
Manager, IT Security Engineering, IAM
United States - California - Foster CityInformation TechnologyRegularJob Description
Essential Job Functions:
Owns enterprise IAM control effectiveness, ensuring identity governance, certification, and access controls are consistently enforced, measurable, and audit-ready across systems and data domains.
Leads and governs DOJ Data Security Program (DSP) IAM controls, including definition, implementation, and ongoing validation of access restrictions protecting sensitive and regulated data.
Drives and matures access certification programs, including campaign strategy, execution oversight, reviewer accountability, exception governance, and remediation enforcement.
Owns role-based access control (RBAC) strategy and execution, including role engineering, role lifecycle management, and alignment to least privilege and compliance requirements.
Establishes and enforces standardized access models and certification scope across enterprise and cloud applications, ensuring consistency and scalability.
Oversees identity lifecycle management (joiner, mover, leaver) as a controlled process, ensuring timely and accurate provisioning aligned with authoritative data sources and governance policies.
Provides leadership over IAM operations, including access request fulfillment, incident/problem management, and operational issue resolution across integrated platforms.
Acts as service owner for IAM platforms, accountable for availability, performance, control enforcement, and continuous service improvement.
Manages managed service providers and vendors supporting IAM, including defining SLAs/KPIs, monitoring performance, and enforcing delivery accountability.
Drives onboarding of applications into IAM platforms with a focus on RBAC alignment, certification inclusion, and governance standardization, reducing control gaps.
Ensures IAM processes and controls support audit, compliance, and regulatory readiness, including GxP and 21 CFR Part 11 requirements.
Partners with Security, Architecture, and business stakeholders to evolve IAM control frameworks and improve governance effectiveness across the enterprise.
Identifies and implements improvements to IAM processes, tools, and operating models to enhance control maturity, operational efficiency, and scalability.
Required Skills & Job Qualifications:
Bachelor’s degree plus 6+ years of IT and/or Information Security experience.
Strong experience owning and operating IAM governance and control functions, including certification and RBAC at enterprise scale.
Hands-on experience with IAM platforms such as SailPoint IdentityIQ, SailPoint Identity Security Cloud, or Saviynt.
Deep experience with access certification programs, RBAC design, and identity lifecycle governance.
Understanding of regulatory-driven IAM controls, including DOJ DSP, GxP, and 21 CFR Part 11.
Experience leading IAM operations and service delivery in complex, hybrid enterprise environments.
Working knowledge of directory services (Active Directory, LDAP) and application integration patterns.
Preferred Skills:
Experience in pharmaceutical, biotech, or life sciences environments.
Familiarity with evolving access control models (e.g., ABAC) and modern IAM architectures.
Experience supporting regulatory audits and control validation activities.
Broad knowledge of enterprise IT systems, cloud platforms, and application architectures.