State Street
IAM Engineering & Operations Lead, VP
Burlington Massachusetts
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Executive
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 27 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Who we are looking for.
State Street Alpha is seeking an experienced Identity & Access Management (IAM) Engineering and Operations Lead to advance IAM operations for Charles River Development SaaS environments. The role combines hands-on engineering, global operational leadership, access governance, privileged access management, automation, service-account security, audit readiness, and continuous improvement across Active Directory, Microsoft Entra ID, SailPoint, CyberArk, and related identity platforms.
The ideal candidate is a technically credible IAM leader who can direct engineers, resolve complex production access issues, translate enterprise standards into reliable operating practices, and modernize high-volume identity services through automation and measurable controls. The successful candidate will work closely with cybersecurity, infrastructure, cloud engineering, product, operations, risk, compliance, audit, client-facing teams, and enterprise IAM partners.
Why is this role important to us.
The team you will join is part of Charles River Development (CRD), which became part of State Street in 2018. CRD creates enterprise investment management software solutions for large institutions in institutional investment, wealth management, and hedge funds. Together we have created the first open front-to-back platform, State Street Alpha, launched in 2019.
Identity services are foundational to the secure and resilient operation of client-facing SaaS environments. This role is accountable for dependable access administration, least-privilege enforcement, privileged-access controls, identity lifecycle operations, evidence-ready controls, and the transformation of legacy account and group-management practices. The role will also help reduce operational risk by expanding automation, improving service-account hygiene, strengthening segregation of duties, and moving suitable workloads toward passwordless authentication.
What you will be responsible for
IAM Operations Leadership and Service Delivery
Lead and mentor a global team of IAM engineers and administrators delivering identity operations, access administration, directory services, privileged access, and production support.
Own operational performance for IAM services, including service health, ticket queues, escalations, incident response, problem management, change execution, runbooks, and stakeholder communications.
Provide Level 3 technical leadership for complex authentication, authorization, directory, provisioning, and access issues affecting internal teams and client environments.
Set clear priorities, delivery plans, support coverage, quality expectations, and operational metrics; drive timely resolution while protecting security and control requirements.
Coordinate recurring working sessions with operational partners to resolve cross-team dependencies and improve end-to-end access request fulfillment.
Directory Services, Entra ID, and Access Administration
Engineer, administer, and support enterprise Active Directory and Microsoft Entra ID environments, including users, groups, organizational units, Group Policy, directory synchronization, connected organizations, and privileged roles.
Lead joiner, mover, and leaver processes and ensure access is provisioned, changed, disabled, or removed through approved workflows and within required service levels.
Design and maintain role-based access control models, group structures, entitlement mappings, and least-privilege patterns for SaaS operational and client-support use cases.
Perform and oversee access fulfillment through SailPoint and approved ticketing workflows, including remediation of failed or manually fulfilled provisioning activities.
Partner with infrastructure and application teams on directory integrations, authentication patterns, domain migrations, and identity-related production changes.
Privileged Access and Segregation of Duties
Operate and expand privileged access management using CyberArk, Azure PIM, and approved enterprise controls for administrative, database, RDP, service, and emergency access.
Ensure privileged access is time-bound where required, supported by approved incident or change records, appropriately authorized, logged, monitored, and periodically reviewed.
Maintain separation between access administration, approval, system administration, and functional access; identify, escalate, and remediate segregation-of-duty conflicts.
Coordinate onboarding of privileged accounts, safes, access groups, and client-agnostic operational groups into approved PAM solutions.
Support break-glass and emergency-access processes, including evidence, review, and post-use validation.
Service Account Governance and Passwordless Modernization
Lead governance and operational controls for service and other non-human accounts, including inventory, ownership, naming, organizational-unit placement, password age, vaulting, certification, and decommissioning.
Drive phased migration of suitable service accounts to group Managed Service Accounts (gMSA) or other approved passwordless and key-based authentication patterns.
Coordinate password-rotation notifications, escalations, change execution, exception handling, and evidence retention for all internal and client owned non-human accounts.
Partner with SaaS Operations, Product Engineering, Global Operations, and client-facing teams to address dependencies that prevent secure rotation or passwordless conversion.
Improve monitoring for account changes, stale identities, interactive-logon exposure, and other service-account hygiene risks.
Access Governance, Certifications, and Client Access Controls
Lead periodic user, privileged, group, guest, and non-human account reviews across CRD SaaS domains and identity platforms.
Develop scalable methods to analyze direct and nested group membership, cross-domain access, client-domain mismatches, dormant access, and excessive entitlements.
Ensure remediation from access reviews is completed through approved workflows and that evidence supports internal control, SOC, client, and regulatory requirements.
Partner with client-facing teams to establish defensible approval patterns for production and non-production access, including start and end dates, business justification, and risk acceptance where required.
Maintain clear procedures for guest-account inactivity, access recertification, leaver processing, and client identity segregation.
Automation, Engineering, and Continuous Improvement
Develop and maintain PowerShell and related automation for identity reporting, lifecycle activities, group analysis, access validation, inactive-account controls, and evidence generation.
Reduce manual effort and operational risk by embedding validation, exception handling, logging, and human approval gates into IAM workflows.
Use Azure Log Analytics, KQL, Windows security events, and other monitoring capabilities to investigate account activity and support proactive control monitoring.
Improve IAM architecture and operating practices through maturity assessments, gap analysis, root-cause reviews, roadmap development, and measurable remediation plans.
Maintain accurate SOPs, procedures, knowledge articles, support documentation, and technical control narratives.
Risk, Audit, Compliance, and Reporting
Serve as an IAM control owner or delegate for applicable access administration, privileged access, segregation-of-duty, service-account, and identity lifecycle controls.
Support internal audit, external audit, regulatory examinations, client due diligence, and control testing through complete, accurate, and timely evidence.
Identify control gaps and operational risks, define sustainable corrective actions, track remediation, and escalate issues through established governance channels.
Translate enterprise IAM policies and technical standards into actionable CRD o
Similar jobs
- Engineering Operations LeadQueracomputinginc · Boston, MA, USAFirst seen today
- Manager Engineering OperationsDigital Realty · VA, United StatesFirst seen today
- Manager Engineering OperationsDigital Realty · Richardson, TX, United StatesFirst seen today
- Engineering Operations Technician, InfraOps AGAmazon · Phoenix, Arizona, USAFirst seen today
- Clearable Engineering Operations Technician, ADC InfraOps DCEOAmazon · Aurora, Colorado, USAFirst seen today
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job