-time

About the role

The Manager, Identity Access Management (IAM) oversees the organization's identity and access management risk framework and provides independent Second Line of Defense (2LOD) oversight of identity governance, access controls, privileged access management, and authentication practices. This role ensures IAM risks are appropriately identified, assessed, monitored, and managed in accordance with regulatory expectations, industry standards, and organizational risk appetite. The position partners closely with Information Technology, Cybersecurity, Internal Audit, Compliance, and business stakeholders to evaluate IAM control effectiveness, assess emerging risks, and strengthen identity governance practices.

Responsibilities

  • Oversee the IAM risk management program, including governance, risk assessments, control evaluations, and monitoring activities.
  • Evaluate the design and effectiveness of identity and access management controls, including user provisioning, deprovisioning, role-based access controls, privileged access management, segregation of duties, and authentication controls.
  • Provide independent challenge and oversight of first-line IAM processes and access governance decisions.
  • Conduct risk assessments of IAM processes, technologies, systems, and emerging identity-related threats.
  • Monitor IAM-related risk indicators, control performance metrics, exceptions, and remediation activities.
  • Oversee periodic access certification and governance processes, ensuring compliance with policies and regulatory requirements.
  • Review and challenge privileged access management programs, identity lifecycle management processes, and authentication controls.
  • Partner with Information Security, Technology, Compliance, and Internal Audit to evaluate control effectiveness and remediation plans.
  • Support regulatory examinations, audits, and independent reviews involving access management and cybersecurity controls.
  • Develop and deliver reporting on IAM risk exposure, control effectiveness, and emerging risks to leadership and governance forums.
  • Support development and maintenance of IAM risk policies, standards, and governance documentation.
  • Identify opportunities to improve IAM governance, risk management practices, and control maturity.

Requirements

  • Bachelor's degree in a field relevant to the role (or 4 additional years of relevant experience in lieu of a degree); advanced degree preferred.
  • 5+ years of relevant experience, with 0-2 years as a People Leader.
  • Strong understanding of IAM governance and controls.
  • Knowledge of access management, privileged access management, authentication, and identity lifecycle management.
  • Understanding of cybersecurity frameworks (NIST, FFIEC, ISO, CIS).
  • Experience assessing technology and cybersecurity risks.
  • Strong analytical and problem-solving skills.
  • Ability to influence stakeholders and provide effective challenge.
  • Experience supporting audits, examinations, and regulatory reviews.

Preferred Qualifications

  • Certifications: CISSP, CISA, CRISC, CISM.

Location

Marlborough or Chelmsford, MA | Hillsboro, OR (HYBRID)

Pay

Target compensation: $116,500 - $140,000 + annual bonus

Schedule

Monday through Friday, 8:00 AM – 5:00 PM

Benefits

  • Traditional medical, dental, and vision coverage.
  • Generous 401(k) match.
  • Paid Time Off: Up to 15 days accrued in your first year, plus 40 hours of sick time and 3 personal days (refreshed annually).
  • Paid federal holidays.
  • Special employee pricing on lending products such as mortgage, auto, and personal loans (eligibility subject to standard account requirements and underwriting criteria).

Similar jobs