Dir, Identity & Access Mgmt (IAM)
BHE Renewables
Director Of Identity & Access Management (Iam)
The Director of Identity & Access Management (IAM) is accountable for the delivery, effectiveness, and ongoing maturity of enterprise workforce identity, secrets, and certificate management platforms. This role ensures secure, reliable, and automated access to systems, applications, and collaboration tools across a hybrid cloud, multi affiliate environment.
Aligned to the Infrastructure & Operations Platform vision, this leader transforms legacy, fragmented and manual identity practices into standardized, policy driven, and automated enterprise services that reduce operational toil, improve resilience, and strengthen regulatory compliance. The role partners closely with Platform Engineering, Security, HR, and Application teams to ensure identity related capabilities are engineered as scalable, consumable, and reliable platforms.
This position drives both technical modernization and enterprise change, standardizing identity practices across historically decentralized affiliates while balancing local regulatory and operational needs.
Responsibilities
1. Enterprise IAM Strategy & Transformation
- Define and execute a multi‑year IAM modernization roadmap aligned with I&O Platform priorities for reliability, automation, toil reduction, and cost efficiency.
- Lead the transition from affiliate‑specific identity practices to a standardized enterprise workforce identity platform.
- Drive organizational and cultural change required to adopt consistent identity standards across decentralized affiliates.
- Establish workforce identity, secrets, and certificate services as foundational shared capabilities supporting enterprise operations and modernization initiatives.
2. Workforce Identity, Secrets & Certificate Platform Ownership
- Accountable for enterprise workforce identity services, including:
- Identity lifecycle management (Joiner / Mover / Leaver)
- Directory services (e.g., Entra ID, Active Directory)
- IAM services (Saviynt, SailPoint, MIM)
- Single Sign‑On (SSO) and Multi‑Factor Authentication (MFA)
- Privileged access management (PAM)
- Own enterprise secrets and certificate management platforms as they relate to workforce identity and shared enterprise services, including lifecycle management, rotation, availability, and monitoring.
- Establish enterprise standards and guardrails for secrets and certificate usage in partnership with Platform Engineering for workload and runtime use cases.
- Ensure HR‑driven identity is the authoritative source for workforce provisioning and de‑provisioning.
- Ensure platforms are engineered for high availability, disaster recovery, and operational continuity.
3. Engineering‑First Identity & Automation
- Drive API‑first and event‑driven identity architecture enabling integration with enterprise platforms and developer workflows.
- Promote infrastructure‑as‑code and policy‑as‑code approaches for identity, access, secrets, and certificates.
- Integrate IAM capabilities into CI/CD pipelines and application delivery processes where appropriate.
- Replace ticket‑driven operations with automated, self‑service workflows.
- Define and track metrics such as time‑to‑provision, automation coverage, and reduction in manual access handling.
4. Governance, Risk & Control Effectiveness
- Design and operate scalable identity governance capabilities including access certifications, role governance, and segregation‑of‑duties controls.
- Ensure IAM capabilities support SOX, NERC‑CIP, and other regulatory requirements.
- Accountable for the design, effectiveness, and continuous improvement of workforce identity access controls.
- Partner with Security and Internal Audit on control testing, regulatory examinations, and remediation activities.
5. Platform Operating Model & Affiliate Alignment
- Establish a centralized IAM platform with federated execution across affiliates.
- Align affiliates to enterprise identity, secrets, and certificate standards through policies, patterns, and approved configurations.
- Serve as the primary IAM point of integration for leadership, HR, and application owners.
6. Partnership with Platform Engineering
- Partner with Platform Engineering on shared identity architecture principles and integration standards.
- Clearly define and maintain ownership boundaries:
- IAM owns workforce identity and enterprise secrets/certificate platforms
- Platform Engineering owns workload and runtime identity
- Coordinate roadmaps and architectural decisions to prevent fragmentation.
7. Operational Resilience & Incident Support
- Participate in major incident response when identity‑related failures impact critical systems or restoration activities.
- Ensure incidents result in root‑cause analysis and durable platform improvements.
8. Team Leadership & Capability Development
- Lead and evolve an IAM organization currently consisting of engineers and administrators to support modern IAM and maturing platform capabilities.
- Shift team culture from operations‑centric execution to platform ownership and engineering excellence.
- Build skills in automation, integration, and modern workforce identity practices.
- Own IAM vendor relationships, budgets, and investment planning.
Qualifications
Experience
- Bachelor's degree in information systems, computer science or related technical field; or equivalent work experience.
