Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

AVP IAM & Governance

$244k - $270k

Jobleads-US

Our Mission

Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.

Overview

How You Can Make a Difference

The AVP, Identity & Access Management, the enterprise authority on identity — the architect, evangelist, and operational owner of an identity-first security model in which identity is the control plane for a cloud-first, zero trust enterprise.

This leader defines and executes a multi-year B2E IAM strategy spanning identity governance and administration (IGA), privileged access management (PAM), customer and workforce access management, non-human/machine identity, and identity threat detection and response (ITDR), and is accountable for the engineering rigor, control effectiveness, and audit posture of the entire identity fabric.

This is a role for a practitioner-leader and recognized thought leader: someone who has designed and operated identity programs at scale, who is fluent in modern identity standards and protocols (OAuth 2.0, OIDC, SAML 2.0, SCIM, FIDO2/WebAuthn), who can whiteboard an authorization model one hour and defend a control posture to auditors and executives the next, and who actively shapes the direction of the identity discipline — inside the organization and in the broader industry — through published points of view, standards engagement, and community leadership.

What You’ll be Doing

  • Identity Strategy & Thought Leadership:
    • Own and evangelize a multi-year AI led identity strategy and reference architecture that treats identity as the primary security perimeter, aligned to zero trust principles (NIST SP 800-207) and enterprise business objectives.
    • Serve as the organization's most senior voice on identity: publish internal position papers and architectural decision records, brief executive leadership and the Board on identity risk, and represent the company externally through industry forums, standards bodies, conference speaking, and peer communities.
    • Anticipate and translate emerging shifts — decentralized identity, verifiable credentials, passwordless/phishing-resistant authentication, AI-agent and workload identity, continuous access evaluation (CAEP/Shared Signals) — into pragmatic roadmap decisions with clear build/buy/retire rationale.
  • Organizational Leadership:
    • Build, lead, and mentor a high-performing team of IAM architects, engineers, and analysts; establish engineering career paths, on‑call/operational maturity, and a culture of automation‑first identity operations.
    • Operate identity as a product: define OKRs and SLOs for identity services (provisioning latency, certification completion, authentication availability, orphaned‑account rates), and manage a prioritized backlog with IT, HR, Legal, Compliance, and business‑line stakeholders.
  • Identity Governance & Administration (IGA):
    • Architect and operate the full identity lifecycle — joiner/mover/leaver (JML) automation driven by authoritative HR sources, birthright provisioning, SCIM‑based downstream integration, and deprovisioning SLAs measured in minutes to hours.
    • Design and mature the enterprise access model using Agentic AI capabilities: role engineering and role mining, RBAC evolving toward attribute‑and‑policy‑based access control (ABAC/PBAC), segregation‑of‑duties (SoD) rulesets, and risk‑based, evidence‑quality access certifications that eliminate rubber‑stamping.
    • Own governance of entitlement sprawl across SaaS, IaaS, and on‑prem estates, including cloud infrastructure entitlement management (CIEM) and least‑privilege enforcement in AWS/Azure environments.
  • Authentication, Authorization & Directory Architecture:
    • Set the enterprise standard for authentication: phishing‑resistant MFA (FIDO2/WebAuthn), passwordless adoption, adaptive/risk‑based authentication, and session management policies calibrated to data sensitivity.
    • Own federation and SSO architecture (SAML 2.0, OIDC/OAuth 2.0), token security and lifetime strategy, and conditional access policy design across the enterprise application portfolio.
    • Govern directory and identity‑store architecture — Entra ID and Active Directory hardening (tiered administration, attack‑path reduction), hybrid identity synchronization, and rationalization of legacy identity repositories.
    • Advance externalized, policy‑as‑code authorization patterns (e.g., OPA/Rego, Cedar) for fine‑grained, auditable access decisions in modern applications.
  • Privileged Access & Non‑Human Identity:
    • Own the privileged access management program: credential vaulting, session isolation and recording, just‑in‑time/zero‑standing‑privilege elevation, and break‑glass governance.
    • Establish lifecycle governance for non‑human identities — service accounts, API keys, certificates, workload identities, and emerging AI‑agent identities — including inventory, ownership attestation, secrets management, and automated rotation.
  • IAM Platform Engineering & Operations:
    • Lead evaluation, selection, and engineering of the IAM technology stack — IGA, access management/IdP, PAM, CIEM, and ITDR platforms — with a bias toward API‑first integration, infrastructure‑as‑code deployment, and CI/CD‑managed identity configuration.
    • Ensure availability, resilience, and disaster recovery of identity services as tier‑zero infrastructure; identity outages are business outages.
    • Instrument the identity fabric end to end: stream identity telemetry to SIEM, define detections for identity‑centric attack techniques (credential stuffing, token theft, MFA fatigue, golden ticket/SAML forging, privilege escalation), and partner with the SOC on ITDR playbooks.
  • Risk, Compliance & Assurance:
    • Own identity‑related control design and operating effectiveness for HIPAA Security Rule safeguards, HITRUST CSF, SOC 1/SOC 2, SOX ITGCs, and applicable state privacy regimes; serve as primary identity interface for internal audit, external auditors, and regulators.
    • Run a continuous identity risk program: access‑risk scoring, toxic‑combination detection, periodic attack‑path and privilege‑escalation reviews, and identity‑specific tabletop exercises.
    • Develop and maintain incident response plans for identity compromise scenarios and lead identity workstreams during security incidents.

