Manager, Identity and Access Management

Posted Yesterday
Be an Early Applicant
Dallas, TX, USA
In-Office
Senior level
Artificial Intelligence • Cloud • Machine Learning • Infrastructure as a Service (IaaS)
The Role
Lead and grow an IAM engineering team to own enterprise and workload identity across human and non-human identities. Define strategy for Microsoft Entra ID, RBAC, PAM, PKI, SPIFFE/SPIRE-based workload identity, mTLS, and zero trust. Integrate IAM into CI/CD and IaC, establish governance and access reviews, and report identity risk and program metrics to leadership.
Summary Generated by Built In

The Company

NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.

The Position

The Identity and Access Management team sits within NMC²'s Security organization and is responsible for ensuring that every human, service, and workload interacting with NMC²'s platforms is verifiably identified, appropriately authorized, and continuously validated. In an environment where HPC workloads, cloud services, and distributed systems operate at massive scale, identity is the foundational control plane.

As the Manager of Identity and Access Management, you will lead a team of engineers responsible for the full spectrum of identity from enterprise identity and access governance to workload and service identity using cryptographic attestation via SPIFFE/SPIRE, mTLS, and PKI. You will set the strategic direction for how NMC² establishes trust across its human and non-human identity landscape, drive the maturation of the organization's zero trust posture, and serve as the primary IAM partner to Platform Engineering, DevOps, and IT leadership. This role demands both deep technical fluency across modern identity protocols and the leadership capability to build a high-performing team and drive identity-first thinking across the organization.

Responsibilities

  • Lead, mentor, and develop a team of IAM engineers, setting clear priorities, fostering technical growth, and cultivating a collaborative, high-performing team culture

  • Own the strategy and roadmap for NMC²'s enterprise identity program, including identity lifecycle management, role-based access control (RBAC), privileged access management (PAM), and access governance across Microsoft Entra ID and connected systems

  • Drive the design, implementation, and operation of workload and service identity programs using SPIFFE/SPIRE, ensuring cryptographically verifiable identity for services, workloads, and infrastructure components across HPC and cloud environments

  • Oversee the organization's PKI strategy and certificate lifecycle management program, ensuring the integrity, availability, and scalability of certificate issuance, rotation, and revocation across the enterprise

  • Lead the adoption and enforcement of mTLS for service-to-service communication, partnering with Platform Engineering and DevOps teams to embed mutual authentication into the fabric of NMC²'s distributed systems

  • Drive NMC²'s zero trust identity strategy, ensuring continuous validation of user, device, and workload identity as the primary access control mechanism across on-premises and cloud environments

  • Partner with Platform Engineering, DevOps, and IT leadership to integrate IAM controls into CI/CD pipelines, IaC workflows, and platform architecture, ensuring identity is never bolted on as an afterthought

  • Establish and maintain identity governance frameworks, including access reviews, entitlement management, and least-privilege enforcement across both human and non-human identities

  • Translate complex identity risks, program metrics, and strategic initiatives into clear, concise reporting for security leadership and executive stakeholders

  • Stay current on emerging identity threats, standards, and technologies — including evolving SPIFFE/SPIRE ecosystem developments, certificate transparency, and zero trust frameworks — continuously maturing the team's capabilities

Requirements

  • 6+ years of experience in identity and access management or security engineering, with hands-on depth across both enterprise and workload identity domains

  • 2–3+ years of experience leading or managing an IAM or security engineering team, with demonstrated ability to develop talent and drive team performance

  • Deep expertise in Microsoft Entra ID (Azure AD), including conditional access, identity governance, privileged identity management (PIM), and enterprise application integration

  • Hands-on experience with SPIFFE/SPIRE or equivalent workload identity frameworks, and a strong understanding of cryptographic identity attestation in distributed and containerized environments

  • Strong command of PKI fundamentals, including certificate authority design, certificate lifecycle management, and certificate issuance patterns for large-scale environments

  • Experience designing and enforcing mTLS architectures for service-to-service communication across microservices, container orchestration platforms, and cloud-native environments

  • Familiarity with zero trust architecture principles and experience applying them across a hybrid enterprise and cloud-native environment

  • Experience with privileged access management solutions and least-privilege enforcement strategies across both human and service accounts

  • Excellent communication skills with the ability to translate complex identity concepts and risks into clear reporting and recommendations for engineering peers and executive leadership

Nice to Have

  • Experience with secrets management platforms such as HashiCorp Vault, with integration into PKI and workload identity workflows

  • Background working in HPC, research computing, or highly regulated environments where identity assurance requirements are exceptionally stringent

  • Familiarity with certificate transparency logs and emerging standards in machine identity management

  • Relevant certifications such as CISSP, CISM, Microsoft Certified: Identity and Access Administrator, or equivalent

It is impossible to list every requirement for, or responsibility of, any position.  Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company’s needs may change over time.  Therefore, the above job description is not comprehensive or exhaustive.  The Company reserves the right to adjust, add to or eliminate any aspect of the above description.  The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.

Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Benefits & Perks:

  • Company-Paid Lunch Stipend: Lunch is provided via GrubHub

  • Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability

  • 401(k): Company will match 100% of your contributions up to 6%

  • Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.

  • Time Off:  25 days of Paid Time Off plus 12 company holidays

EQUAL OPPORTUNITY EMPLOYER

NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW. THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.

Skills Required

  • 6+ years of experience in identity and access management or security engineering
  • 2-3+ years of experience leading or managing an IAM or security engineering team
  • Deep expertise in Microsoft Entra ID (Azure AD) including conditional access, identity governance, PIM, and enterprise application integration
  • Hands-on experience with SPIFFE/SPIRE or equivalent workload identity frameworks and cryptographic identity attestation
  • Strong command of PKI fundamentals, certificate authority design, and certificate lifecycle management
  • Experience designing and enforcing mTLS architectures for service-to-service communication in microservices and cloud-native environments
  • Familiarity with zero trust architecture principles and applying them across hybrid enterprise and cloud-native environments
  • Experience with privileged access management solutions and least-privilege enforcement across human and service accounts
  • Excellent communication skills to translate complex identity concepts and risks for engineering peers and executive leadership
  • Experience with secrets management platforms such as HashiCorp Vault integrated into PKI and workload identity workflows
  • Background working in HPC, research computing, or highly regulated environments
  • Familiarity with certificate transparency logs and emerging standards in machine identity management
  • Relevant certifications such as CISSP, CISM, Microsoft Certified: Identity and Access Administrator
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
157 Employees

What We Do

NorthMark Strategies is a strategic capital firm that combines investment capital with engineering and technology to build enduring businesses. The firm operates a High-Performance Computing platform and supports simulation, AI/ML-enabled engineering and data-driven design to accelerate portfolio companies. NorthMark deploys capital, operates complex businesses, and builds infrastructure (including compute and cloud services) to drive long‑term innovation and operational outcomes.

Similar Jobs

In-Office
5 Locations
17 Employees
105K-214K Annually
In-Office
4 Locations
8926 Employees
136K-227K Annually
In-Office
4 Locations
8926 Employees
109K-182K Annually

Similar Companies Hiring

Legora Thumbnail
Artificial Intelligence • Legal Tech • Software
New York, New York
700 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account