Covetrus is a global animal-health technology and services leader dedicated to empowering veterinary practice partners to drive improved health and financial outcomes. We bring together products, services, and technology into a single platform that connects our customers to the solutions and insights they need to work best. Our passion for the well-being of animals and those who care for them drives us to advance the world of veterinary medicine.
IAM / Automation LeadInformation Technology • Full-Time • Remote
About the RoleAs the IAM / Automation Lead, you will own the strategy, operations, and roadmap for enterprise Identity & Access Management (IAM) — protecting our workforce, applications, and data by ensuring the right people have the right access at the right time.
This is a high-impact, senior level role reporting to the Senior Director of IT. You will serve as the organization’s subject-matter expert and technical lead for enterprise IAM, partnering closely with IT, HR, Legal, and Compliance, and driving continuous maturity of our identity posture across cloud and on-premises environments. The role carries a heavy focus on automation and self-service — reducing manual operations, improving the end-user experience, and strengthening our cybersecurity posture while delivering cost savings.
Key Responsibilities- Serve as the North American Center of Excellence (COE) lead for IAM, partnering with global COE counterparts to align standards, tooling, and best practices — ensuring IAM responsibilities and services are delivered consistently on a global basis
- Serve as the technical lead for IAM integration on current and future mergers, acquisitions, and divestitures (M&A)
- Lead the design, implementation, and operations of IAM programs including SSO, MFA, PAM, IGA, and directory services
- Deliver measurable cost savings and operational efficiencies by leading product evaluations, tools consolidations, and IAM initiatives back by data-driven financial business cases
- Enforce compliance with IAM policies and standards; Create procedures aligned to NIST, CIS, ISO 27001, SOX, and other applicable frameworks
- Own user lifecycle management: joiner/mover/leaver (JML) execution, access provisioning, role engineering, and automated de-provisioning
- Drive automation and self-service capabilities across the IAM function — including automated access requests, approvals, and provisioning — to reduce manual operations and improve the end-user service experience
- Partner with End User Services and the Service Desk to identify and automate away manual, ticket-based access requests, replacing them with self-service and automated workflows
- Deliver automated entitlement and permission reviews across SaaS, cloud, and on-prem applications
- Mature Privileged Access Management (PAM) adoption, including vault adoption, session monitoring, and just-in-time (JIT) access
- Partner with Cyber and Network Operations on global user controls, including Zero Trust and SSO group management — leading identity-centric network access controls and conditional access policy development
- Build and maintain integrations between IAM platforms, HR systems (HCM), ticketing systems, and downstream applications via SCIM, LDAP, and API connectors
- Define KPIs and metrics for access hygiene, orphaned accounts, and privilege sprawl; report SLA performance and program health to leadership quarterly
- Partner across teams to advance the IAM roadmap, and support IAM vendor relationships, licensing, and contract renewals in collaboration with Cyber and Procurement
- Serve as a technical mentor to IAM engineers and analysts, sharing best practices in design, implementation, and troubleshooting
- Support audits (SOX, SOC 2, ISO 27001) with evidence of quarterly access reviews, control narratives, and remediation tracking
- Drive IAM roadmap planning with a 12–18 month horizon, balancing security uplift with employee experience
Identity Governance & Administration (IGA)
- Okta Identity Governance
- Microsoft Entra ID Governance
- One Identity Manager
Single Sign-On & Federation
- Okta Workforce Identity (SSO, MFA, Lifecycle Management, Workflows)
- Microsoft Entra ID (Azure AD) — Conditional Access, PIM, Entitlement Management
Privileged Access Management (PAM)
- CyberArk PAM Suite (Vault, PSM, PVWA, CPM, Conjur)
- BeyondTrust Password Safe / Privileged Remote Access
- Delinea Secret Server / Privileged Access Service
- HashiCorp Vault (secrets management)
Directory Services
- Microsoft Active Directory (AD) & Active Directory Federation Services (ADFS)
- Microsoft Entra ID (Azure AD)
- LDAP / OpenLDAP
Cloud & Infrastructure Platforms
- AWS IAM, AWS Identity Center (SSO), AWS Cognito
- Microsoft Azure — Entra ID, Managed Identities, RBAC
- Kubernetes RBAC and workload identity
Protocols & Standards
- SAML 2.0, OAuth 2.0, OpenID Connect (OIDC)
- SCIM 2.0 (automated provisioning/deprovisioning)
- LDAP / LDAPS, Kerberos, RADIUS
- FIDO2 / WebAuthn (phishing-resistant MFA)
ITSM, SIEM & Adjacent Tools
- ServiceNow (self-service access catalog, automated request fulfillment, ITSM integration)
- Splunk / Microsoft Sentinel (identity threat detection, UEBA)
- CrowdStrike Falcon Identity Protection
- Workday / SAP SuccessFactors (HRIS integration for JML)
- Jira / Confluence (project tracking, runbooks)
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent professional experience will be considered in lieu of a degree.