- 10+ years in identity, security, or enterprise infrastructure
- 5+ years leading IAM, security, or platform teams in complex enterprises
- Proven success modernizing IAM in federated or multi‑entity organizations
- Experience in regulated or critical‑infrastructure environments preferred
Technical & Domain Expertise
- Workforce identity lifecycle management
- Cloud and hybrid directory platforms
- SSO, MFA, PAM, and access governance
- Secrets and certificate management platforms
- Identity integration patterns (APIs, SCIM, event‑driven architectures)
- Infrastructure‑as‑code and automation concepts
- Working knowledge of Zero Trust principles
Experience with modern IAM and access platforms such as Entra ID, SailPoint, Saviynt, CyberArk, HashiCorp Vault, or similar is preferred.
What Success Looks Like
Workforce identity, secrets, and certificates are engineered as reliable enterprise platforms rather than operational bottlenecks. Access is automated, resilient, auditable, and easy to consume. Affiliates operate on shared standards while maintaining regulatory accountability. IAM quietly enables secure operations, modernization, and enterprise delivery at scale.
Work Authorization/Sponsorship
At this time, we're not considering applicants that need any type of immigration sponsorship (additional work authorization or permanent work authorization) now or in the future to work in the United States. This includes, but IS NOT LIMITED TO: F1-OPT, F1-CPT, H-1B, TN, L-1, J-1, etc. For additional information around work authorization needs please use the following links.
Nonimmigrant Workers and Green Card for Employment-Based Immigrants
About Us
MidAmerican Energy Company, a Midwest utility, provides regulated electric and natural gas service to more than 1.6 million customers in Illinois, Iowa, Nebraska and South Dakota. The company owns and operates a portfolio of power-generating assets, approximately 61% of which is wind generation.
About the Team
MidAmerican Energy Company is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion or religious creed, age, national origin, ancestry, citizenship status (except as required by law), gender (including gender identity and expression), sex (including pregnancy), sexual orientation, genetic information, physical or mental disability, veteran or military status, familial or parental status, marital status or any other category protected by applicable local, state or U.S. federal law. Employees must be able to perform the essential functions of the position, with or without an accommodation.
- Ernst & Young Oman is looking for a Digital Identity & Authentication SME to enhance the user experience and implement robust identity solutions using technologies like Microsoft Entra, Okta, and Saviynt. With 6-8 years of relevant experience and a bachelor’s degree, candidates...SuggestedFlexible hours
- Smarsh is seeking a Software Engineer for the Professional Archive Identity & Access Management (IAM) team in Portland, Oregon. This position involves designing and building secure access systems, collaborating with cross-functional partners, and maintaining strong identity...SuggestedFlexible hours
- ...Junior Business Analyst - Identity and Access Management (IAM) Job Duties: Stakeholder Engagement: Collaborate with various stakeholders to understand their business processes and requirements. Schedule and conduct meetings with stakeholders to gather and review information...SuggestedWork experience placement
- An established industry player is seeking a skilled Identity Management Specialist to design and implement solutions using IBM ISVG tools. This role involves hands-on configuration, custom application integration, and the management of identity management processes. You...Suggested
- A technology solutions company in Portland, Oregon is seeking a professional responsible for access control management. The role requires collaboration with stakeholders to identify access needs, initiating provisioning actions, and executing deprovisioning for users changing...Suggested
- A technology solutions company located in Portland, Oregon, is looking for a professional to manage access provisioning and deprovisioning processes. Responsibilities will include collaborating with stakeholders to assess access needs, maintaining SailPoint workflows,...
- A tech solutions provider in Portland, Oregon, seeks an Access Control Manager to oversee access requirements and provisioning actions. The successful candidate will closely collaborate with stakeholders and maintain workflows in SailPoint ISC, ensuring accuracy and compliance...
- A technology company in Portland, Oregon seeks an access management specialist to handle provisioning and deprovisioning actions. The role involves collaboration with stakeholders to ensure accurate access rights aligned with functional roles. Proficiency in SailPoint...
- A tech solutions firm is seeking a professional for access management responsibilities. The role involves reviewing enablement matrices, collaborating with various stakeholders, and managing user access rights using tools like SailPoint ISC and Active Directory. This position...
- A technology services provider based in Portland, Oregon, is looking for a professional to manage access control processes and handle provisioning and deprovisioning tasks. The job involves reviewing access requirements, collaborating with stakeholders, and maintaining...
- ...Experience with hands-on solution design and deployment of IBM identity management tools. Setting up ISVG, configuration of LDAP,... ...solutions. Intermediate to advanced knowledge of multiple IAM domains including Access Management, Identity Management, Security Controls, and...
