← Back to jobs
ST

IAM Engineering & Operations Lead, VP

Statestreet
Burlington Massachusetts VP Full-time
Azure

Who we are looking for. 

State Street Alpha is seeking an experienced Identity & Access Management (IAM) Engineering and Operations Lead to advance IAM operations for Charles River Development SaaS environments. The role combines hands-on engineering, global operational leadership, access governance, privileged access management, automation, service-account security, audit readiness, and continuous improvement across Active Directory, Microsoft Entra ID, SailPoint, CyberArk, and related identity platforms. 

The ideal candidate is a technically credible IAM leader who can direct engineers, resolve complex production access issues, translate enterprise standards into reliable operating practices, and modernize high-volume identity services through automation and measurable controls. The successful candidate will work closely with cybersecurity, infrastructure, cloud engineering, product, operations, risk, compliance, audit, client-facing teams, and enterprise IAM partners. 

Why is this role important to us. 

The team you will join is part of Charles River Development (CRD), which became part of State Street in 2018. CRD creates enterprise investment management software solutions for large institutions in institutional investment, wealth management, and hedge funds. Together we have created the first open front-to-back platform, State Street Alpha, launched in 2019. 

Identity services are foundational to the secure and resilient operation of client-facing SaaS environments. This role is accountable for dependable access administration, least-privilege enforcement, privileged-access controls, identity lifecycle operations, evidence-ready controls, and the transformation of legacy account and group-management practices. The role will also help reduce operational risk by expanding automation, improving service-account hygiene, strengthening segregation of duties, and moving suitable workloads toward passwordless authentication. 

What you will be responsible for 

IAM Operations Leadership and Service Delivery 

  • Lead and mentor a global team of IAM engineers and administrators delivering identity operations, access administration, directory services, privileged access, and production support. 

  • Own operational performance for IAM services, including service health, ticket queues, escalations, incident response, problem management, change execution, runbooks, and stakeholder communications. 

  • Provide Level 3 technical leadership for complex authentication, authorization, directory, provisioning, and access issues affecting internal teams and client environments. 

  • Set clear priorities, delivery plans, support coverage, quality expectations, and operational metrics; drive timely resolution while protecting security and control requirements. 

  • Coordinate recurring working sessions with operational partners to resolve cross-team dependencies and improve end-to-end access request fulfillment. 

Directory Services, Entra ID, and Access Administration 

  • Engineer, administer, and support enterprise Active Directory and Microsoft Entra ID environments, including users, groups, organizational units, Group Policy, directory synchronization, connected organizations, and privileged roles. 

  • Lead joiner, mover, and leaver processes and ensure access is provisioned, changed, disabled, or removed through approved workflows and within required service levels. 

  • Design and maintain role-based access control models, group structures, entitlement mappings, and least-privilege patterns for SaaS operational and client-support use cases. 

  • Perform and oversee access fulfillment through SailPoint and approved ticketing workflows, including remediation of failed or manually fulfilled provisioning activities. 

  • Partner with infrastructure and application teams on directory integrations, authentication patterns, domain migrations, and identity-related production changes. 

Privileged Access and Segregation of Duties 

  • Operate and expand privileged access management using CyberArk, Azure PIM, and approved enterprise controls for administrative, database, RDP, service, and emergency access. 

  • Ensure privileged access is time-bound where required, supported by approved incident or change records, appropriately authorized, logged, monitored, and periodically reviewed. 

  • Maintain separation between access administration, approval, system administration, and functional access; identify, escalate, and remediate segregation-of-duty conflicts. 

  • Coordinate onboarding of privileged accounts, safes, access groups, and client-agnostic operational groups into approved PAM solutions. 

  • Support break-glass and emergency-access processes, including evidence, review, and post-use validation. 

Service Account Governance and Passwordless Modernization 

  • Lead governance and operational controls for service and other non-human accounts, including inventory, ownership, naming, organizational-unit placement, password age, vaulting, certification, and decommissioning. 

  • Drive phased migration of suitable service accounts to group Managed Service Accounts (gMSA) or other approved passwordless and key-based authentication patterns. 