What You’ll Need to be Successful

Education and Experience

  • Bachelor's degree in Computer Science, Cybersecurity, or a related discipline, or equivalent work experience. Master's degree preferred.
  • 12–15+ years of progressive information security experience, with at least 5 years leading IAM teams and programs at enterprise scale.
  • Demonstrated track record of architecting and delivering at least one major identity transformation end to end (e.g., IGA platform implementation, workforce IdP migration, PAM program build‑out, or zero trust identity modernization).

Specialized Knowledge, Skills, and Abilities

  • Deep, hands‑on‑credible expertise across the identity domain: IGA, access management, PAM, CIEM, ITDR, directory services, and non‑human identity.
  • Fluency in identity standards and protocols — OAuth 2.0, OIDC, SAML 2.0, SCIM, LDAP/Kerberos, FIDO2/WebAuthn — and the architectural trade‑offs among them.
  • Enterprise experience with leading IAM platforms (e.g., SailPoint, Saviynt, Okta, Microsoft Entra, Ping Identity, CyberArk, Delinea or comparable) and with integrating identity into SIEM/SOAR ecosystems.
  • Working knowledge of zero trust architecture (NIST SP 800-207), NIST SP 800-63 digital identity guidelines, and least‑privilege design in cloud environments (AWS IAM, Azure RBAC/Entra).
  • Strong command of identity‑relevant regulatory and assurance frameworks — HIPAA, HITRUST, SOC 2, SOX ITGCs — and experience defending control design to auditors.
  • Evidence of thought leadership: published writing, conference talks, standards or working‑group participation, patents, open‑source contribution, or recognized community leadership in the identity space.
  • Executive‑caliber communication — able to translate deep technical architecture into board‑level risk narratives — paired with strong leadership, mentorship, and team‑building skills.

Certifications, Licenses, Registrations

  • Relevant industry certifications strongly preferred — e.g., CISSP, CISM, CISA, CIDPRO, or vendor‑specific identity certifications (SailPoint, Okta, Microsoft, CyberArk).

Travel Requirements

  • Occasional travel to attend training, industry conferences, or meetings may be required.

This is a remote position.

Salary Range

$244000.00 To $270000.00 / year

Benefits & Perks

The actual compensation offer is determined based on job‑related knowledge, education, skills, experience, and work location. This position will be eligible for performance‑based incentives and restricted stock units as part of the total compensation package, in addition to a full range of benefits including:

  • Medical, dental, and vision
  • HSA contribution and match
  • Dependent care FSA match
  • Uncapped paid time off
  • Paid parental leave
  • 401(k) match
  • Personal and healthcare financial literacy programs
  • Ongoing education& tuition assistance
  • Gym and fitness reimbursement
  • Wellness program incentives

Onboarding & Travel

This is a remote role, with an in‑person onboarding training component. New team members must participate in Trailhead , HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.

This role may begin with a virtual, self‑paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.

HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.

HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt‑out request from you, we will assume that you consent to the use of Microsoft Copilot.

At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.

As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills. For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.

HealthEquity is committed to your privacy as an applicant for employment. For information on our privacy policies and practices, please visitHealthEquity Privacy.

#J-18808-Ljbffr Jobleads-US
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the AVP IAM & Governance in Kentucky vacancy
  • $244k - $270k

     ...remarkable. Overview How You Can Make a Difference The AVP, Identity & Access Management, the enterprise authority...  .... This leader defines and executes a multi-year B2E IAM strategy spanning identity governance and administration (IGA), privileged access management (... 
    Suggested
    Work experience placement
    Remote work
    Shift work

    HealthEquity, Inc.

