About this role
JOB DESCRIPTION
Why GMF Technology?
Innovation isn't just a talking point at GM Financial, it's how we operate. From generative AI and cloud-native technologies to peer-led learning and hackathons, our tech teams are building real solutions that make a difference. We're committed to AI-powered transformation, using advanced machine learning and automation to help us reimagine customer interactions and modernize operations, positioning GM Financial as a leader in digital innovation within a dynamic industry.
Join us and discover a workplace where your ideas matter, your development is prioritized, and you can truly make a global impact.
This position will be posted until filled.
RESPONSIBILITIES
About the role:
The Manager of Identity & Access Management Engineering and Integration is responsible for leading the design, engineering, integration, and operational excellence of enterprise IAM platforms. This role ensures secure, scalable, and compliant identity services across Active Directory, SailPoint IdentityIQ (IQ), SailPoint Identity Security Cloud (ISC), Okta, CyberArk, and PKI Services, supporting on‑premises, cloud, and hybrid environments.
The manager leads a team of IAM engineers and analysts, serving as a tower lead for our managed service partner resources and works cross‑functionally with cybersecurity, infrastructure, application teams, and audit partners to deliver identity lifecycle automation, privileged access management, authentication services, and certificate services aligned with Zero Trust and least‑privilege principles.
In this role you will:
IAM Platform Engineering & Integration
Lead engineering, configuration, and lifecycle management of IAM platforms including Active Directory, SailPoint (IIQ and ISC), Okta, CyberArk, and PKI ServicesOversee platform integrations with HR systems, ServiceNow, enterprise applications, cloud services, and third party vendorsEnsure resilient, highly available, and scalable IAM architectures across on prem and cloud environmentsEstablish reference architectures, integration patterns, and technical standards for IAM services Active Directory
Provide technical and operational leadership for enterprise Active Directory services, including on premises and hybrid directory environmentsOwn AD architecture, design standards, and operational patterns, ensuring alignment with Zero Trust, least privilege, and identity centric security modelsOversee directory hygiene and lifecycle management, including user objects, service accounts, groups, and delegated administration modelsLead AD group and service account governance, ensuring alignment with SailPoint driven identity lifecycle (Joiner Mover Leaver) processes and access certificationsPartner with Identity Governance teams to ensure AD entitlements are authoritative, well modeled, and auditable within SailPointEnsure secure integration between Active Directory and Okta, including federation, authentication flows, and directory synchronizationSupport and enhance privileged access controls for AD in coordination with CyberArk, including protection of domain level and Tier 0 privileged accountsLead AD remediation and risk reduction efforts, including cleanup of legacy groups, orphaned accounts, excessive permissions, and insecure configurationsEstablish and maintain monitoring, alerting, and operational metrics for directory services availability, security posture, and access integrityAct as the escalation point for directory related incidents, audits, and compliance inquiries, ensuring timely remediation and root cause resolutionCollaborate with Infrastructure, Endpoint, Cloud, and Security Architecture teams to ensure AD remains a foundational identity control plane for enterprise services Identity Governance & Lifecycle Management
Own Joiner Mover Leaver (JML) automation, role based access control (RBAC), entitlement modeling, and access request workflows using SailPointEnsure consistent execution of access certificationsPartner with application owners and engineers to onboard applications into IAM governance and provisioning frameworks to ensure completeness and accuracy and entitlement metadataAssist in testing of lower environments Privileged Access & Authentication Services
Lead implementation and ongoing enhancement of CyberArk for privileged account management, credential vaulting, and session monitoringOversee Okta services including SSO, MFA, and API authentication for workforce and application accessEnsure authentication services meet enterprise security, user experience, and regulatory requirements PKI & Certificate Services
Manage enterprise PKI services, including certificate issuance, automation, renewal, and lifecycle managementEnsure certificates are properly governed and integrated across applications, infrastructure, and security platformsSupport certificate compliance requirements across the enterprise Security, Risk & Compliance
Ensure IAM controls meet regulatory and audit requirements (e.g., SOX, internal cybersecurity standards)Support internal and external audits by providing evidence, walkthroughs, and remediation plansUnderstanding of look back effortsProactively identify IAM risks and lead remediation of control gaps and vulnerabilitiesLead the engineering, maintenance, and modernization of IAM platformsIdentify mitigating controls to reduce riskEnsure compliance with internal policies, audit requirements, and regulatory frameworks
QUALIFICATIONS
Knowledge and Skills
Deep knowledge of Identity and Access Management technologies across Active Directory, PKI, SailPoint, Okta, CyberArk, and modern authentication standardsStrong understanding of identity governance frameworks, privileged access controls, certificate-based authentication, and directory servicesAbility to architect and guide the implementation of secure, scalable IAM solutionsExperience leading complex engineering teams, including roadmapping, prioritization, and resource planningSolid understanding of Zero Trust principles, identity security best practices, audit requirements, and regulatory controlsAbility to embed security-by-design into all IAM engineering processesDemonstrated experience managing high-performing technical teams and developing engineering talentEffective stakeholder communication and coordination across security, infrastructure, and application teamsStrong problem-solving skills and ability to lead incident response related to IAM platformsVendor relationship and contract management experience (particularly with SailPoint, Okta, CyberArk, and certificate authorities)Hands on experience with Active Directory/Azure AD, SailPoint IdentityIQ & ISC, Okta (SSO, MFA), CyberArk (PAM), PKI/Certificate Services AI Skills Preferred:
Experience with AI assisted software development or automationKnowledge of prompting techniques to improve output qualityAwareness of emerging GenAI capabilities and limitations Experience and Education
5-7 years in Identity and Access Management or related experience at a medium-to-large company required3-5 years of experience in an IT leadership role preferredHigh School Diploma or equivalent requiredBachelor's Degree in related field or equivalent experience required What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.
Our Culture: Our team members define and shape our culture - an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work - we thrive.
Compensation: Competitive pay and bonus eligibility
Work Life Balance: Flexible hybrid work environment, 2-days a week in office
Location: Arlington (AOC1), TX office.
NOTE: We are unable to consider candidates who require visa sponsorship for this position
This position is not open to agency submissions
#GMFJobs #LI-Hybrid #LI-DW1