Job Description:
AssetMark is establishing a centralized Enterprise Identity & Access Management (IAM) function to strengthen access controls, reduce risk, improve audit and regulatory readiness, and create scalable identity services across the enterprise.
The Director of Identity & Access Management will build and lead this function and own the IAM strategy, operating model, architecture, engineering, governance, delivery, and service roadmap. The Director will lead identity services across on-premises Active Directory, Microsoft Entra ID, Azure, Microsoft 365, business applications, endpoints, collaboration platforms, and data services.
The Job/What You'll Do:
This is a hands-on technical leadership role for a leader who can establish strategy while remaining close enough to the technology to guide architecture, solve complex identity challenges, challenge designs, lead major implementations, and help the team deliver. The Director will initially lead a focused team of three IAM Engineers and one IAM Compliance/Controls resource and will partner extensively with Cybersecurity, Infrastructure, HR, Risk & Compliance, Internal Audit, application teams, and business/data owners.
The successful Director will transform IAM from distributed access activities into a centralized enterprise capability. Early priorities include establishing the IAM operating model, strengthening lifecycle and termination controls, defining identity, group, role, permission, SharePoint, and data-classification standards, establishing Purview governance and control evidence, and prioritizing the technology roadmap.
Key Responsibilities
- Build and lead AssetMark's centralized enterprise IAM function, including its strategy, operating model, service catalog, technology roadmap, engineering standards, governance practices, budget, vendors, and delivery partners.
- Define the target-state identity architecture and multi-year roadmap for hybrid identity modernization, Zero Trust, least privilege, secure-by-design access, SSO, federation, MFA, passwordless authentication, identity governance, and application integration.
- Lead the design and maturation of Identity Governance & Administration capabilities, including joiner, mover, leaver, contractor, partner, rehire, and non-person identity lifecycle processes.
- Provide strategic and technical leadership for Microsoft Entra ID and Active Directory.
- Establish governance and operating standards for Active Directory organizational units, naming conventions, delegation, administrative boundaries, directory roles, domain controllers, trusts, DNS dependencies, and lifecycle management.
- Establish secure authentication and authorization patterns for enterprise applications and SaaS platforms.
- Oversee enterprise identity and access administration for Microsoft 365 and SharePoint.
- Establish least-privilege standards and governance for permissions across applications, infrastructure, SaaS, cloud, file shares, SharePoint, and collaboration platforms.
- Lead the strategy and governance for privileged accounts.
- Define identity and access standards across Azure management groups, subscriptions, resource groups, and resources.
- Establish governance for Microsoft Purview data classification.
- Champion an engineering-first approach using PowerShell, Python, Microsoft Graph, REST APIs, reusable patterns, Git, CI/CD, Terraform or other Infrastructure as Code.
- Establish monitoring and reporting for Entra sign-in, audit, provisioning, and privileged-activity logs.
- Own the IAM service catalog, service health, operating procedures, service levels, incident and problem management partnership, change governance, documentation, continuity planning, and recovery testing.
- Align IAM capabilities to AssetMark security policies and applicable requirements.
Knowledge, Skills & Abilities
- Deep knowledge of enterprise IAM architecture and program delivery.
- Advanced Microsoft identity expertise.
- Strong knowledge of Azure, Microsoft 365, SharePoint, and cloud identity and authorization.
- Strong understanding of enterprise application and information access patterns.
- Working knowledge of Microsoft Purview and data protection concepts.
- Hands-on engineering and automation capability.
- Strong understanding of privileged access and identity monitoring.
- Excellent executive communication, stakeholder management, analytical, presentation, and problem-solving skills.
- Demonstrated ability to develop engineers and build strong technical organizations.
Education & Experience
- 10 or more years of progressive technology, cybersecurity, or identity experience.
- Five or more years leading technical teams.
- Proven experience building, transforming, or significantly maturing an enterprise IAM program.
- Experience within financial services or another highly regulated enterprise environment.
- Experience with IGA platforms.
- Experience with PAM and secrets-management platforms.
- Relevant certifications are preferred.
Compensation:
The Base Salary range for this position is between $190,000-$220,000. This information reflects a base salary range that AssetMark reasonably expects to pay for the position based on a number of factors which may include job-related knowledge, skills, education, experience, and actual work location. This position will also be eligible for additional variable incentive compensation and competitive benefits.
Candidates must be legally authorized to work in the US to be considered. We are unable to provide visa sponsorship for this position.
Who We Are & What We Offer:
We are AssetMark, a company on the move, shaping the future of financial services. Growth is in our DNA. Every day, we combine technology, insight, and collaboration to create new possibilities for advisors, for our people and for our investors.
Our Mission
Our mission is simple: to help our 10,500+ financial advisors make a meaningful difference in their clients’ lives.
Our Values
Heart. Client Success. Integrity. Respect. Excellence.
Our Culture & Benefits
Our culture brings our mission and values to life. Here, we do what’s right, embrace diverse ideas, and innovate together.