About this role
Job Description:
AssetMark is establishing a centralized Enterprise Identity & Access Management (IAM) function to strengthen access controls, reduce risk, improve audit and regulatory readiness, and create scalable identity services across the enterprise.
The Director of Identity & Access Management will build and lead this function and own the IAM strategy, operating model, architecture, engineering, governance, delivery, and service roadmap. The Director will lead identity services across on-premises Active Directory, Microsoft Entra ID, Azure, Microsoft 365, business applications, endpoints, collaboration platforms, and data services.
The Job/What You'll Do:
This is a hands-on technical leadership role for a leader who can establish strategy while remaining close enough to the technology to guide architecture, solve complex identity challenges, challenge designs, lead major implementations, and help the team deliver. The Director will initially lead a focused team of three IAM Engineers and one IAM Compliance/Controls resource and will partner extensively with Cybersecurity, Infrastructure, HR, Risk & Compliance, Internal Audit, application teams, and business/data owners.
The successful Director will transform IAM from distributed access activities into a centralized enterprise capability. Early priorities include establishing the IAM operating model, strengthening lifecycle and termination controls, defining identity, group, role, permission, SharePoint, and data-classification standards, establishing Purview governance and control evidence, and prioritizing the technology roadmap.
We can only consider candidates for this position who are able to accommodate a hybrid work schedule and are close to our Charlotte, NC office.
Key Responsibilities
- Build and lead AssetMark's centralized enterprise IAM function, including its strategy, operating model, service catalog, technology roadmap, engineering standards, governance practices, budget, vendors, and delivery partners. Establish clear ownership across IAM Engineering, Directory Services, Identity Governance, Privileged Access, IAM Automation, and Compliance/Controls.
- Define the target-state identity architecture and multi-year roadmap for hybrid identity modernization, Zero Trust, least privilege, secure-by-design access, SSO, federation, MFA, passwordless authentication, identity governance, and application integration. Reduce legacy dependencies and create consistent identity patterns across the enterprise.
- Lead the design and maturation of Identity Governance & Administration capabilities, including joiner, mover, leaver, contractor, partner, rehire, and non-person identity lifecycle processes; authoritative-source integration; access requests and approvals; birthright access; provisioning and deprovisioning; certifications; entitlement governance; role management; segregation of duties; and automated workflows using standards such as SCIM where appropriate.
- Provide strategic and technical leadership for Microsoft Entra ID and Active Directory, including directory architecture, identity synchronization through Entra Connect Sync or Cloud Sync, authentication, authorization, Conditional Access, MFA, passwordless authentication, Windows Hello for Business, self-service password reset, federation, external identities, identity protection, and identity governance.
- Establish governance and operating standards for Active Directory organizational units, naming conventions, delegation, administrative boundaries, directory roles, domain controllers, trusts, DNS dependencies, and lifecycle management. Oversee Group Policy design, management, testing, documentation, exception handling, recovery, and change control.
- Establish secure authentication and authorization patterns for enterprise applications and SaaS platforms. Govern application registrations, enterprise applications, app roles, consent, federation, and SSO using protocols such as SAML, OAuth 2.0, OpenID Connect, WS-Fed, LDAP, Kerberos, and SCIM, and create repeatable onboarding standards for application teams.
- Oversee enterprise identity and access administration for Microsoft 365 and SharePoint, including role assignments, licensing-related access, administrative controls, security groups, collaboration settings, information architecture, site and hub structure, permission levels, sharing settings, external collaboration, inheritance, ownership, lifecycle, and access-review practices.
- Establish least-privilege standards and governance for permissions across applications, infrastructure, SaaS, cloud, file shares, SharePoint, and collaboration platforms. Ensure access is approved by appropriate business or data owners, periodically reviewed, traceable, and promptly removed when no longer required. Use RBAC, ABAC, role engineering, and access analytics where appropriate.
- Lead the strategy and governance for privileged accounts, vaulting, credential management, session controls, emergency access, tiered administration, privileged access workstations, service accounts, application identities, APIs, secrets, certificates, cloud workloads, managed identities, service principals, and just-in-time elevation. Establish controls for break-glass access and administrative separation.
- Define identity and access standards across Azure management groups, subscriptions, resource groups, and resources. Govern Azure RBAC, managed identities, workload identities, service principals, application registrations, role assignments, secrets, certificates, keys, and credentials using Azure Key Vault and related services.
- Establish governance for Microsoft Purview data classification, sensitivity labels, Data Loss Prevention, retention, records management, insider-risk integrations, and related policies. Promote awareness of personally identifiable information, sensitive-data handling requirements, and the relationship between data sensitivity and access decisions.
- Champion an engineering-first approach using PowerShell, Python, Microsoft Graph, REST APIs, reusable patterns, Git, CI/CD, Terraform or other Infrastructure as Code, testing, monitoring, logging, reconciliation, runbooks, recovery procedures, and disciplined change management. Automate lifecycle events, application onboarding, access reviews, evidence collection, reporting, and credential rotation.
- Establish monitoring and reporting for Entra sign-in, audit, provisioning, and privileged-activity logs. Partner with Security Operations on Microsoft Sentinel, Log Analytics, KQL, Defender for Identity, risky users, risky sign-ins, compromised accounts, workload-identity threats, and identity-related incident response and remediation.
- Own the IAM service catalog, service health, operating procedures, service levels, incident and problem management partnership, change governance, documentation, continuity planning, and recovery testing. Establish metrics and executive reporting for service health, risk reduction, control effectiveness, certification completion, privileged access, lifecycle performance, PII policy coverage, excessive permissions, unmanaged sharing, audit findings, and program maturity.
