Identity and Access Management (IAM) Manager
Position Summary
The IAM Project Manager will coordinate project initiation, governance, stakeholder alignment, and execution of Identity and Access Management adherence and remediation activities across 30 client sites. The role will assess IAM controls at 13 critical/high-risk sites and drive the timely completion of existing remediation plans at 17 medium/low-risk sites. The successful candidate will combine IAM subject-matter knowledge with strong project management, documentation, and stakeholder engagement skills.
Key Responsibilities
Project Initiation, Onboarding, and Alignment
" Facilitate project kickoff and onboarding activities with key client stakeholders and site representatives.
" Review and align project objectives, scope, assumptions, deliverables, timelines, and success criteria.
" Confirm stakeholder roles, responsibilities, dependencies, and communication protocols.
" Establish project governance, including status reporting cadence, escalation procedures, risk and issue management, and decision-making processes.
" Maintain clear project documentation and communicate progress, risks, decisions, and required actions to stakeholders.
IAM Adherence Assessments for 13 Critical/High-Risk Sites
" Conduct lightweight IAM adherence assessments to validate alignment with client security standards.
" Assess Active Directory password configurations against the client's ISO-02 requirements and identify control gaps.
" Review and validate existing leaver controls, including timely account deactivation and access removal.
" Establish and verify minimum oversight controls for privileged access.
" Evaluate endpoint privilege management protocols and confirm control effectiveness.
" Document findings, risks, recommendations, owners, and target completion dates.
Remediation Plan Completion for 17 Medium/Low-Risk Sites
" Track, follow up on, and drive remediation plans to completion in accordance with attested 30-, 60-, and 90-day due dates.
" Drive completion of password policy plans for critical applications and primary domain controllers.
" Ensure execution of the privileged account Organizational Unit (OU) and policy implementation plan.
" Monitor and validate progress on shared-account discovery and inventory activities.
" Validate the establishment of a leaver procedure documentation framework and active/inactive account review process.
" Escalate overdue actions, unresolved dependencies, and control gaps through the established governance process.
" Act with integrity, professionalism, and personal responsibility to uphold the firm's respectful and courteous work environment.
Required Qualifications
" Experience supporting IAM, cybersecurity, information security, technology risk, or compliance initiatives.
" Working knowledge of Active Directory, password controls, privileged access management, endpoint privilege management, user access reviews, shared accounts, and joiner/mover/leaver controls.
" Demonstrated ability to manage multiple workstreams, sites, remediation actions, deadlines, risks, and dependencies.
" Strong stakeholder management, facilitation, written communication, and status reporting skills.
" Ability to assess control design and implementation, document findings, and translate gaps into clear remediation actions.
" Strong organizational skills and attention to detail.
Preferred Qualifications
" Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field.
" Relevant certification such as CISSP, CISM, CISA, CRISC, Security+, or PMP.
" Experience working in a multi-site or global environment and coordinating with technical and business stakeholders.
" Familiarity with security control frameworks, audit evidence, risk tracking, and remediation governance.