More jobs:
Dir, Identity & Access Mgmt; IAM
Job in
Des Moines, Polk County, Iowa, 50309, USA
Listed on 2026-06-01
Listing for:
Berkshire Hathaway Energy
Full Time
position Listed on 2026-06-01
Job specializations:
-
IT/Tech
Systems Engineer, Cybersecurity
Job Description & How to Apply Below
Job Description
The Director of Identity & Access Management (IAM) is accountable for the delivery, effectiveness, and ongoing maturity of enterprise workforce identity, secrets, and certificate management platforms. This role ensures secure, reliable, and automated access to systems, applications, and collaboration tools across a hybrid cloud, multi affiliate environment.
Aligned to the Infrastructure & Operations Platform vision, this leader transforms legacy, fragmented and manual identity practices into standardized, policy driven, and automated enterprise services that reduce operational toil, improve resilience, and strengthen regulatory compliance. The role partners closely with Platform Engineering, Security, HR, and Application teams to ensure identity related capabilities are engineered as scalable, consumable, and reliable platforms.
This position drives both technical modernization and enterprise change, standardizing identity practices across historically decentralized affiliates while balancing local regulatory and operational needs.
Responsibilities
1. Enterprise IAM Strategy & Transformation
- Define and execute a multi-year IAM modernization roadmap aligned with I&O Platform priorities for reliability, automation, toil reduction, and cost efficiency.
- Lead the transition from affiliate-specific identity practices to a standardized enterprise workforce identity platform.
- Drive organizational and cultural change required to adopt consistent identity standards across decentralized affiliates.
- Establish workforce identity, secrets, and certificate services as foundational shared capabilities supporting enterprise operations and modernization initiatives.
- Accountable for enterprise workforce identity services, including:
- Identity lifecycle management (Joiner / Mover / Leaver)
- Directory services (e.g., Entra , Active Directory)
- IAM services (Saviynt, SailPoint, MIM)
- Single Sign-On (SSO) and Multi-Factor Authentication (MFA)
- Privileged access management (PAM)
- Own enterprise secrets and certificate management platforms as they relate to workforce identity and shared enterprise services, including lifecycle management, rotation, availability, and monitoring.
- Establish enterprise standards and guardrails for secrets and certificate usage in partnership with Platform Engineering for workload and runtime use cases.
- Ensure HR-driven identity is the authoritative source for workforce provisioning and de-provisioning.
- Ensure platforms are engineered for high availability, disaster recovery, and operational continuity.
- Drive API-first and event-driven identity architecture enabling integration with enterprise platforms and developer workflows.
- Promote infrastructure-as-code and policy-as-code approaches for identity, access, secrets, and certificates.
- Integrate IAM capabilities into CI/CD pipelines and application delivery processes where appropriate.
- Replace ticket-driven operations with automated, self-service workflows.
- Define and track metrics such as time-to-provision, automation coverage, and reduction in manual access handling.
- Design and operate scalable identity governance capabilities including access certifications, role governance, and segregation-of-duties controls.
- Ensure IAM capabilities support SOX, NERC-CIP, and other regulatory requirements.
- Accountable for the design, effectiveness, and continuous improvement of workforce identity access controls.
- Partner with Security and Internal Audit on control testing, regulatory examinations, and remediation activities.
- Establish a centralized IAM platform with federated execution across affiliates.
- Align affiliates to enterprise identity, secrets, and certificate standards through policies, patterns, and approved configurations.
- Serve as the primary IAM point of integration for leadership, HR, and application owners.
- Partner with Platform Engineering on shared identity architecture principles and integration standards.
- Clearly…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×