Manager, Identity and Access Management
@ NorthMark Compute and Cloud LLCManager, Identity and Access Management
About the job
NorthMark Compute & Cloud (NMC²) builds HPC and cloud infrastructure for research and innovation. The IAM Manager leads identity teams, sets strategy, and advances zero trust for enterprise and workload identities in a cutting-edge environment.
Requirements
- 6+ years in IAM or security engineering
- 2–3+ years leading IAM teams
- Expertise in Microsoft Entra ID
- Experience with SPIFFE/SPIRE frameworks
- Strong PKI knowledge
Qualifications
- Bachelor's degree in related field
- Leadership and team development skills
- Strong communication skills
- Experience with zero trust architecture
Full job description
The Company
NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.
The Position
The Identity and Access Management (IAM) team sits within NMC²’s Security organization and is building the identity control plane for a new generation of HPC, cloud, and distributed infrastructure. The team’s mission spans workforce and tenant identity, privileged access, workload identity, public key infrastructure (PKI), secrets access, and cloud federation. Its work makes secure access possible without placing an external identity provider on the critical path of the platform.
As the Engineering Manager, Identity and Access Management, you will turn a broad identity architecture into an executable, phased roadmap and build the team that delivers it. Near-term priorities include maturing Microsoft Entra ID as the governed identity hub, automating joiner, mover, and leaver workflows, implementing phishing-resistant authentication and access governance, and establishing resilient privileged-access controls. You will also guide the evolution of workload identity, certificate lifecycle management, service-to-service trust, token exchange, and multi-cloud federation in partnership with Platform Engineering and Infrastructure teams.
This is an opportunity to shape a foundational security capability while the platform is still being built. You will have meaningful influence over architecture, team design, engineering standards, and the operating model, with the mandate to replace standing privilege and long-lived credentials with automated, observable, and resilient identity controls.
Responsibilities
Recruit, lead, and develop a team of IAM engineers, establishing clear ownership, sustainable on-call practices, and growth plans that build both enterprise and machine-identity capability.
Own the IAM strategy, phased roadmap, and delivery outcomes across workforce, privileged, workload, and federated identity, sequencing research, proofs of concept, production implementation, and hardening work around explicit dependencies and risks.
Lead the workforce identity program across Microsoft Entra ID and connected systems, including identity lifecycle automation, Conditional Access, phishing-resistant authentication, role and entitlement design, separation of duties, Privileged Identity Management, and access recertification.
Set technical direction for workload and service identity, PKI, certificate lifecycle management, and mutual TLS, partnering with platform teams to establish scalable trust patterns for Kubernetes, bare-metal, network, and cloud environments.
Establish a Zero Standing Privilege operating model for administrative access, including just-in-time elevation, approval controls, recorded sessions, break-glass paths, and periodic validation of privileged-access boundaries.
Guide identity federation and token-service design across tenants and cloud platforms, ensuring issuer trust, claims, token lifetimes, key rotation, local validation, and revocation are secure, interoperable, and resilient.
Make identity infrastructure reviewable and repeatable through declarative configuration, GitOps workflows, automated testing, drift detection, and evidence-producing controls rather than manual console changes.
Define and track service outcomes for availability, provisioning and revocation time, certificate and key rotation, policy convergence, audit coverage, and recovery readiness; ensure runbooks and failure-mode exercises validate those outcomes.
Partner with Platform Engineering, Cloud, Network, Security Operations, Governance, Risk and Compliance, and external service owners to define clear boundaries, resolve cross-team dependencies, and embed identity controls into platform delivery.
Translate architecture trade-offs, operational risk, investment needs, and program progress into clear decisions and measurable reporting for technical and executive stakeholders.
Requirements
6+ years of experience in identity and access management, security engineering, platform security, or a closely related field, including ownership of production identity capabilities.
2+ years of people-management or formal engineering-leadership experience, with evidence of hiring, developing, and retaining engineers and improving team delivery.
Deep expertise in at least one major identity domain, such as workforce IAM, identity governance, privileged access, workload identity, PKI, or cloud federation, with working knowledge of the adjacent domains.
Strong experience with Microsoft Entra ID or a comparable enterprise identity platform, including authentication policy, lifecycle management, federation, privileged access, or access governance.
Experience setting a technical roadmap, prioritizing across competing risks and dependencies, and moving identity capabilities from design or proof of concept into reliable production operation.
Practical understanding of modern identity and federation standards such as OAuth 2.0, OpenID Connect, SAML, SCIM, X.509, and mutual TLS, with the judgment to apply them securely in distributed systems.
Experience using automation, infrastructure as code, APIs, or Git-based delivery practices to manage security or identity configuration at scale.
Demonstrated operational judgment in areas such as incident response, break-glass access, key or credential rotation, disaster recovery, monitoring, and control validation.
Ability to communicate complex technical decisions and risks clearly, influence partner teams without direct authority, and create alignment among engineering, security, compliance, and leadership stakeholders.
Preferred
Experience with SPIFFE/SPIRE, Kubernetes workload identity, service meshes, or other patterns for issuing short-lived workload credentials.
Experience designing or operating PKI and certificate lifecycle platforms, including step-ca, hardware security modules, ACME, trust-bundle distribution, or certificate revocation.
Familiarity with privileged-access and secrets platforms such as Teleport, HashiCorp Vault, or equivalent technologies.
Experience with identity federation across Azure, AWS, or Google Cloud, including workload identity federation, IAM Identity Center, attribute-based access control, or token exchange.
Background in HPC, multi-tenant platforms, regulated environments, or systems designed to continue operating through cloud or internet outages.
Relevant certifications such as CISSP, CISM, Microsoft Certified: Identity and Access Administrator, or equivalent practical experience.
It is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company’s needs may change over time. Therefore, the above job description is not comprehensive or exhaustive. The Company reserves the right to adjust, add to or eliminate any aspect of the above description. The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Benefits & Perks:
Company-Paid Lunch Stipend: Lunch is provided via GrubHub
Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability
401(k): Company will match 100% of your contributions up to 6%
Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
Time Off: 25 days of Paid Time Off plus 12 company holidays
EQUAL OPPORTUNITY EMPLOYER
NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW. THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.