- Overview Key Responsibilities: Access Control Management. Responsibilities Review and understand the organization's predefined enablement... ...to race, color, religion, sex, sexual orientation, gender identity, age, disability, national origin, citizenship/immigration status...Permanent employmentContract workLocal area
- Key Responsibilities - Access Control Management Review and understand the organization's predefined enablement matrix by functional... ...regard to race, color, religion, sex, sexual orientation, gender identity, age, disability, national origin, citizenship/immigration...Permanent employmentContract workLocal area
$120k - $135k
As a Software Engineer on the Professional Archive Identity & Access Management (IAM) team, you’ll design and build systems that ensure secure, reliable access to our platform. This is a new and growing team focused on protecting users, services, and data through modern...Work at officeLocal areaFlexible hours$375.96k
...program growth and new program development to enhance patient access. Work with senior leadership on all matters related to collective... ...or creed, citizenship status, sex, sexual orientation, gender identity, pregnancy, age, national origin, disability status, genetic...Contract workH1b$140k - $175k
...changes while taking responsibility for continuous personal skill development and technical growth.The expected hiring range for an **IAM Security Architect** is $140K - $175K/year depending on skills, experience, education, and training; relevant licensure /...Immediate start- Manage the overall day‑to‑day operations of the store's e‑Commerce department to achieve desired sales objectives, goals and budgets. Responsible for staffing the department and developing associates to achieve desired results. Demonstrate the company's core values of respect...Hourly payWork at officeLocal area
$92.82k - $109.2k
...consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law. Applicants must comply with U.S. Bank policies and...Temporary workWork experience placement- ...Improve referral workflows and conversion rates Analyze and act on access KPI’s (new patient lag, template utilization, referral... ...religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic...Shift work
$41.57 per hour
Union Pacific Railroad is hiring a Work Equipment Mechanic for our Engineering department in Portland, OR. In this role, you will maintain tools and equipment essential for our operations. The ideal candidate should have at least 4 years of experience as a mechanic and ...$140k - $175k
A leading health care solutions company in Portland, Oregon is hiring an IAM Security Architect to provide organization-wide technical leadership in information security. The role offers a competitive salary ranging from $140K to $175K annually, determined by experience...- Responsible for assisting with the overall day‑to‑day operations of the store including continuous development of effective store associates to achieve desired sales and profit results. Assess daily the stores' ability to meet/exceed customer expectations for ease of shopping...Local area
- ...Head of Data Science & AI, Identity & Compliance About the Company Leading provider of financial technology (FinTech) solutions Industry Information Technology and Services Type Privately Held About the Role The Company is in search of a Head of...
$104.8k - $192.2k
...cybersecurity risks and regulatory pressures. Identity—both human and non-human—is at the core... ...and perform capability maturity Develop IAM strategy and roadmaps, including... ...development of RBAC models, workflows, and access certification campaigns Onboard applications...Work experience placementSummer holidayFlexible hours$10k
...Patient Access Specialist At The Portland Clinic our mission is to be a trusted community collaborating to improve the health and... ...Disability, Critical Illness, Accident, and Hospital Indemnity Norton Identity Theft Protection (optional) Pet Insurance (optional) 4.92 hours...Temporary workMonday to FridayFlexible hoursShift work$144.9k - $265.8k
Digital Identity & Authentication SME (Microsoft Entra, Okta, Ping, Saviynt) Overview In today... ...Conduct current state and application access assessments Perform capability maturity and benchmarking assessments Analyze IAM data and provide actionable insights Develop...Work experience placementSummer holidayFlexible hours$104.8k - $192.2k
Location: Anywhere in Country Digital Identity SME - Senior (Microsoft Entra, Saviynt) Overview... ...and perform capability maturity Develop IAM strategy and roadmaps, including... ...development of RBAC models, workflows, and access certification campaigns. Onboard applications...Work experience placementSummer holidayFlexible hours$10k
...Patient Access Coordinator At The Portland Clinic our mission is to be a trusted community collaborating to improve the health and... ...Critical Illness, Accident, and Hospital Indemnity ~ Norton Identity Theft Protection (optional) ~ Pet Insurance (optional) ~4.92...Temporary workMonday to FridayFlexible hours$104.8k - $192.2k
A leading professional services firm seeks a Digital Identity SME to enhance user experience and increase operational efficiency through identity solutions. This role requires hands-on experience with Microsoft Entra and Saviynt, understanding of identity lifecycle management...Flexible hours$90k - $100k
Jobot is looking for an experienced IT Financial Analyst to manage IT budgets and oversee vendor relationships in Portland, Oregon. With a salary range of $90,000 to $100,000, plus a monthly bonus, this full-time, hybrid role requires at least 7 years of experience in finance...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Dir, Identity & Access Mgmt (IAM). Be the first to apply!
