Manager, Identity and Access Management; IAM
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, IT Consultant, Information Security & Data Protection
Florida Crystals Corporation is a fully integrated cane sugar company. Florida Crystals regeneratively farms sugarcane and rice in South Florida, where it owns two sugar mills, a sugar refinery, a packaging and distribution center, Florida's only rice mill, a compost facility, and one of the largest renewable power plants of its kind in the U.S., which uses sugarcane fiber to generate eco-friendly energy that powers its sugar operations.
Florida Crystals owns one of the largest Regenerative Organic Certified farms in the U.S. and its Florida Crystals products are the only ROC sugar grown and milled sugar in the country. Florida Crystals owns ASR Group International, Inc., a holding company that conducts operations through its subsidiaries. The ASR Group family of companies make up the world's largest refiner and marketer of cane sugar.
Florida Crystals is headquartered in West Palm Beach, Florida. Learn more at
The Identity and Access Management (IAM) Manager reports to the Sr. Director, Information Security (CISO) and serves as the enterprise leader for the IAM program across Florida Crystals / ASR Group. The role owns the strategy, roadmap, and day-to-day execution of Identity and Access Management, including
Microsoft Entra Entra , SAP Security across ECC,S/4
HANA, and SAP RISE, privileged access, joiner/mover/leaver processes, access certifications, and audit readiness. The primary focus is to mature and operate the IAM program with a strong emphasis on expert-level SAP Security, identity governance, and audit-defensible controls. This role leads a hybrid team consisting of an in-house Senior SAP Security Administrator, an in-house Senior IAM Engineer focused on Entra , and an outsourced team of SAP Security administrators executing SAP permissions changes under tight SLAs.
The IAM Manager partners closely with SAP BASIS and functional teams, Enterprise Architecture, HRIS, Internal Audit, and business leadership to advance the IAM architecture and execute the multi-year identity, governance, and SAP Security roadmap.
Roles & Responsibilities
- Lead, coach, and develop a hybrid IAM team, including in-house engineers and an outsourced SAP Security administration team of seven, with clear SLAs, quality standards, and escalation paths.
- Own the multi-year IAM roadmap aligned to the Zero Trust and enterprise security strategy, covering SAP Security, Entra , privileged access, and access certification modernization.
- Serve as the enterprise
SAP Security subject-matter expert
across ECC, S/4
HANA, BW/BI,RISE,Fiori,CIS, IAS,Sol Man, and GRC Access Control (ARA, ARM, BRM, EAM), including role designmethodology,SoDruleset, mitigation controls, and derivation strategy. - Direct the outsourced SAP admin team on day-to-day security operations, including role creation and change, user provisioning, license type assignment,FUE tracking,SU53/ST01 tracing, transport strategy, and emergency (firefighter) access.
- Oversee So Danalysis and remediation, critical authorization reviews, EWA security findings, and SAP Security Notes patching cadence in partnership with SAP Basis.
- Lead SAP Security work streams for upgrades, S/4
HANA transformations, greenfield and brownfield conversions, Fiori rollouts, and M&A integrations or divestiture carve-outs. - Own the Microsoft Entra platform, including entitlement management, access packages, access reviews, lifecycle workflows, and Privileged Identity Management (PIM), and drive the broader IGA strategy.
- Drive automation of joiner/mover/leaver processes across HRIS (Success Factors), Entra, Active Directory, SAP, and downstream SaaS applications, applying least-privilege and zero-trust principles.
- Define and enforce access certification cadences for privileged, sensitive, and regulated application access, and mature RBAC/ABAC models, conditional access, and least-privilege enforcement enterprise-wide.
- Lead the IAM response to internal audit, external audit (ITGC), SOX-style controls, NIS 2, GDPR, and cyber insurance requirements, including control design, evidence collection, and remediation.
- Set priorities across competing operational, audit, and project demands with clear…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).