United States flag

Manager, IT Security Engineering, IAM

United States - California - Foster CityInformation TechnologyRegular

Job Description

Essential Job Functions:

  • Owns enterprise IAM control effectiveness, ensuring identity governance, certification, and access controls are consistently enforced, measurable, and audit-ready across systems and data domains.

  • Leads and governs DOJ Data Security Program (DSP) IAM controls, including definition, implementation, and ongoing validation of access restrictions protecting sensitive and regulated data.

  • Drives and matures access certification programs, including campaign strategy, execution oversight, reviewer accountability, exception governance, and remediation enforcement.

  • Owns role-based access control (RBAC) strategy and execution, including role engineering, role lifecycle management, and alignment to least privilege and compliance requirements.

  • Establishes and enforces standardized access models and certification scope across enterprise and cloud applications, ensuring consistency and scalability.

  • Oversees identity lifecycle management (joiner, mover, leaver) as a controlled process, ensuring timely and accurate provisioning aligned with authoritative data sources and governance policies.

  • Provides leadership over IAM operations, including access request fulfillment, incident/problem management, and operational issue resolution across integrated platforms.

  • Acts as service owner for IAM platforms, accountable for availability, performance, control enforcement, and continuous service improvement.

  • Manages managed service providers and vendors supporting IAM, including defining SLAs/KPIs, monitoring performance, and enforcing delivery accountability.

  • Drives onboarding of applications into IAM platforms with a focus on RBAC alignment, certification inclusion, and governance standardization, reducing control gaps.

  • Ensures IAM processes and controls support audit, compliance, and regulatory readiness, including GxP and 21 CFR Part 11 requirements.

  • Partners with Security, Architecture, and business stakeholders to evolve IAM control frameworks and improve governance effectiveness across the enterprise.

  • Identifies and implements improvements to IAM processes, tools, and operating models to enhance control maturity, operational efficiency, and scalability.

Required Skills & Job Qualifications:

  • Bachelor’s degree plus 6+ years of IT and/or Information Security experience.

  • Strong experience owning and operating IAM governance and control functions, including certification and RBAC at enterprise scale.

  • Hands-on experience with IAM platforms such as SailPoint IdentityIQ, SailPoint Identity Security Cloud, or Saviynt.

  • Deep experience with access certification programs, RBAC design, and identity lifecycle governance.

  • Understanding of regulatory-driven IAM controls, including DOJ DSP, GxP, and 21 CFR Part 11.

  • Experience leading IAM operations and service delivery in complex, hybrid enterprise environments.

  • Working knowledge of directory services (Active Directory, LDAP) and application integration patterns.

Preferred Skills:

  • Experience in pharmaceutical, biotech, or life sciences environments.

  • Familiarity with evolving access control models (e.g., ABAC) and modern IAM architectures.

  • Experience supporting regulatory audits and control validation activities.

  • Broad knowledge of enterprise IT systems, cloud platforms, and application architectures.