- 8+ years of progressive experience in information security or information technology, including 4+ years focused specifically on Identity and Access Management (IAM), with a demonstrated track record of applying automation and engineering discipline to reduce risk and manual effort
- 3+ years serving as a senior or lead technical contributor on an IAM function or program within a mid-to-large enterprise environment (5,000+ employees), with direct accountability for security outcomes and operational metrics
- Hands-on engineering experience designing, building, and operating enterprise IAM automation — including workflow engines, API/SCIM-based provisioning pipelines, and self-service access solutions that eliminate manual, ticket-based processes
- Experience integrating joiner/mover/leaver (JML) automation with an HRIS platform (e.g., Workday, SAP SuccessFactors, or similar) to drive straight-through processing and eliminate manual provisioning touchpoints
- Experience automating access certification/recertification campaigns at enterprise scale, reducing audit preparation time and manual reviewer effort
- Experience supporting compliance and security audits (SOX, SOC 2, ISO 27001, HIPAA, or equivalent), with a focus on building repeatable, automated evidence-collection and control-monitoring processes
- Experience managing PAM programs and vault platforms (e.g., CyberArk, BeyondTrust, Delinea) in production, including automating credential rotation, session monitoring, and just-in-time access to shrink the enterprise attack surface
- Demonstrated success building data-driven business cases that translate automation and tooling consolidation into measurable cost savings and licensing efficiencies
- Relevant industry certifications preferred (e.g., CISSP, CIAM, SC-300, Okta Certified Professional, or equivalent)
Automation & Engineering
- Strong engineering mindset: able to design, script, and deploy automated identity workflows (SCIM, LDAP, REST/API connectors) rather than relying on manual or ticket-driven processes
- Proven ability to identify high-friction, manual IAM operations and re-architect them into scalable, self-service, automated solutions
- Skilled in building automated provisioning, de-provisioning, and entitlement review pipelines across SaaS, cloud, and on-prem systems
- Comfortable working across scripting/automation tooling (e.g., PowerShell, Python, workflow orchestration platforms) to extend platform capabilities beyond out-of-the-box functionality
Cybersecurity Expertise
- Deep working knowledge of authentication and federation protocols (SAML 2.0, OAuth 2.0, OIDC, Kerberos, LDAP/LDAPS) and how they underpin a secure identity fabric
- Strong grasp of Zero Trust architecture, conditional access, and least-privilege enforcement as engineering requirements, not just policy statements
- Ability to harden IAM/PAM environments against credential theft, privilege escalation, and lateral movement, and to translate threat intelligence into control improvements
- Skilled in defining and tracking security KPIs (orphaned accounts, privilege sprawl, stale entitlements, MFA/phishing-resistant authentication coverage) to continuously mature the identity security posture
Operational Efficiency
- Track record of measurably reducing manual operations, ticket volume, and mean-time-to-provision through automation and process redesign
- Strong bias toward eliminating toil: consistently looks for ways to remove human touchpoints from repeatable IAM processes without compromising control
- Ability to design for scale and resilience, ensuring automated processes hold up across M&A integrations, org changes, and growth
- Skilled in building dashboards/metrics that give leadership real-time visibility into program health and operational throughput
Cost Optimization & Business Value
- Ability to build and present data-driven financial business cases for tooling consolidation, license optimization, and platform rationalization
- Skilled in quantifying the ROI of automation initiatives (labor hours saved, ticket deflection, reduced audit remediation costs)
- Strong vendor and contract management acumen, able to negotiate and manage IAM licensing to avoid overspend and redundant tooling
Leadership & Collaboration
- Ability to serve as a technical mentor, instilling automation-first and security-first engineering practices in junior engineers and analysts
