Manager, Identity and Access Management
NorthMark Compute & Cloud · Dallas, TX · 2 wk ago
Information TechnologyFull-time
About the role
The Identity and Access Management team sits within NMC²'s Security organization and is responsible for ensuring that every human, service, and workload interacting with NMC²'s platforms is verifiably identified, appropriately authorized, and continuously validated. As the Manager of Identity and Access Management, you will lead a team of engineers responsible for the full spectrum of identity from enterprise identity and access governance to workload and service identity using cryptographic attestation via SPIFFE/SPIRE, mTLS, and PKI.
Responsibilities
- Lead, mentor, and develop a team of IAM engineers, setting clear priorities, fostering technical growth, and cultivating a collaborative, high-performing team culture
- Own the strategy and roadmap for NMC²'s enterprise identity program, including identity lifecycle management, role-based access control (RBAC), privileged access management (PAM), and access governance across Microsoft Entra ID and connected systems
- Drive the design, implementation, and operation of workload and service identity programs using SPIFFE/SPIRE, ensuring cryptographically verifiable identity for services, workloads, and infrastructure components across HPC and cloud environments
- Oversee the organization's PKI strategy and certificate lifecycle management program, ensuring the integrity, availability, and scalability of certificate issuance, rotation, and revocation across the enterprise
- Lead the adoption and enforcement of mTLS for service-to-service communication, partnering with Platform Engineering and DevOps teams to embed mutual authentication into the fabric of NMC²'s distributed systems
- Drive NMC²'s zero trust identity strategy, ensuring continuous validation of user, device, and workload identity as the primary access control mechanism across on-premises and cloud environments
- Partner with Platform Engineering, DevOps, and IT leadership to integrate IAM controls into CI/CD pipelines, IaC workflows, and platform architecture, ensuring identity is never bolted on as an afterthought
- Establish and maintain identity governance frameworks, including access reviews, entitlement management, and least-privilege enforcement across both human and non-human identities
- Translate complex identity risks, program metrics, and strategic initiatives into clear, concise reporting for security leadership and executive stakeholders
- Stay current on emerging identity threats, standards, and technologies — including evolving SPIFFE/SPIRE ecosystem developments, certificate transparency, and zero trust frameworks — continuously maturing the team's capabilities
Requirements
- 6+ years of experience in identity and access management or security engineering, with hands-on depth across both enterprise and workload identity domains
- 2–3+ years of experience leading or managing an IAM or security engineering team, with demonstrated ability to develop talent and drive team performance
- Deep expertise in Microsoft Entra ID (Azure AD), including conditional access, identity governance, privileged identity management (PIM), and enterprise application integration
- Hands-on experience with SPIFFE/SPIRE or equivalent workload identity frameworks, and a strong understanding of cryptographic identity attestation in distributed and containerized environments
- Strong command of PKI fundamentals, including certificate authority design, certificate lifecycle management, and certificate issuance patterns for large-scale environments
- Experience designing and enforcing mTLS architectures for service-to-service communication across microservices, container orchestration platforms, and cloud-native environments
- Familiarity with zero trust architecture principles and experience applying them across a hybrid enterprise and cloud-native environment
- Experience with privileged access management solutions and least-privilege enforcement strategies across both human and service accounts
- Excellent communication skills with the ability to translate complex identity concepts and risks into clear reporting and recommendations for engineering peers and executive leadership
Nice to Have
- Experience with secrets management platforms such as HashiCorp Vault, with integration into PKI and workload identity workflows
- Background working in HPC, research computing, or highly regulated environments where identity assurance requirements are exceptionally stringent
- Familiarity with certificate transparency logs and emerging standards in machine identity management
- Relevant certifications such as CISSP, CISM, Microsoft Certified: Identity and Access Administrator, or equivalent