Live opening · Posted 8 hours ago

IAM Engineering & Operations Lead, VP

State Street · Burlington Massachusetts
Workday
You are 8 hours behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 8 hours ago
CompanyState Street
LocationBurlington Massachusetts
SourceWorkday
Listed8 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
1 min from Workday publishing this role to us finding it
47 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
15,935 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Who we are looking for.
State Street Alpha is seeking an experienced Identity & Access Management (IAM) Engineering and Operations Lead to advance IAM operations for Charles River Development SaaS environments. The role combines hands-on engineering, global operational leadership, access governance, privileged access management, automation, service-account security, audit readiness, and continuous improvement across Active Directory, Microsoft Entra ID, SailPoint, CyberArk, and related identity platforms.
The ideal candidate is a technically credible IAM leader who can direct engineers, resolve complex production access issues, translate enterprise standards into reliable operating practices, and modernize high-volume identity services through automation and measurable controls. The successful candidate will work closely with cybersecurity, infrastructure, cloud engineering, product, operations, risk, compliance, audit, client-facing teams, and enterprise IAM partners.
Why is this role important to us.
The team you will join is part of Charles River Development (CRD), which became part of State Street in 2018. CRD creates enterprise investment management software solutions for large institutions in institutional investment, wealth management, and hedge funds. Together we have created the first open front-to-back platform, State Street Alpha, launched in 2019.
Identity services are foundational to the secure and resilient operation of client-facing SaaS environments. This role is accountable for dependable access administration, least-privilege enforcement, privileged-access controls, identity lifecycle operations, evidence-ready controls, and the transformation of legacy account and group-management practices. The role will also help reduce operational risk by expanding automation, improving service-account hygiene, strengthening segregation of duties, and moving suitable workloads toward passwordless authentication.
What you will be responsible for
IAM Operations Leadership and Service Delivery
Lead and mentor a global team of IAM engineers and administrators delivering identity operations, access administration, directory services, privileged access, and production support.
Own operational performance for IAM services, including service health, ticket queues, escalations, incident response, problem management, change execution, runbooks, and stakeholder communications.
Provide Level 3 technical leadership for complex authentication, authorization, directory, provisioning, and access issues affecting internal teams and client environments.
Set clear priorities, delivery plans, support coverage, quality expectations, and operational metrics; drive timely resolution while protecting security and control requirements.
Coordinate recurring working sessions with operational partners to resolve cross-team dependencies and improve end-to-end access request fulfillment.
Directory Services, Entra ID, and Access Administration
Engineer, administer, and support enterprise Active Directory and Microsoft Entra ID environments, including users, groups, organizational units, Group Policy, directory synchronization, connected organizations, and privileged roles.
Lead joiner, mover, and leaver processes and ensure access is provisioned, changed, disabled, or removed through approved workflows and within required service levels.
Design and maintain role-based access control models, group structures, entitlement mappings, and least-privilege patterns for SaaS operational and client-support use cases.
Perform and oversee access fulfillment through SailPoint and approved ticketing workflows, including remediation of failed or manually fulfilled provisioning activities.
Partner with infrastructure and application teams on directory integrations, authentication patterns, domain migrations, and identity-related production changes.
Privileged Access and Segregation of Duties
Operate and expand privileged access management using CyberArk, Azure PIM, and approved enterprise controls for administrative, database, RDP, service, and emergency access.
Ensure privileged access is time-bound where required, supported by approved incident or change records, appropriately authorized, logged, monitored, and periodically reviewed.
Maintain separation between access administration, approval, system administration, and functional access; identify, escalate, and remediate segregation-of-duty conflicts.
Coordinate onboarding of privileged accounts, safes, access groups, and client-agnostic operational groups into approved PAM solutions.
Support break-glass and emergency-access processes, including evidence, review, and post-use validation.
Service Account Governance and Passwordless Modernization
Lead governance and operational controls for service and other non-human accounts, including inventory, ownership, naming, organizational-unit placement, password age, vaulting, certification, and decommissioning.
Drive phased migration of suitable service accounts to group Managed Service Accounts (gMSA) or other approved passwordless and key-based authentication patterns.
Coordinate password-rotation notifications, escalations, change execution, exception handling, and evidence retention for all internal and client owned non-human accounts.
Partner with SaaS Operations, Product Engineering, Global Operations, and client-facing teams to address dependencies that prevent secure rotation or passwordless conversion.
Improve monitoring for account changes, stale identities, interactive-logon exposure, and other service-account hygiene risks.
Access Governance, Certifications, and Client Access Controls
Lead periodic user, privileged, group, guest, and non-human account reviews across CRD SaaS domains and identity platforms.
Develop scalable methods to analyze direct and nested group membership, cross-domain access, client-domain mismatches, dormant access, and excessive entitlements.
Ensure remediation from access reviews is completed through approved workflows and that evidence supports internal control, SOC, client, and regulatory requirements.
Partner with client-facing teams to establish defensible approval patterns for production and non-production access, including start and end dates, business justification, and risk acceptance where required.
Maintain clear procedures for guest-account inactivity, access recertification, leaver processing, and client identity segregation.
Automation, Engineering, and Continuous Improvement
Develop and maintain PowerShell and related automation for identity reporting, lifecycle activities, group analysis, access validation, inactive-account controls, and evidence generation.
Reduce manual effort and operational risk by embedding validation, exception handling, logging, and human approval gates into IAM workflows.
Use Azure Log Analytics, KQL, Windows security events, and other monitoring capabilities to investigate account activity and support proactive control monitoring.
Improve IAM architecture and operating practices through maturity assessments, gap analysis, r

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App