- Align IAM capabilities to AssetMark security policies and applicable requirements such as SOX, NIST, ISO 27001, and financial-services expectations. Establish clear accountability across IAM, HR, application and platform owners, Cybersecurity, Infrastructure, Risk, Compliance, Privacy, and Internal Audit, and partner with these groups to deliver secure, scalable, automated, and adopted IAM services.
Knowledge, Skills & Abilities
- Deep knowledge of enterprise IAM architecture and program delivery, including IGA, identity lifecycle management, authentication, SSO/federation, provisioning, access governance, RBAC/ABAC, certifications, segregation of duties, PAM, Zero Trust, and least-privilege principles.
- Advanced Microsoft identity expertise, including Microsoft Entra ID, Active Directory, OU structure, Group Policy, directory governance, delegation, synchronization, Conditional Access, MFA, passwordless and modern authentication, identity protection, and identity governance.
- Strong knowledge of Azure, Microsoft 365, SharePoint, and cloud identity and authorization, including Azure RBAC, management groups, subscriptions, resource groups, managed identities, service principals, application registrations, Key Vault, Microsoft 365 administrative controls, SharePoint governance, and information access models.
- Strong understanding of enterprise application and information access patterns, including SaaS, file shares, collaboration platforms, application registrations, SAML, OAuth 2.0, OpenID Connect, WS-Fed, LDAP, Kerberos, and SCIM.
- Working knowledge of Microsoft Purview and data protection concepts, including PII, sensitive-data classification, sensitivity labels, Data Loss Prevention, retention, records management, insider-risk integrations, and control monitoring.
- Hands-on engineering and automation capability using PowerShell, Python, Microsoft Graph, REST APIs, KQL, Git, CI/CD, Terraform or other Infrastructure as Code, testing, monitoring, logging, and reconciliation.
- Strong understanding of privileged access, secrets and workload identities, identity monitoring, incident response, audit evidence, and cross-functional control remediation.
- Excellent executive communication, stakeholder management, analytical, presentation, and problem-solving skills, with the ability to move between strategy, business impact, and technical detail.
- Demonstrated ability to develop engineers, build strong technical organizations, establish clear accountability, mentor technical teams, and influence partners across business and technology functions.
Education & Experience
- 10 or more years of progressive technology, cybersecurity, or identity experience, with significant experience focused on enterprise IAM.
- Five or more years leading technical teams, with demonstrated success developing engineers, building strong technical organizations, and directing delivery through a roadmap.
- Proven experience building, transforming, or significantly maturing an enterprise IAM program in a complex or regulated environment.
- Experience within financial services or another highly regulated enterprise environment, including audit, regulatory examination, and remediation activities.
- Experience with IGA platforms such as SailPoint Identity Security Cloud or IdentityIQ, Microsoft Entra ID Governance, Saviynt, Okta, or comparable platforms.
- Experience with PAM and secrets-management platforms such as CyberArk, BeyondTrust, Delinea, HashiCorp Vault, or comparable technologies.
- Relevant certifications are preferred, such as CISSP, CISM, CIAM, Microsoft Identity and Access Administrator, Microsoft Azure Security Engineer, Microsoft 365 or Purview certifications, SailPoint certification, or comparable credentials.
Compensation: The Base Salary range for this position is between $190,000-$220,000.
This information reflects a base salary range that AssetMark reasonably expects to pay for the position based on a number of factors which may include job-related knowledge, skills, education, experience, and actual work location. This position will also be eligible for additional variable incentive compensation and competitive benefits.
Candidates must be legally authorized to work in the US to be considered. We are unable to provide visa sponsorship for this position.
#LI-hybrid
#LI-TN1
Who We Are & What We Offer:
We are AssetMark, a company on the move, shaping the future of financial services. Growth is in our DNA. Every day, we combine technology, insight, and collaboration to create new possibilities for advisors, for our people and for our investors. At AssetMark your ideas matter; they’re heard, valued, and drive meaningful change. Join a team that sets new standards and creates space for you to thrive and do your best work.
Our Mission
Our mission is simple: to help our 10,500+ financial advisors make a meaningful difference in their clients’ lives. We do this by combining powerful technology, holistic support, and expert consulting to help advisors run stronger, more efficient businesses. Backed by a comprehensive suite of investment solutions and a trust company that boasts of $150B+ AUM, our platform empowers advisors to deliver exceptional service and an outstanding client experience.
Our Values
Heart. Client Success. Integrity. Respect. Excellence. Our values are how we show up every day.
We believe in:
- Leading with Heart, in truly making a difference in the lives of others: teammates, clients, investors and communities.
- Obsessing over Client Success, bringing a relentless focus on what matters to clients that sets us apart and creates loyal, lasting relationships.
- Unyielding Integrity, doing what’s right, always. Even when it’s hard.
- Collective Respect, in being authentic, inclusive and valuing all voices while winning together.
- Operating with Excellence, in learning fast, continuously improving, innovating and collaborating to find new and better solutions.
These values shape our culture, guide our decisions, and define what it means to be part of the AssetMark family.
Our Culture & Benefits
Our culture brings our mission and values to life. Here, we do what’s right, embrace diverse ideas, and innovate together. We also offer a wide range of benefits to support you and your family—because thriving at work starts with thriving in life.
- Flex Time or Paid Time Off and Sick Time Off
- 401K – 6% Employer Match
- Medical, Dental, Vision – HDHP or PPO
- HSA – Employer contribution (HDHP only)
- Volunteer Time Off
- Career Development / Recognition
- Fitness Reimbursement
- Hybrid Work Schedule
As an Equal Opportunity Employer, AssetMark is committed to building a diverse and inclusive workplace where everyone feels valued.