AssetMark
Director, Identity & Access Management
Charlotte, NC
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Director
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 29 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Job Description:
AssetMark is establishing a centralized Enterprise Identity & Access Management (IAM) function to strengthen access controls, reduce risk, improve audit and regulatory readiness, and create scalable identity services across the enterprise.
The Director of Identity & Access Management will build and lead this function and own the IAM strategy, operating model, architecture, engineering, governance, delivery, and service roadmap. The Director will lead identity services across on-premises Active Directory, Microsoft Entra ID, Azure, Microsoft 365, business applications, endpoints, collaboration platforms, and data services.
The Job/What You'll Do:
This is a hands-on technical leadership role for a leader who can establish strategy while remaining close enough to the technology to guide architecture, solve complex identity challenges, challenge designs, lead major implementations, and help the team deliver. The Director will initially lead a focused team of three IAM Engineers and one IAM Compliance/Controls resource and will partner extensively with Cybersecurity, Infrastructure, HR, Risk & Compliance, Internal Audit, application teams, and business/data owners.
The successful Director will transform IAM from distributed access activities into a centralized enterprise capability. Early priorities include establishing the IAM operating model, strengthening lifecycle and termination controls, defining identity, group, role, permission, SharePoint, and data-classification standards, establishing Purview governance and control evidence, and prioritizing the technology roadmap.
We can only consider candidates for this position who are able to accommodate a hybrid work schedule and are close to our Charlotte, NC office.
Key Responsibilities
- Build and lead AssetMark's centralized enterprise IAM function, including its strategy, operating model, service catalog, technology roadmap, engineering standards, governance practices, budget, vendors, and delivery partners. Establish clear ownership across IAM Engineering, Directory Services, Identity Governance, Privileged Access, IAM Automation, and Compliance/Controls.
- Define the target-state identity architecture and multi-year roadmap for hybrid identity modernization, Zero Trust, least privilege, secure-by-design access, SSO, federation, MFA, passwordless authentication, identity governance, and application integration. Reduce legacy dependencies and create consistent identity patterns across the enterprise.
- Lead the design and maturation of Identity Governance & Administration capabilities, including joiner, mover, leaver, contractor, partner, rehire, and non-person identity lifecycle processes; authoritative-source integration; access requests and approvals; birthright access; provisioning and deprovisioning; certifications; entitlement governance; role management; segregation of duties; and automated workflows using standards such as SCIM where appropriate.
- Provide strategic and technical leadership for Microsoft Entra ID and Active Directory, including directory architecture, identity synchronization through Entra Connect Sync or Cloud Sync, authentication, authorization, Conditional Access, MFA, passwordless authentication, Windows Hello for Business, self-service password reset, federation, external identities, identity protection, and identity governance.
- Establish governance and operating standards for Active Directory organizational units, naming conventions, delegation, administrative boundaries, directory roles, domain controllers, trusts, DNS dependencies, and lifecycle management. Oversee Group Policy design, management, testing, documentation, exception handling, recovery, and change control.
- Establish secure authentication and authorization patterns for enterprise applications and SaaS platforms. Govern application registrations, enterprise applications, app roles, consent, federation, and SSO using protocols such as SAML, OAuth 2.0, OpenID Connect, WS-Fed, LDAP, Kerberos, and SCIM, and create repeatable onboarding standards for application teams.
- Oversee enterprise identity and access administration for Microsoft 365 and SharePoint, including role assignments, licensing-related access, administrative controls, security groups, collaboration settings, information architecture, site and hub structure, permission levels, sharing settings, external collaboration, inheritance, ownership, lifecycle, and access-review practices.
- Establish least-privilege standards and governance for permissions across applications, infrastructure, SaaS, cloud, file shares, SharePoint, and collaboration platforms. Ensure access is approved by appropriate business or data owners, periodically reviewed, traceable, and promptly removed when no longer required. Use RBAC, ABAC, role engineering, and access analytics where appropriate.
- Lead the strategy and governance for privileged accounts, vaulting, credential management, session controls, emergency access, tiered administration, privileged access workstations, service accounts, application identities, APIs, secrets, certificates, cloud workloads, managed identities, service principals, and just-in-time elevation. Establish controls for break-glass access and administrative separation.
- Define identity and access standards across Azure management groups, subscriptions, resource groups, and resources. Govern Azure RBAC, managed identities, workload identities, service principals, application registrations, role assignments, secrets, certificates, keys, and credentials using Azure Key Vault and related services.
- Establish governance for Microsoft Purview data classification, sensitivity labels, Data Loss Prevention, retention, records management, insider-risk integrations, and related policies. Promote awareness of personally identifiable information, sensitive-data handling requirements, and the relationship between data sensitivity and access decisions.
- Champion an engineering-first approach using PowerShell, Python, Microsoft Graph, REST APIs, reusable patterns, Git, CI/CD, Terraform or other Infrastructure as Code, testing, monitoring, logging, reconciliation, runbooks, recovery procedures, and disciplined change management. Automate lifecycle events, application onboarding, access reviews, evidence collection, reporting, and credential rotation.
- Establish monitoring and reporting for Entra sign-in, audit, provisioning, and privileged-activity logs. Partner with Security Operations on Microsoft Sentinel, Log Analytics, KQL, Defender for Identity, risky users, risky sign-ins, compromised accounts, workload-identity threats, and identity-related incident response and remediation.
- Own the IAM service catalog, service health, operating procedures, service levels, incident and problem management partnership, change governance, documentation, continuity planning, and recovery testing. Establish metrics and executive reporting for service health, risk reduction, control effectiveness, certification completion, privileged access, lifecycle performance, PII policy coverage, excessive permissions, unmanaged sharing, audit findings, and program maturity.
- Align IAM capabilities to AssetMark security policies and applicable requirements such as SOX, NIST, ISO 27001, and financial-services expectations. Establish clear accountability across IAM, HR, application and platform owners, Cybersecurity, Infrastructure, Risk, Compliance, Privacy, and Internal Audit, and partner with these groups to deliver secure, scalable, automated, and adopted IAM services.
Knowledge, Skills & Abilities
- Deep knowledge of enterprise IAM architecture and program delivery, including IGA, identity lifecycle management, authentication, SSO/federation, provisioning, access governance, RBAC/ABAC, certifications, segregation of duties, PAM, Zero Trust, and least-privilege principles.
- Advanced Microsoft identity expertise, including Microsoft Entra ID, Act
Similar jobs
- Associate Director, Policy, EM-0301-00 (Merit Promotion)Federal Deposit Insurance Corporation · Washington, District of Columbia, United StatesFirst seen today
- Associate Director, Policy, EM-0301-00 (Public)Federal Deposit Insurance Corporation · Washington, District of Columbia, United StatesFirst seen today
- Clinical Director (O-6 Billet) SupervisoryImmigration and Customs Enforcement · Elizabeth, New Jersey, United StatesFirst seen today
- Director of Accountability and Operational Analysis DivisionFederal Acquisition Service · San Francisco, California, United StatesFirst seen today
- Director of Operations AnalysisDepartment of the Air Force Headquarters · Pentagon, Arlington, Virginia, United StatesFirst seen today
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job