Information Security Manager - Identity and Access Management (IAM)
Zoox
- 🇺🇸 United States
- Hybrid
- Manager or above
- 1 day ago
- $228,000 – $273,000 / year
- IAM
- Zero Trust
- RBAC
- ABAC
- SAML
- OpenID Connect
- OIDC
- Risk Management
- Incident Response
- Azure AD
- Okta
- Ping Identity
- Active Directory
- SailPoint
- CyberArk
- SCIM
- Kerberos
- LDAP
- Regulatory Compliance
- CISSP
- CISM
- CISA
- AWS
- Azure
- GCP
- PowerShell
- Python
- REST API
- Machine Learning
- Health insurance
- Equity
1 day ago
In This Role, You Will...
- Strategic Leadership & Governance
- IAM Strategy: Lead the definition, rollout, and execution of the enterprise IAM roadmap, aligning identity practices with Zero Trust principles and corporate security standards.
- Governance & Policies: Develop, maintain, and enforce identity policies, including Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), Least Privilege, and Separation of Duties (SoD).
- Team Management: Lead, mentor, and build a high-performing team of IAM engineers, system integrators, and security analysts. Operational Excellence & Technical Oversight
- Lifecycle Management: Oversee the Joiner, Mover, and Leaver (JML) processes to automate provisioning and de-provisioning workflows across on-premises and cloud platforms.
- Authentication & SSO: Architect and oversee modern authentication standards, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), SAML 2.0, OpenID Connect (OIDC), and passwordless technology.
- Privileged Access Management (PAM): Manage enterprise PAM solution implementation, securing administrative credentials, session monitoring, and just-in-time access controls.
- Identity Governance & Administration (IGA): Direct user access reviews, entitlement certification campaigns, and automated access request/approval workflows. Risk Management, Compliance & Support
- Audit & Compliance: Function as the primary IAM lead for internal and external audits, ensuring timely remediation of access-related findings.
- Incident Response: Act as an escalation point for identity-focused security incidents, credentials compromise, and unauthorized access investigations.
- Vendor Management: Evaluate, select, and manage third-party IAM software vendors, tools, and professional services partners.
Qualifications
- 8+ years of total experience in IT and Cybersecurity, with at least 3+ years in a leadership/management capacity focused specifically on Identity & Access Management.
- Hands-on experience with industry-standard IAM tools:
○ Directory & Identity Providers: Microsoft Entra ID (Azure AD), Okta, Ping Identity, Active Directory.
â—‹ IGA Platforms: SailPoint, Saviynt, or Microsoft Entra ID Governance.
○ PAM Solutions: CyberArk, BeyondTrust, Delinea, or HashiCorp Vault. - Deep understanding of OAuth 2.0, SAML, OIDC, SCIM, Kerberos, and LDAP protocols.
- Strong familiarity with regulatory compliance frameworks.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
Bonus Qualifications
- CISSP, CISM, CISA, or vendor-specific certifications (e.g., Okta Certified Professional, Microsoft Certified: Identity and Access Administrator Associate, SailPoint Certified).
- Hands-on experience managing identity across AWS, Azure, or GCP cloud environments.
- Proficiency in scripting/automation (PowerShell, Python, REST APIs) for workflow optimization.
Follow us on LinkedIn
AccommodationsIf you need an accommodation to participate in the application or interview process please reach out to accommodations@zoox.com or your assigned recruiter.
A Final Note:You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills.
Information Security Manager - Identity and Access Management (IAM) · Zoox