Manager - IAM Engineering and Integration

Posted Yesterday
Be an Early Applicant
Arlington, TX, USA
Hybrid
Senior level
Fintech • Financial Services
The Role
Leads IAM engineering, integration, and operations across Active Directory, SailPoint, Okta, CyberArk, and PKI environments. Manages IAM engineers and service partners while overseeing identity lifecycle automation, access governance, privileged access management, authentication, certificate services, platform architecture, and integrations. Ensures scalable hybrid IAM services align with Zero Trust, least privilege, audit, regulatory, and cybersecurity requirements. Drives remediation, modernization, incident escalation, stakeholder coordination, and technical team development.
Summary Generated by Built In

Why GMF Technology?

Innovation isn’t just a talking point at GM Financial, it’s how we operate. From generative AI and cloud-native technologies to peer-led learning and hackathons, our tech teams are building real solutions that make a difference. We’re committed to AI-powered transformation, using advanced machine learning and automation to help us reimagine customer interactions and modernize operations, positioning GM Financial as a leader in digital innovation within a dynamic industry.

Join us and discover a workplace where your ideas matter, your development is prioritized, and you can truly make a global impact.

Flexible hybrid work environment (onsite 2 days a week/3 days remote) at our Arlington (AOC1), TX office.
Please note: We are unable to provide any type of sponsorship for this position at this time.  

Responsibilities

The Manager of Identity & Access Management Engineering and Integration is responsible for leading the design, engineering, integration, and operational excellence of enterprise IAM platforms. This role ensures secure, scalable, and compliant identity services across Active Directory, SailPoint IdentityIQ (IQ), SailPoint Identity Security Cloud (ISC), Okta, CyberArk, and PKI Services, supporting on‑premises, cloud, and hybrid environments.

The manager leads a team of IAM engineers and analysts, serving as a tower lead for our managed service partner resources and works cross‑functionally with cybersecurity, infrastructure, application teams, and audit partners to deliver identity lifecycle automation, privileged access management, authentication services, and certificate services aligned with Zero Trust and least‑privilege principles.

IAM Platform Engineering & Integration

  • Lead engineering, configuration, and lifecycle management of IAM platforms including Active Directory, SailPoint (IIQ and ISC), Okta, CyberArk, and PKI Services
  • Oversee platform integrations with HR systems, ServiceNow, enterprise applications, cloud services, and third party vendors
  • Ensure resilient, highly available, and scalable IAM architectures across on prem and cloud environments
  • Establish reference architectures, integration patterns, and technical standards for IAM services

Active Directory

  • Provide technical and operational leadership for enterprise Active Directory services, including on premises and hybrid directory environments
  • Own AD architecture, design standards, and operational patterns, ensuring alignment with Zero Trust, least privilege, and identity centric security models
  • Oversee directory hygiene and lifecycle management, including user objects, service accounts, groups, and delegated administration models
  • Lead AD group and service account governance, ensuring alignment with SailPoint driven identity lifecycle (Joiner Mover Leaver) processes and access certifications
  • Partner with Identity Governance teams to ensure AD entitlements are authoritative, well modeled, and auditable within SailPoint
  • Ensure secure integration between Active Directory and Okta, including federation, authentication flows, and directory synchronization
  • Support and enhance privileged access controls for AD in coordination with CyberArk, including protection of domain level and Tier 0 privileged accounts
  • Lead AD remediation and risk reduction efforts, including cleanup of legacy groups, orphaned accounts, excessive permissions, and insecure configurations
  • Establish and maintain monitoring, alerting, and operational metrics for directory services availability, security posture, and access integrity
  • Act as the escalation point for directory related incidents, audits, and compliance inquiries, ensuring timely remediation and root cause resolution
  • Collaborate with Infrastructure, Endpoint, Cloud, and Security Architecture teams to ensure AD remains a foundational identity control plane for enterprise services

Identity Governance & Lifecycle Management

  • Own Joiner Mover Leaver (JML) automation, role based access control (RBAC), entitlement modeling, and access request workflows using SailPoint
  • Ensure consistent execution of access certifications
  • Partner with application owners and engineers to onboard applications into IAM governance and provisioning frameworks to ensure completeness and accuracy and entitlement metadata
  • Assist in testing of lower environments

Privileged Access & Authentication Services

  • Lead implementation and ongoing enhancement of CyberArk for privileged account management, credential vaulting, and session monitoring
  • Oversee Okta services including SSO, MFA, and API authentication for workforce and application access
  • Ensure authentication services meet enterprise security, user experience, and regulatory requirements

PKI & Certificate Services

  • Manage enterprise PKI services, including certificate issuance, automation, renewal, and lifecycle management
  • Ensure certificates are properly governed and integrated across applications, infrastructure, and security platforms
  • Support certificate compliance requirements across the enterprise

