IAM Systems Manager

Posted Yesterday
Be an Early Applicant
New York, NY, USA
In-Office
Senior level
Energy
The Role
Lead design, implementation, and governance of enterprise IAM and PAM; define cloud identity strategy across AWS/Azure/GCP; secure non-human and AI agent identities; automate just-in-time access and secrets scanning; ensure compliance (NERC CIP, SOX); manage Tier 0 applications, vendor relationships, and a team; present access metrics via dashboards.
Summary Generated by Built In

Come join us at Con Edison as an IAM Systems Manager where you will play a pivotal role in shaping the future of our enterprise security. You will lead the design, implementation, and governance of our Identity and Access Management (IAM) systems. This role bridges the gap between legacy identity architectures and the autonomous, agent-driven future.

As the IAM Systems Manager, you will not only oversee traditional identity lifecycle and governance but also spearhead our Cloud Identity strategy and secure Agentic/Non-Human Identities (NHI) across our evolving AI and automation ecosystems. You will partner with business customers, security engineering, and cloud operations to ensure that all human, cloud, and machine identities are authenticated, properly authorized, and governed in real-time.

ResponsibilitiesCore Responsibilities
  • Lead the implementation, administration, and continuous optimization of Identity and Access Management (IAM) and Privileged Access Management (PAM) services.
  • Direct cloud IAM strategies across public cloud environments (AWS, Azure, GCP), encompassing Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), Service Control Policies (SCPs), and permissions boundaries.
  • Manage access, permissions, and identity stores, implementing automated solutions to streamline just-in-time access and session management.
  • Ensure systems maintain audit and privacy compliance with regulatory requirements (e.g., NERC CIP, SOX) by providing robust access reporting, entitlement mapping, and certification.
  • Manager Tier 0 application portfolio that include PAM, Active directory and DNS
  • Design and implement robust security controls for agentic and non-human identities (service accounts, machine/workload identities, API keys, and AI agents).
  • Establish unique non-human identities for AI agents, enforcing delegation instead of credential sharing, and applying dynamic, least-privilege authorization.
  • Define and enforce security boundaries and containment strategies for AI agents and automated workflows to reduce excessive privilege exposure and limit blast radius.
  • Perform credential and secrets scanning across AI environments to detect exposed credentials, utilizing tools like Secrets Manager, CIEM, and CSPM.
  • Implement runtime identity controls where access decisions for AI agents are evaluated continuously at the moment of action.
  • Manage and lead a team overseeing vendor relationships, technical interfaces, and system functionality between IAM platforms and business applications.
  • Partner closely with IAM engineering, AI technical leads, and enterprise architecture teams to align enterprise identity controls with emerging AI security initiatives.
  • Track investigation progress and access metrics, presenting complex analyses in clear, understandable terms to audiences at all levels via dashboards (e.g., Power BI).
QualificationsRequired Education/Experience
  • Bachelor's Degree and 8 years of relevant experience or
  • Master's Degree and 6 years of relevant experience.
Preferred Education/Experience
  • Master's Degree in Computer Science, Information Systems, Cybersecurity, or a related field and 6 years of relevant experience.
Relevant Work Experience
  • 6+ years of experience in enterprise Identity and Access Management (IAM/IGA), Privileged Access Management (PAM), and identity governance, required.
  • Deep understanding of cloud-native identity controls, particularly AWS IAM, Azure AD, federated identities (SAML, OAuth, OIDC), and Secrets Manager, required.
  • Proven hands-on experience securing non-human identities (NHIs), service accounts, and workload identities. Exposure to AI security, agentic identity concepts, and privilege escalation risks, required.
  • Proficiency with infrastructure-as-code and scripting (Terraform, GitHub, Python, PowerShell) to automate cloud infrastructure and identity configurations, required.
  • Ability to clearly articulate technical issues and concepts to business users, stakeholders, and vendors, working as a proactive member of a cross-functional team, required.
Skills and Abilities
  • Demonstrated problem solving skills
  • Ability to lead/manage others
  • Demonstrates a high commitment to quality
  • Ability to build strong customer relationships
Licenses and Certifications
  • Driver's License Required
Additional Physical Demands
  • The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
About Us

Mission Statement:


Consolidated Edison Company of New York, Inc. (Con Edison), Orange & Rockland Utilities (O&R), and Consolidated Edison Transmission (CET) employees are required to follow health, safety, and environmental policies, EEO, Standards of Business Conduct, and all other applicable company policy and procedures. We all share a responsibility to advance the company’s mission by excelling at our three corporate priorities – safety of our people and the public, operational excellence in all that we do, and ensuring the best possible customer experience.