  • Coordinate password-rotation notifications, escalations, change execution, exception handling, and evidence retention for all internal and client owned non-human accounts. 

  • Partner with SaaS Operations, Product Engineering, Global Operations, and client-facing teams to address dependencies that prevent secure rotation or passwordless conversion. 

  • Improve monitoring for account changes, stale identities, interactive-logon exposure, and other service-account hygiene risks. 

Access Governance, Certifications, and Client Access Controls 

  • Lead periodic user, privileged, group, guest, and non-human account reviews across CRD SaaS domains and identity platforms. 

  • Develop scalable methods to analyze direct and nested group membership, cross-domain access, client-domain mismatches, dormant access, and excessive entitlements. 

  • Ensure remediation from access reviews is completed through approved workflows and that evidence supports internal control, SOC, client, and regulatory requirements. 

  • Partner with client-facing teams to establish defensible approval patterns for production and non-production access, including start and end dates, business justification, and risk acceptance where required. 

  • Maintain clear procedures for guest-account inactivity, access recertification, leaver processing, and client identity segregation. 

Automation, Engineering, and Continuous Improvement 

  • Develop and maintain PowerShell and related automation for identity reporting, lifecycle activities, group analysis, access validation, inactive-account controls, and evidence generation. 

  • Reduce manual effort and operational risk by embedding validation, exception handling, logging, and human approval gates into IAM workflows. 

  • Use Azure Log Analytics, KQL, Windows security events, and other monitoring capabilities to investigate account activity and support proactive control monitoring. 

  • Improve IAM architecture and operating practices through maturity assessments, gap analysis, root-cause reviews, roadmap development, and measurable remediation plans. 

  • Maintain accurate SOPs, procedures, knowledge articles, support documentation, and technical control narratives. 

Risk, Audit, Compliance, and Reporting 

  • Serve as an IAM control owner or delegate for applicable access administration, privileged access, segregation-of-duty, service-account, and identity lifecycle controls. 

  • Support internal audit, external audit, regulatory examinations, client due diligence, and control testing through complete, accurate, and timely evidence. 

  • Identify control gaps and operational risks, define sustainable corrective actions, track remediation, and escalate issues through established governance channels. 

  • Translate enterprise IAM policies and technical standards into actionable CRD operational requirements and implementation plans. 

  • Provide concise executive reporting on service performance, access risk, control effectiveness, audit commitments, automation progress, and modernization outcomes. 

Education & Preferred Qualifications 

  • Bachelor's degree in computer science, engineering, information systems, cybersecurity, or a related technical field, or equivalent professional experience. 

  • 10+ years of experience in IAM, directory services, cybersecurity engineering, infrastructure operations, or related technology functions, including experience leading engineers or operational teams. 

  • Deep hands-on expertise with Active Directory, Microsoft Entra ID, Windows Server, Group Policy, identity lifecycle management, RBAC, LDAP, DNS, and hybrid identity integration. 

  • Practical experience with SailPoint or another identity governance and administration platform, and CyberArk or another enterprise privileged access management platform. 

  • Strong PowerShell automation skills; experience with KQL, Azure Log Analytics, security-event analysis, or comparable observability tools is highly desirable. 

  • Experience governing service accounts, gMSA, non-human identities, password rotation, credential vaulting, access certifications, and segregation-of-duty controls. 

  • Experience operating IAM services in a regulated financial-services, SaaS, or other high-control environment, including audit evidence and remediation responsibilities. 

  • Demonstrated ability to manage production incidents, prioritize competing operational demands, communicate with senior stakeholders, and lead cross-functional delivery. 

  • CyberArk Defender, Microsoft identity or Azure certification, CISSP, CISM, or comparable industry certification is preferred. 

Salary Range:

$120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

More jobs at Statestreet

See all Statestreet jobs →

Similar roles

Free Access

Subscribe to view full job details

Get unlimited access to job listings, apply links, and weekly curated picks. Plus, learn how Latentra's career placement program can land your next role — we only charge after you're hired.

No spam. Unsubscribe anytime. Learn about our program

Chat with us