×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

AVP IAM & Governance

Job in Northern, Floyd County, Kentucky, USA
Listing for: HealthEquity, Inc.
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 244000 - 270000 USD Yearly USD 244000.00 270000.00 YEAR
Job Description & How to Apply Below
Our Mission

Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS.
Come be part of remarkable.

Overview How You Can Make a Difference

The AVP, Identity & Access Management, the enterprise authority on identity — the architect, evangelist, and operational owner of an identity-first security model in which identity is the control plane for a cloud-first, zero trust enterprise.

This leader defines and executes a multi-year B2E IAM strategy spanning identity governance and administration (IGA), privileged access management (PAM), customer and workforce access management, non-human/machine identity, and identity threat detection and response (ITDR), and is accountable for the engineering rigor, control effectiveness, and audit posture of the entire identity fabric.

This is a role for a practitioner-leader and recognized thought leader: someone who has designed and operated identity programs at scale, who is fluent in modern identity standards and protocols (OAuth 2.0, OIDC, SAML 2.0, SCIM, FIDO2/Web Authn), who can whiteboard an authorization model one hour and defend a control posture to auditors and executives the next, and who actively shapes the direction of the identity discipline — inside the organization and in the broader industry — through published points of view, standards engagement, and community leadership.

What

You’ll be Doing
  • Identity Strategy & Thought Leadership:
    • Own and evangelize a multi-year AI led identity strategy and reference architecture that treats identity as the primary security perimeter, aligned to zero trust principles (NIST SP 800-207) and enterprise business objectives.
    • Serve as the organization's most senior voice on identity: publish internal position papers and architectural decision records, brief executive leadership and the Board on identity risk, and represent the company externally through industry forums, standards bodies, conference speaking, and peer communities.
    • Anticipate and translate emerging shifts — decentralized identity, verifiable credentials, passwordless/phishing-resistant authentication, AI-agent and workload identity, continuous access evaluation (CAEP/Shared Signals) — into pragmatic roadmap decisions with clear build/buy/retire rationale.
  • Organizational Leadership:
    • Build, lead, and mentor a high-performing team of IAM architects, engineers, and analysts; establish engineering career paths, on‑call/operational maturity, and a culture of automation‑first identity operations.
    • Operate identity as a product: define OKRs and SLOs for identity services (provisioning latency, certification completion, authentication availability, orphaned‑account rates), and manage a prioritized backlog with IT, HR, Legal, Compliance, and business‑line stakeholders.
  • Identity Governance & Administration (IGA):
    • Architect and operate the full identity lifecycle — joiner/mover/leaver (JML) automation driven by authoritative HR sources, birthright provisioning, SCIM‑based downstream integration, and deprovisioning SLAs measured in minutes to hours.
    • Design and mature the enterprise access model using Agentic AI capabilities: role engineering and role mining, RBAC evolving toward attribute‑and‑policy‑based access control (ABAC/PBAC), segregation‑of‑duties (SoD) rulesets, and risk‑based, evidence‑quality access certifications that eliminate rubber‑stamping.
    • Own governance of entitlement sprawl across SaaS, IaaS, and on‑prem estates, including cloud infrastructure entitlement management (CIEM) and least‑privilege enforcement in AWS/Azure environments.
  • Authentication, Authorization & Directory Architecture:
    • Set the enterprise standard for authentication: phishing‑resistant MFA (FIDO2/Web Authn), passwordless adoption, adaptive/risk‑based authentication, and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary