Director, Identity & Access Management
Listed on 2026-10-01
-
IT/Tech
Cybersecurity
Asset Mark is establishing a centralized Enterprise Identity & Access Management (IAM) function to strengthen access controls, reduce risk, improve audit and regulatory readiness, and create scalable identity services across the enterprise. The Director of Identity & Access Management will build and lead this function and own the IAM strategy, operating model, architecture, engineering, governance, delivery, and service roadmap. The Director will lead identity services across on-premises Active Directory, Microsoft Entra , Azure, Microsoft 365, business applications, endpoints, collaboration platforms, and data services.
The Job/What You'll Do:
This is a hands‑on technical leadership role for a leader who can establish strategy while remaining close enough to the technology to guide architecture, solve complex identity challenges, challenge designs, lead major implementations, and help the team deliver.
The Director will initially lead a focused team of three IAM Engineers and one IAM Compliance/Controls resource and will partner extensively with Cybersecurity, Infrastructure, HR, Risk & Compliance, Internal Audit, application teams, and business/data owners.
The successful Director will transform IAM from distributed access activities into a centralized enterprise capability.
Early priorities include establishing the IAM operating model, strengthening lifecycle and termination controls, defining identity, group, role, permission, SharePoint, and data‑classification standards, establishing Purview governance and control evidence, and prioritizing the technology roadmap.
We can only consider candidates for this position who are able to accommodate a hybrid work schedule and are close to our Charlotte, NC office.
Key ResponsibilitiesBuild and lead Asset Mark's centralized enterprise IAM function, including its strategy, operating model, service catalog, technology roadmap, engineering standards, governance practices, budget, vendors, and delivery partners. Establish clear ownership across IAM Engineering, Directory Services, Identity Governance, Privileged Access, IAM Automation, and Compliance/Controls. Define the target‑state identity architecture and multi‑year roadmap for hybrid identity modernization, Zero Trust, least privilege, secure‑by‑design access, SSO, federation, MFA, passwordless authentication, identity governance, and application integration.
Reduce legacy dependencies and create consistent identity patterns across the enterprise. Lead the design and maturation of Identity Governance & Administration capabilities, including joiner, mover, leaver, contractor, partner, rehire, and non‑person identity lifecycle processes; authoritative‑source integration; access requests and approvals; birthright access; provisioning and deprovisioning; certifications; entitlement governance; role management; segregation of duties; and automated workflows using standards such as SCIM where appropriate.
Provide strategic and technical leadership for Microsoft Entra Active Directory, including directory architecture, identity synchronization through Entra Connect Sync or Cloud Sync, authentication, authorization, Conditional Access, MFA, passwordless authentication, Windows Hello for Business, self‑service password reset, federation, external identities, identity protection, and identity governance. Establish governance and operating standards for Active Directory organizational units, naming conventions, delegation, administrative boundaries, directory roles, domain controllers, trusts, DNS dependencies, and lifecycle management.
Oversee Group Policy design, management, testing, documentation, exception handling, recovery, and change control. Establish secure authentication…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).