Skip to content
← Back to job listings

Manager - IAM Engineering and Integration

Fa Exvu Saasfaprod1 (CX_1) · Arlington, TX, United States

IT - Network / Systems / DB AdminExternal listingfull-timeabout 2 hours ago

About The Role

Why GMF Technology?

Innovation isn’t just a talking point at GM Financial, it’s how we operate. From generative AI and cloud-native technologies to peer-led learning and hackathons, our tech teams are building real solutions that make a difference. We’re committed to AI-powered transformation, using advanced machine learning and automation to help us reimagine customer interactions and modernize operations, positioning GM Financial as a leader in digital innovation within a dynamic industry.

Join us and discover a workplace where your ideas matter, your development is prioritized, and you can truly make a global impact.

Flexible hybrid work environment (onsite 2 days a week/3 days remote) at our Arlington (AOC1), TX office.

Please note: We are unable to provide any type of sponsorship for this position at this time.

The Manager of Identity & Access Management Engineering and Integration is responsible for leading the design, engineering, integration, and operational excellence of enterprise IAM platforms. This role ensures secure, scalable, and compliant identity services across Active Directory, SailPoint IdentityIQ (IQ), SailPoint Identity Security Cloud (ISC), Okta, CyberArk, and PKI Services, supporting on‑premises, cloud, and hybrid environments.

The manager leads a team of IAM engineers and analysts, serving as a tower lead for our managed service partner resources and works cross‑functionally with cybersecurity, infrastructure, application teams, and audit partners to deliver identity lifecycle automation, privileged access management, authentication services, and certificate services aligned with Zero Trust and least‑privilege principles.

IAM Platform Engineering & Integration

  • Lead engineering, configuration, and lifecycle management of IAM platforms including Active Directory, SailPoint (IIQ and ISC), Okta, CyberArk, and PKI Services
  • Oversee platform integrations with HR systems, ServiceNow, enterprise applications, cloud services, and third party vendors
  • Ensure resilient, highly available, and scalable IAM architectures across on prem and cloud environments
  • Establish reference architectures, integration patterns, and technical standards for IAM services

Active Directory

  • Provide technical and operational leadership for enterprise Active Directory services, including on premises and hybrid directory environments
  • Own AD architecture, design standards, and operational patterns, ensuring alignment with Zero Trust, least privilege, and identity centric security models
  • Oversee directory hygiene and lifecycle management, including user objects, service accounts, groups, and delegated administration models
  • Lead AD group and service account governance, ensuring alignment with SailPoint driven identity lifecycle (Joiner Mover Leaver) processes and access certifications
  • Partner with Identity Governance teams to ensure AD entitlements are authoritative, well modeled, and auditable within SailPoint
  • Ensure secure integration between Active Directory and Okta, including federation, authentication flows, and directory synchronization
  • Support and enhance privileged access controls for AD in coordination with CyberArk, including protection of domain level and Tier 0 privileged accounts
  • Lead AD remediation and risk reduction efforts, including cleanup of legacy groups, orphaned accounts, excessive permissions, and insecure configurations
  • Establish and maintain monitoring, alerting, and operational metrics for directory services availability, security posture, and access integrity
  • Act as the escalation point for directory related incidents, audits, and compliance inquiries, ensuring timely remediation and root cause resolution
  • Collaborate with Infrastructure, Endpoint, Cloud, and Security Architecture teams to ensure AD remains a foundational identity control plane for enterprise services

Identity Governance & Lifecycle Management

  • Own Joiner Mover Leaver (JML) automation, role based access control (RBAC), entitlement modeling, and access request workflows using SailPoint
  • Ensure consistent execution of access certifications
  • Partner with application owners and engineers to onboard applications into IAM governance and provisioning frameworks to ensure completeness and accuracy and entitlement metadata
  • Assist in testing of lower environments

Privileged Access & Authentication Services

  • Lead implementation and ongoing enhancement of CyberArk for privileged account management, credential vaulting, and session monitoring
  • Oversee Okta services including SSO, MFA, and API authentication for workforce and application access
  • Ensure authentication services meet enterprise security, user experience, and regulatory requirements

PKI & Certificate Services

  • Manage enterprise PKI services, including certificate issuance, automation, renewal, and lifecycle management
  • Ensure certificates are properly governed and integrated across applications, infrastructure, and security platforms
  • Support certificate compliance requirements across the enterprise

Security, Risk & Compliance

  • Ensure IAM controls meet regulatory and audit requirements (e.g., SOX, internal cybersecurity standards)
  • Support internal and external audits by providing evidence, walkthroughs, and remediation plans
  • Understanding of look back efforts
  • Proactively identify IAM risks and lead remediation of control gaps and vulnerabilities
  • Lead the engineering, maintenance, and modernization of IAM platforms
  • Identify mitigating controls to reduce risk
  • Ensure compliance with internal policies, audit requirements, and regulatory frameworks

Knowledge and Skills

  • Deep knowledge of Identity and Access Management technologies across Active Directory, PKI, SailPoint, Okta, CyberArk, and modern authentication standards
  • Strong understanding of identity governance frameworks, privileged access controls, certificate-based authentication, and directory services
  • Ability to architect and guide the implementation of secure, scalable IAM solutions
  • Experience leading complex engineering teams, including roadmapping, prioritization, and resource planning
  • Solid understanding of Zero Trust principles, identity security best practices, audit requirements, and regulatory controls
  • Ability to embed security-by-design into all IAM engineering processes
  • Demonstrated experience managing high-performing technical teams and developing engineering talent
  • Effective stakeholder communication and coordination across security, infrastructure, and application teams
  • Strong problem-solving skills and ability to lead incident response related to IAM platforms
  • Vendor relationship and contract management experience (particularly with SailPoint, Okta, CyberArk, and certificate authorities)
  • Hands on experience with Active Directory/Azure AD, SailPoint IdentityIQ & ISC, Okta (SSO, MFA), CyberArk (PAM), PKI/Certificate Services

Experience and Education

  • 5-7 years in Identity and Access Management or related experience at a medium-to-large company required
  • 3-5 years of experience in an IT leadership role preferred
  • High School Diploma or equivalent required
  • Bachelor’s Degree in related field or equivalent experience required

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.

Our Culture: Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.

Compensation: Competitive pay and bonus eligibility

Work Life Balance: Flexible hybrid work environment, 2-days a week in office

NOTE: We are unable to consider candidates who require visa sponsorship for this position

This position is not open to agency submissions

#GMFJobs #LI-Hybrid #LI-DW1

This is an external listing. JobSpring does not represent or verify the employer. Report this listing