- Company Name
- Cross River
- Job Title
- VP, Identity & Access Management
- Job Description
-
**Job title**
VP, Identity & Access Management
**Role Summary**
Lead the design, governance, and execution of a modern, risk‑aligned IAM program across cloud, on‑premises, and SaaS environments. Own the IAM vision, roadmap, and architecture; build a high‑performing team; and partner with security, compliance, engineering, and business units to enable automated, least‑privilege identity lifecycle management and secure access governance.
**Expectations**
- 10+ years of IAM/Information Security/IT Risk experience with 3+ years in people management or technical leadership.
- Proven ability to develop and implement enterprise‑wide IAM strategy in a regulated environment.
- Deep knowledge of IAM platforms (e.g., SailPoint, Saviynt, Azure AD, Okta, CyberArk) and modern identity protocols (SAML, OAuth2, OIDC, SCIM).
- Demonstrated experience in automating Joiner‑Mover‑Leaver (JML) workflows, RBAC/ABAC, SSO, MFA, and privileged access management.
- Strong communication, influencing, and documentation skills to evangelize IAM to technical and business stakeholders.
- Familiarity with scripting (PowerShell, Python) and integration with HRIS (Workday) and ITSM (ServiceNow) systems.
**Key Responsibilities**
- Define and own the IAM vision, roadmap, and architecture aligned with security, compliance, and business objectives.
- Build, lead, and mentor a small IAM team, fostering a culture of collaboration, innovation, and accountability.
- Champion secure and scalable IAM practices across product teams, business units, and infrastructure domains.
- Design and automate JML processes; implement access request workflows and access reviews via ServiceNow with tight policy enforcement.
- Reduce identity sprawl by enforcing RBAC/ABAC, and roll out federated SSO and MFA across all SaaS applications to eliminate shadow IT.
- Lead privileged access rationalization and control across AWS, Azure (PIM), and legacy AD environments; design segregation of duties frameworks and access certification cycles.
- Guide cloud identity strategy for Azure, AWS, and SaaS ecosystems; onboard new vendors under centralized identity management and SSO.
- Maintain IAM controls to meet FFIEC, SOC 2, PCI DSS, and other regulatory standards; respond to FDIC audits.
- Establish KPI and metrics for IAM hygiene, access review coverage, and lifecycle automation; report progress to executive leadership.
**Required Skills**
- Leadership and team management in enterprise IAM environments.
- Hands‑on expertise with SailPoint, Saviynt, Azure AD, Okta, CyberArk, or equivalent IAM platforms.
- Strong understanding of identity lifecycle automation, JML, RBAC, ABAC, SSO, MFA, and PAM.
- Experience with scripting (PowerShell, Python) and identity protocols (SAML, OAuth2, OIDC, SCIM).
- Familiarity with HRIS (Workday) and ITSM (ServiceNow) integration.
- Excellent communication, influencing, and stakeholder management.
- Knowledge of regulatory compliance (FFIEC, SOC 2, PCI DSS, audit processes).
- Ability to develop and execute KPI‑driven IAM metrics.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Preferred certifications: CISSP, CISM, or vendor‑specific IAM certifications (SailPoint IdM, Saviynt, Okta, Azure AD, CyberArk).