Benefits:


We are dedicated to supporting the physical, mental, and financial health of our employees and their families. This commitment extends beyond the workplace to foster personal growth and holistic wellbeing. Our life-changing rewards package includes:


  • Rich medical & pharmacy benefits, including vision benefits
  • Dental benefits
  • Health Savings Accounts
  • Health Care and Dependent Care Flexible Spending Accounts
  • 401(k) with robust matching
  • Employer paid Pension Plan
  • Employee Stock Purchase Plan with a generous matching contribution
  • State of the art Employee Assistance Program
  • Paid Parental Leave
  • Generous paid time off plus paid holidays
  • Family support: emergency backup child, & elder care assistance
  • Social responsibility and volunteer opportunities
  • Employee discount program
  • Commuter Benefits
  • Culture of growth and learning: career development; tuition reimbursement; recognition program
  • Life and Long-Term Disability Benefits


*Please be aware that some benefits may not apply to provisional or part-time job titles.

About the Team

EEO Statement:

Consolidated Edison Company of New York, Inc. (Con Edison), Orange & Rockland Utilities (O&R), and Consolidated Edison Transmission (CET) are equal opportunity employers. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of the individual’s actual or perceived disability, protected veteran status, race, color, creed, religion, sex, age, national origin, gender, gender identity, gender expression, genetic information, marital status, sexual orientation, citizenship, domestic violence victim status, or any other actual or perceived status protected by law.

 

Technical Difficulty Statement:

For technical issues, please contact us at [email protected]


Skills Required

  • Bachelor's Degree and 8 years of relevant experience (or equivalent)
  • Master's Degree and 6 years of relevant experience (alternate education path)
  • 6+ years experience in enterprise Identity and Access Management (IAM/IGA) and Privileged Access Management (PAM)
  • Deep understanding of cloud-native identity controls (AWS IAM, Azure AD) and federated identities (SAML, OAuth, OIDC); Secrets Manager
  • Proven hands-on experience securing non-human identities (service accounts, workload identities, API keys, AI agents)
  • Proficiency with infrastructure-as-code and scripting (Terraform, GitHub workflows, Python, PowerShell)
  • Experience with CIEM, CSPM, credential/secrets scanning and runtime identity controls
  • Experience managing Tier 0 application portfolio including PAM, Active Directory, and DNS
  • Knowledge of regulatory compliance for access controls and reporting (e.g., NERC CIP, SOX)
  • Ability to present complex analyses and dashboards (e.g., Power BI) and communicate technical issues to stakeholders
  • Experience leading/managing a technical team and vendor relationships
  • Driver's license
  • Master's Degree in Computer Science, Information Systems, Cybersecurity, or related field
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
7,742 Employees

What We Do

We provide power to more than 10 million people and businesses across NYC and Westchester. Reliability and accessibility are central to what we do and how we provide energy service. Leading the industry to power tomorrow is our other focus- we are committed to aggressively transitioning away from fossil fuels to a net-zero economy by 2050. To help achieve this we collaborate with customers, regulators, policymakers, engineers, and other stakeholders to ensure our clean energy future is informed by principles of affordability, equity, and environmental justice. We’re also heavily investing in new technologies and the infrastructure that can get us there. What are a few things we have achieved so far? • Since 2009, our energy efficiency programs have prevented 11 million metric tons of carbon emissions – the same amount it would take to power 1.4 million homes for a year • We’re currently the second largest producer of solar energy in North America • Recently, we’ve embarked on an 8-year project to make our systems more resilient in the face of extreme weather events

Similar Jobs

PNC Bank Logo PNC Bank

System Reliability & Support Specialist Sr. - Core Apps and Payroll Team

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
45K-122K Annually

ServiceNow Logo ServiceNow

Account Executive

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
New York, NY, USA
29000 Employees
139K-230K Annually

ServiceNow Logo ServiceNow

Implementation Manager

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
New York, NY, USA
29000 Employees
116K-192K Annually

ServiceNow Logo ServiceNow

Architect

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
United States
29000 Employees
124K-217K Annually

Similar Companies Hiring

UL Solutions Thumbnail
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Chicago, IL
15000 Employees
Runwise Thumbnail
Greentech • Hardware • Real Estate • Software • Energy • PropTech
New York, NY
199 Employees
Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
108 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account