- Strong cross-functional collaboration with IT, HR, Legal, Compliance, Cyber, and Procurement to align automation initiatives with business and audit requirements
- Effective communicator, able to translate technical automation and security work into business impact and cost-savings narratives for executive leadership
Physical Demands/Work Environment
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Travel as required to remote locations to provide project and technology services
- On-call and on-demand extended work hours may include nights and weekends
We offer the following benefits for you to take advantage of while you are here provided you meet the eligibility requirements under each governing program:
401k savings & company match
Paid time off
Paid holidays
Maternity leave
Parental leave
Military leave
Other leaves of absence
Health, dental, and vision benefits
Health savings accounts
Flexible spending accounts
Life & disability benefits
Identity theft protection
Pet insurance
Certain positions may include eligibility for a short-term incentive plan
Salary may vary depending on factors such as confirmed job-related skills, experience, and location. It is not typical for an individual to be hired at or near the top end of the range for their role. Compensation decisions are dependent upon the facts and circumstances of each case. Sales Positions are eligible for a Variable Incentive.
The pay range for this position is as follows:
$86,300-$123,300Covetrus is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.
Skills Required
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent professional experience
- 8+ years of progressive experience in information security or information technology
- 4+ years of experience specifically focused on Identity and Access Management
- 3+ years as a senior or lead technical contributor on an IAM function or program in a mid-to-large enterprise environment
- Hands-on experience designing, building, and operating enterprise IAM automation, including workflow engines, API or SCIM provisioning pipelines, and self-service access solutions
- Experience integrating joiner, mover, and leaver automation with an HRIS such as Workday or SAP SuccessFactors
- Experience automating enterprise-scale access certification and recertification campaigns
- Experience supporting SOX, SOC 2, ISO 27001, HIPAA, or equivalent compliance and security audits
- Experience managing production PAM programs and platforms such as CyberArk, BeyondTrust, or Delinea
- Demonstrated success building data-driven business cases for automation, tooling consolidation, and licensing efficiencies
- Relevant industry certification such as CISSP, CIAM, SC-300, or Okta Certified Professional
Covetrus Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Covetrus and has not been reviewed or approved by Covetrus.
-
Leave & Time Off Breadth — Paid time off is described as a notable part of the package, including paid holidays and vacation time, with additional mention of paid sick leave in some cases. Time-off flexibility is also referenced positively via flexible or “unlimited” PTO for certain roles.
-
Healthcare Strength — Medical, dental, and vision insurance are presented as core, standard offerings with broad coverage categories. Health insurance is characterized as reasonably solid in coverage even if not positioned as best-in-class.
-
Retirement Support — A 401(k) plan is available and is repeatedly paired with mention of a company match structure. The match is framed as present but modest compared with richer market alternatives.
Covetrus Insights
What We Do
Covetrus specializes in the production and distribution, inventory management, software and prescription management for veterinary care. Covetrus is a global animal-health technology and services company dedicated to empowering veterinary practice partners to drive improved health and financial outcomes. We’re bringing together products, services, and technology into a single platform that connects our customers to the solutions and insights they need to work best. Our passion for the well-being of animals and those who care for them drives us to advance the world of veterinary medicine. Covetrus is headquartered in Portland, Maine, with more than 5,500 employees, serving over 100,000 customers around the globe.
.png)