    Kentucky
    2 days ago
  •  ...day interactions with our patients and teammates.Job SummaryThe AVP, Information Security leads the enterprise information security...  ...and access management, HIPAA security compliance, and data governance. This role advises executive leadership during security events,... 
    Suggested

    Cornerstone Healthcare Group Holding

    Louisville, KY
    2 days ago
  •  ...seeking a Senior Product Manager for IdentityApply in the US to lead the IAM platform strategy. You will work with security, engineering, and business partners to define features, align with governance, and drive secure, scalable identity solutions for enterprise users.... 
    Suggested
    Remote job

    Jobleads-US

    Kentucky
    2 days ago
  •  ...HealthEquity, Inc. is seeking an AVP Identity & Access Management to architect and lead a comprehensive identity program across IGA,...  ...travel as needed. Deep expertise in modern identity standards and enterprise IAM platforms is essential. #J-18808-Ljbffr Jobleads-US
    Suggested
    Remote work

    Jobleads-US

    Kentucky
    2 days ago
  • Wonder is hiring an Identity Governance Engineer in New York, NY. The role focuses on identity governance, Okta administration in production, and supporting SOX ITGC audits. You will manage lifecycle processes, SAML/OIDC integrations, and access reviews while documenting... 
    Suggested

    Blue Apron

    Eastern, KY
    4 days ago
  •  ...C1 is the modern identity governance platform that makes it possible to move beyond the limitations of legacy IGA and reduce the identity...  .... Architect and deliver technical solutions spanning IGA, IAM, CIEM, and PAM, mapping business requirements into scalable identity... 

    C-1 Inc

    Eastern, KY
    4 days ago
  •  ...Develop and own the enterprise data governance framework, including policies, standards, metadata strategy, and data stewardship processes...  ...AWS data services (e.g., S3, Glue, Lake Formation, Redshift, IAM). ~ Experience with data governance workflows, tooling, and model... 
    Permanent employment
    Contract work
    Local area

    Quantum Technologies USA

    Eastern, KY
    4 days ago
  •  ...eliminate the complexities and time-consuming processes often required to govern identities, manage privileged accounts and control access. Our solutions enhance business agility while addressing IAM challenges within on-premises, cloud and hybrid environments. The... 
    Contract work

    One Identity

    Eastern, KY
    3 days ago
  • $104.8k - $192.2k

     ...technical delivery across identity modernization, authentication, governance and security posture improvement programs. This role is a fit...  ..., NIST or CIS-aligned security controls, or adjacent IAM platforms such as SailPoint, Saviynt or CyberArk. Microsoft identity... 
    Summer holiday
    Flexible hours

    EY

    Frankfort, KY
    5 days ago
  • $213.1k - $245k

    Company Overview Joby Flight Research designs, develops, and flight-tests novel aircraft using a software-first autonomy approach. We build and deploy autonomy, perception, planning, and radar systems across conventional, electric, and hydrogen-electric aircraft in ...
    Permanent employment
    Temporary work
    Remote work

    Joby Aviation

    Eastern, KY
    2 days ago
  • $250k - $375k

     ...Full-Time, Salaried/Exempt Position Summary: The COO is responsible for managing the daily operations of an independent, self-governing non-profit district hospital, aligning healthcare delivery with the hospital’s community focused mission. Will carry out responsibilities... 
    Full time
    Local area

    Watsonvillehospital

    Kentucky
    1 day ago
  • ## Vice President and Chief Operations OfficerApply: Frick PA Region: Full time: Posted Today: JR26-45634## Welcome! We’re excited you’re considering an opportunity with us! To apply to this position and be considered, click the Apply button located above this message and...
    Full time
    Work at office
    Immediate start
    Shift work

    WVU Medicine

    Kentucky
    4 days ago
  •  ...End Date: October 26, 2026 (24 days left to apply): JR0131247**Vice President, Financial & Regulatory Reporting, Consolidations & Governance****Location: Atlanta GA**We are seeking a strategic and experienced finance executive to lead our SEC reporting, regulatory... 
    Full time
    Temporary work
    Work at office
    3 days per week

    The Western Union Company

    Kentucky
    1 day ago
  •  ...Platform that services some of the largest global enterprises and government agencies. Our platform currently reduces manual work by up to 9...  ...~ Cloud Expertise: Expertise with AWS (e.g., EC2, ECS, S3, IAM, Lambda, CloudWatch). ~ Infrastructure as Code: Expertise... 
    Remote work
    Visa sponsorship

    Akkadian Labs

    Eastern, KY
    4 days ago
  • Overview The Chief Operating Officer (COO), in dyad partnership with the hospital's Chief Nursing Officer (CNO), is responsible and accountable for the safe and effective day-to-day operation of the assigned hospital. The COO has direct responsibility for overseeing...
    Local area

    Appalachian Regional Healthcare

    South Williamson, KY
    1 day ago
  •  ...colleges and campuses Maintain and strengthen Ohio University’s standing as an R1 research institution Faculty Leadership and Shared Governance Partner effectively within a unionized faculty environment, respecting collective bargaining agreements and established... 
    Full time
    Work at office
    Weekend work
    Afternoon shift

    Ohio Ag

    Eastern, KY
    5 days ago
  • Yugo is a global student living brand creating communities where students can settle in, connect and thrive. With a growing U.S. portfolio and a global network spanning markets around the world, we combine global experience with strong local leadership to deliver exceptional...
    Local area

    Yugo USA LLC.

