IAM Risk & Governance Lead

WorldpayAlpharetta, GA
Hybrid

About The Position

This position is hybrid 3 days per week in the following office locations: Cincinnati, OH or Atlanta, GA. This role involves leading the IAM Controls & Audit team, establishing operating standards, ownership models, staffing priorities, and a multi-year controls and automation roadmap. The position is responsible for owning IAM audit and assessment coordination across SOX, SOC, internal/external audits, regulatory reviews, customer audits, and security assessments, from planning through remediation. It also involves developing and governing the IAM control framework covering identity lifecycle management, access provisioning, authentication, privileged access, certifications, segregation of duties, and cloud/service identities. The role drives control readiness and remediation by overseeing testing, evidence quality, issue tracking, root cause analysis, corrective actions, and risk escalation. Additionally, it leads IAM GRC strategy and platform management, including tool selection, implementation, integrations, governance, vendor management, and ongoing service delivery. A key aspect is automating audit and control processes through integrations with IAM, IGA, PAM, HR, cloud, and service management platforms to improve efficiency, traceability, and compliance. The lead will chair the IAM Controls Council and provide leadership reporting on control health, audit outcomes, remediation status, automation adoption, risk reduction, and operational effectiveness.

Requirements

  • 10+ years in IAM, cybersecurity risk, technology controls, or audit readiness, including 3+ years leading teams or cross-functional IAM governance programs in a large, regulated enterprise.
  • Ability to build and coach a team, set priorities, and hold stakeholders accountable for outcomes.
  • Demonstrated leadership of IAM workstreams across multiple SOX/SOC and internal or external audit cycles, including walkthroughs, control testing coordination, evidence quality assurance, deficiency assessment, corrective-action tracking, and executive reporting.
  • Strong working knowledge of IAM, PAM, and IGA controls, including joiner-mover-leaver processes, authentication, privileged access, access reviews, segregation of duties, dormant accounts, excessive permissions, and cloud identity governance.
  • Ability to translate technical workflows and configurations into clear control narratives and risk decisions.
  • Hands-on experience operating GRC evidence and remediation workflows in platforms such as AuditBoard, Archer, or ServiceNow, plus experience leading enterprise platform evaluation or implementation.
  • Ability to define requirements, assess integration and automation options, manage a backlog, and demonstrate adoption and operational value.
  • Strong stakeholder management across IAM engineering, control owners, GRC, Finance, service providers, and auditors.
  • Ability to build business cases, define useful control metrics and dashboards, communicate material risk to executives, and drive timely remediation across organizational boundaries.

Nice To Haves

  • Experience integrating GRC workflows with platforms such as SailPoint, Saviynt, BeyondTrust, CyberArk, Delinea, Microsoft Entra ID, Okta, AWS, or enterprise HR and service-management systems.
  • Experience with control automation, continuous control monitoring, permissions-risk dashboards, and process improvement that measurably reduces evidence preparation and control-owner workload.
  • Relevant credentials such as CISA, CRISC, CISSP, CISM, PMP, Security+, Scrum Master, or Lean Six Sigma, and experience in payments or financial services.

Responsibilities

  • Lead the IAM Controls & Audit team, establishing operating standards, ownership models, staffing priorities, and a multi-year controls and automation roadmap.
  • Own IAM audit and assessment coordination across SOX, SOC, internal/external audits, regulatory reviews, customer audits, and security assessments, from planning through remediation.
  • Develop and govern the IAM control framework covering identity lifecycle management, access provisioning, authentication, privileged access, certifications, segregation of duties, and cloud/service identities.
  • Drive control readiness and remediation by overseeing testing, evidence quality, issue tracking, root cause analysis, corrective actions, and risk escalation.
  • Lead IAM GRC strategy and platform management, including tool selection, implementation, integrations, governance, vendor management, and ongoing service delivery.
  • Automate audit and control processes through integrations with IAM, IGA, PAM, HR, cloud, and service management platforms to improve efficiency, traceability, and compliance.
  • Chair the IAM Controls Council and provide leadership reporting on control health, audit outcomes, remediation status, automation adoption, risk reduction, and operational effectiveness.

Benefits

  • The EEO is the Law poster is available here.
  • Reasonable accommodations will be made for individuals with qualified disabilities both during the hiring process, as well as to allow the individual to perform the essential functions of the job, if hired.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service