About The Position

The IAM Identity, Authentication, Authorization & Governance Senior Security Specialist sits within Global Information Security (GIS) and plays a highly visible role in shaping how human, machine, and service identities are governed across the enterprise. This role offers the opportunity to influence strategic security priorities, partner with senior stakeholders across technology, risk, compliance, and audit, and help strengthen how authentication and authorization controls evolve to support cloud and digital growth. It is an excellent opportunity for an internal candidate looking to broaden their impact, build enterprise-wide relationships, and contribute to a critical and evolving security agenda.

Requirements

  • 10+ years of experience in identity and access management, cybersecurity, cloud security, or access management within large, complex organizations.
  • Leadership experience required
  • Demonstrated success setting direction for or influencing enterprise-scale IAM transformation, modernization, governance, or control programs.
  • Deep knowledge of modern authentication, federation, and authorization standards and patterns, including OAuth 2.0, OpenID Connect, SAML, service-to-service access, and token-based authentication.
  • Experience governing identity and access across cloud, SaaS, API, application, and hybrid environments.
  • Strong understanding of human and non-human identity risk, including workload, service, machine, and AI-agent identities, delegated authority, and lifecycle accountability.
  • Experience translating policy, regulatory, and audit requirements into practical identity controls within regulated environments.
  • Knowledge of relevant standards and frameworks, including NIST, ISO, FFIEC, SOX, SOC, or equivalent.
  • Demonstrated ability to advise, brief, and influence senior leaders on complex technology, security, and risk matters.
  • Exceptional written and verbal communication skills, with experience translating complex concepts into clear executive-level presentations and recommendations.
  • Strong judgment and analytical decision-making skills, with the ability to operate effectively in ambiguous and rapidly evolving environments.
  • Proven ability to prioritize competing demands, drive cross-functional alignment, and deliver measurable outcomes.

Nice To Haves

  • Experience in financial services, banking, or another highly regulated industry.
  • Knowledge of RBAC, ABAC, PBAC, segregation of duties, just-in-time access, runtime authorization, and cloud entitlement management.
  • Experience with identity platforms such as Active Directory, Microsoft Entra ID, Ping, or equivalent technologies.
  • Experience with identity analytics, automation, policy-as-code, AI-enabled security solutions, or workflow optimization.
  • Familiarity with scripting and analytics tools such as Python, R, SQL, Splunk, Tableau, Power BI, Microsoft Copilot Studio, Power Automate, or equivalent.
  • Experience with cloud security, infrastructure, microsegmentation, monitoring, infrastructure-as-code, or related technologies.
  • Industry certification such as CISSP, CCSP, CRISC, CISM, or equivalent.

Responsibilities

  • Establish IAM control requirements, governance measures, and escalation paths in partnership with risk and control organizations.
  • Translate internal policy, regulatory, and audit requirements into practical, sustainable controls across enterprise platforms and processes.
  • Drive remediation of identity risks and control gaps across business and technology organizations, escalating risk acceptance decisions as appropriate.
  • Provide executive-level reporting and recommendations on identity risk, control health, adoption, exceptions, and remediation progress.
  • Support audit readiness and sustainable issue closure through clear accountability, evidence, metrics, and ongoing control monitoring.
  • Build trusted partnerships across GIS, Core Technology, Application Development, Risk, Compliance, Audit, and Third-Party Management.
  • Advise and influence senior leaders on complex identity, technology, security, and risk matters, including strategic options and trade-offs.
  • Drive cross-functional alignment, ownership, and adoption across teams operating at different speeds and maturity levels.
  • Translate complex technical and risk concepts into clear executive recommendations, decisions, and measurable outcomes.
  • Define enterprise business requirements, strategic direction, and standards for authentication, authorization, and identity governance.
  • Establish governance for human, non-human, workload, service, and AI-agent identities, including ownership, lifecycle management, delegated authority, credential rotation and revocation, and human accountability.
  • Set enterprise standards for API authentication and authorization, service-to-service access, token-based controls, and consistent secure identity patterns.
  • Drive adoption of zero trust, least privilege, phishing-resistant and passwordless authentication, continuous access evaluation, and fine-grained, context-aware authorization.
  • Advance policy-as-code, automated control enforcement, and identity threat detection to improve control consistency and reduce manual risk.
  • Embed IAM requirements into application, platform, API, cloud, and AI solution design and development lifecycles.
  • Influence investment priorities and modernization roadmaps that reduce standing privilege, unmanaged identities, inconsistent access patterns, and control gaps.
  • Define measures of adoption, control health, identity risk, and remediation progress, and use results to drive accountable outcomes.

Benefits

  • Access to paid time off
  • Resources and support to our employees
  • Discretionary incentive eligible
  • Annual discretionary award based on individual performance, business performance, and company success.
  • Industry-leading benefits
  • Affordable, competitive and flexible benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service