Senior Director, Identity Access Management & Data Security Engineering
Listed on 2026-07-06
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Company Overview
Zelis is modernizing the healthcare financial experience across payers, providers, and healthcare consumers. We serve more than 750 payers, including the top five national health plans, regional health plans, TPAs and millions of healthcare providers and consumers across our platform of solutions.
Position OverviewThe Senior Director of Identity Access Management (IAM) & Data Security Engineering is a senior leadership role responsible for the strategy, architecture, engineering, and operations of enterprise-wide identity, access, and data protection programs. The role will report to the Global CISO and is part of the Cyber Leadership Team. Operating at the intersection of healthcare and financial technology, this leader will ensure that our platforms meet the stringent security and compliance requirements of HIPAA, PCI-DSS, SOC 2, and other applicable frameworks while enabling a frictionless experience for internal users, partners, and patients.
This executive will build and scale a world‑class engineering team, partner closely with Product, Infrastructure, Legal, and Compliance leadership, and serve as the subject‑matter authority for IAM and data security across the organization.
- Lead, mentor, and grow a multi-disciplinary team of engineers, architects, and analysts across IAM and data security domains both in the US and India.
- Define team structure, hiring roadmap, and career development frameworks to attract and retain top security engineering talent.
- Foster a culture of ownership, continuous learning, and security‑first engineering.
- Serve as a visible advocate for security engineering practices across engineering and product organizations.
- Develop a multi‑year IAM and data security roadmap aligned to business growth, M&A integration, and regulatory evolution.
- Own the end‑to‑end IAM strategy covering workforce identity, customer identity (CIAM), privileged access management (PAM), and machine/service identity.
- Architect and deliver Zero Trust access models, MFA enforcement, SSO, RBAC/ABAC policies, and identity federation across cloud and on‑premises environments.
- Drive adoption of modern identity standards including OAuth
2.0, OpenIDConnect, SAML, SCIM, and FIDO2/Web Authn. - Oversee privileged access governance and just‑in‑time access workflows for production healthcare and financial systems.
- Lead the evaluation, selection, and operationalization of IAM platforms (e.g., MFA, IGA, PAM, Non Human Identity, etc.).
- Develop and execute a comprehensive data security strategy spanning data classification, data loss prevention (DLP), encryption at rest and in transit, tokenization, and secrets management.
- Ensure robust protection of Protected Health Information (PHI) and Personally Identifiable Financial Information (PIFI) across all data stores, pipelines, and APIs.
- Lead implementation and enforcement of data access governance, including automated discovery, tagging, and lineage for sensitive data across cloud data lakes and warehouses.
- Partner with data engineering and ML teams to embed privacy‑by‑design and security‑by‑design principles into data platform architectures.
- Ensure IAM and data security controls satisfy HIPAA/HITECH, PCI‑DSS, SOC2 TypeII, NIST
800‑53, ISO
27001, and state data privacy laws. - Own the IAM and data security sections of audit readiness programs, regulatory examinations, and third‑party assessments.
- Define metrics, KPIs, and executive dashboards to communicate program health and risk posture to the CISO, CTO, and Board.
- Partner with Legal and Privacy teams on data breach response, regulatory notifications, and privacy impact assessments.
- Collaborate with Infrastructure, Dev Ops, and Platform Engineering to embed security controls natively into CI/CD pipelines and cloud infrastructure (IaC).
- Evaluate and manage relationships with security technology vendors, MSSPs, and industry partners.
- Represent the organization in industry forums, regulatory engagements, and partner/customer security reviews.
- 12+ years of progressive experience in information security, with at least 5 years in a senior leadership role managing security engineering teams.
- Deep…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).