Security, Risk & Compliance

  • Ensure IAM controls meet regulatory and audit requirements (e.g., SOX, internal cybersecurity standards)
  • Support internal and external audits by providing evidence, walkthroughs, and remediation plans
  • Understanding of look back efforts
  • Proactively identify IAM risks and lead remediation of control gaps and vulnerabilities
  • Lead the engineering, maintenance, and modernization of IAM platforms
  • Identify mitigating controls to reduce risk
  • Ensure compliance with internal policies, audit requirements, and regulatory frameworks
Qualifications

Knowledge and Skills

  • Deep knowledge of Identity and Access Management technologies across Active Directory, PKI, SailPoint, Okta, CyberArk, and modern authentication standards
  • Strong understanding of identity governance frameworks, privileged access controls, certificate-based authentication, and directory services
  • Ability to architect and guide the implementation of secure, scalable IAM solutions
  • Experience leading complex engineering teams, including roadmapping, prioritization, and resource planning
  • Solid understanding of Zero Trust principles, identity security best practices, audit requirements, and regulatory controls
  • Ability to embed security-by-design into all IAM engineering processes
  • Demonstrated experience managing high-performing technical teams and developing engineering talent
  • Effective stakeholder communication and coordination across security, infrastructure, and application teams
  • Strong problem-solving skills and ability to lead incident response related to IAM platforms
  • Vendor relationship and contract management experience (particularly with SailPoint, Okta, CyberArk, and certificate authorities)
  • Hands on experience with Active Directory/Azure AD, SailPoint IdentityIQ & ISC, Okta (SSO, MFA), CyberArk (PAM), PKI/Certificate Services

Experience and Education

  • 5-7 years in Identity and Access Management or related experience at a medium-to-large company required
  • 3-5 years of experience in an IT leadership role preferred
  • High School Diploma or equivalent required
  • Bachelor’s Degree in related field or equivalent experience required
     

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.

Our Culture: Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.

Compensation: Competitive pay and bonus eligibility

Work Life Balance: Flexible hybrid work environment, 2-days a week in office

NOTE: We are unable to consider candidates who require visa sponsorship for this position

This position is not open to agency submissions 

#GMFJobs #LI-Hybrid #LI-DW1

Skills Required

  • 5-7 years of Identity and Access Management or related experience at a medium-to-large company
  • 3-5 years of experience in an IT leadership role
  • High School Diploma or equivalent
  • Bachelor's Degree in a related field or equivalent experience
  • Deep knowledge of Active Directory, PKI, SailPoint, Okta, CyberArk, and modern authentication standards
  • Strong understanding of identity governance, privileged access controls, certificate-based authentication, and directory services
  • Experience architecting and implementing secure, scalable IAM solutions
  • Experience leading complex engineering teams, including roadmapping, prioritization, and resource planning
  • Understanding of Zero Trust principles, identity security best practices, audit requirements, and regulatory controls
  • Experience managing technical teams and developing engineering talent
  • Stakeholder communication and coordination across security, infrastructure, and application teams
  • Experience leading IAM-related incident response and resolving complex problems
  • Vendor relationship and contract management experience
  • Hands-on experience with Active Directory or Azure AD, SailPoint IdentityIQ and ISC, Okta SSO and MFA, CyberArk PAM, and PKI or certificate services

GM Financial Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about GM Financial and has not been reviewed or approved by GM Financial.

  • Strong & Reliable Incentives Annual and performance bonuses are described as meaningful additions to total compensation. In several functions, incentives reliably boost take-home pay when available.
  • Leave & Time Off Breadth Generous paid time off, corporate and floating holidays, and paid volunteer time are emphasized. Time-away programs contribute significantly to perceived total rewards.
  • Parental & Family Support Paid parental leave and family-friendly policies are highlighted, with recent expansions mentioned in some areas. Support for bonding time is seen as a notable strength of the package.

GM Financial Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fort Worth, TX
7,790 Employees
Year Founded: 1992

What We Do

GM Financial is the captive finance company and the wholly owned subsidiary of General Motors and is headquartered in Fort Worth, Texas. The company is a global provider of auto finance solutions, with operations in North America, Latin America and China. Through our long-standing relationships with auto dealers, we offer attractive retail loan and lease programs to meet the needs of each customer. We also offer commercial lending products to dealers to help them finance and grow their businesses. GM Financial employs more than 9,000 hard-working team members, and we're always looking for new people with diverse talents. GM Financial is a workplace where dedicated people have the opportunity to work together and celebrate our successes. Our culture is based on respect, integrity, innovation and personal development. GM Financial is committed to strengthening the communities where we live and work. Each year, we select several philanthropic organizations to support through our Signature Events program. The company and its team members actively support these organizations through many company-wide initiatives; in addition we support numerous other nonprofit organizations through sponsorships and monetary donations.

Similar Jobs

Samsara Logo Samsara

Sales Compensation Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
107K-144K Annually

PwC Logo PwC

Designer

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
6 Locations
370000 Employees
77K-202K Annually

ChowNow Logo ChowNow

Analytics Manager

Food • Software
Easy Apply
Remote or Hybrid
USA
208 Employees
120K-152K Annually

PwC Logo PwC

Site Reliability Engineer

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
9 Locations
370000 Employees
124K-280K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account