    Eastern, KY
    2 days ago
  •  ...families, faculty and staff, and with members of the Greater Cincinnati community. Partners with the Board of Directors to implement governance and school policies; hires, leads, and holds accountable the executive leadership team while serving as President of both the... 
    Work at office

    Gilman Partners

    Crestview Hills, KY
    1 day ago
  •  ...translate strategic objectives into practical operational plans Strong understanding of risk management, compliance and corporate governance Experience within construction, engineering, industrial flooring or a related specialist sector would be highly advantageous... 
    Local area
    Relocation

    Twintec Group

    Kentucky
    3 days ago
  •  ...innovations that improve organizational performance.* Serve as a member of the senior leadership team and contribute to enterprise governance and decision making.* Create an environment that attracts, develops, and retains exceptional talent.* Build a high-performing... 
    Full time
    Work at office

    University of Texas

    Kentucky
    3 days ago
  • The Opportunity As the North Slope Chief Pilot, you’ll supervise a team of slope‑based pilots, set the operational tone, and fly as PIC on at least one of our North Slope turboprop types. You’ll be the single point of contact for aviation matters on the slope—partnering...
    Local area
    Remote work

    Pilot Assessments

    Kentucky
    1 day ago
  •  ...organization activities and operations are carried out in compliance with local, state and federal regulations, HFAP standards and laws governing healthcare operations. #*Maintains an environment of collaboration and cooperation among hospital departments. #*Maintains... 
    Temporary work
    Local area
    Flexible hours

    Bryan College Of Health Sciences

    Kentucky
    3 days ago
  •  ...Partnerships Support the organization's mission through active engagement with community partners, healthcare organizations, government agencies, and stakeholders. Represent the health center in external meetings, professional organizations, community events,... 
    Full time
    Temporary work
    Flexible hours

    Peoples Health Centers Inc

    Kentucky
    2 days ago
  •  ...strengthen relationships with clients, partners and key stakeholders. Ensure regulatory compliance and effective corporate governance. Lead organisational development, recruitment and talent management. Candidate Requirements Fluent Arabic speaker... 

    Uniglo Financial Limited

    Kentucky
    2 days ago
  •  ...will be subject to a criminal record identification check pursuant to ORS 181.536.727.537 and agency policy. We are an Equal Opportunity Employer and Service Provider and support culturally linguistically diverse governance, leadership, and workforce. #J-18808-Ljbffr... 
    Ongoing contract
    Full time

    Trillium Family Services

    Eastern, KY
    2 days ago
  • The McDonnel Group is seeking an experienced Chief Operating Officer to provide strategic leadership across our Operations—including Field Operations and Project Management—as well as our Preconstruction and Estimating teams. This executive will drive operational excellence...

    The McDonnel Group

    Eastern, KY
    2 days ago
  • $180k - $210k

     ...leaders. We believe meaningful, lasting political change starts not in Washington, but at state and local levels, where most actual government decisions and spending occurs. About the Opportunity This role will be the second-in-command for a well-known national grassroots... 
    Work at office
    Local area
    Remote work

    Liberty Seeds

    Eastern, KY
    4 days ago
  • $174.25k - $205k

     ...and compliance—while maintaining enterprise‑grade control and governance. Jasper is trusted by hundreds of enterprises worldwide, including...  ...Strong working knowledge of GCP and AWS security services and IAM models Experience with GitHub security controls (branch... 
    Local area
    Remote work
    Worldwide
    Home office
    Flexible hours
    Shift work

    AI Chopping Block

    Eastern, KY
    4 days ago
  • If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Full Time Senior Management Cloverleaf OP, KS, Overland Park, KS, US 7 days ago Requisition ID: 9576 Executive Vice...
    Full time
    Night shift

    St. Louis Children’s and KVC Health Systems

    Eastern, KY
    2 days ago
  • Job Description Job Description CEO position coming soon in the Central Kentucky Area   Must have knowledge of industry regulations on the federal level  

    MRINetwork Jobs

    Richmond, KY
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to AVP IAM & Governance. Be the first to apply!