Job Title: Identity and Access Management Leader
Berwyn, PA, US, 19312
AMETEK is building out its identity and access management capability and is hiring a founding Identity and Access Management Leader to lead this effort. Reporting to the Director of Enterprise Operations and Architecture, the leader will help establish identity as a central role in advancing foundational control for AMETEK’s Zero Trust strategy by making identity the primary control point for secure access, with, ensuring access decisions informed are continuously evaluated based on user, device, application, data sensitivity, location, and risk context. This is a hands-on, senior-level role for someone with deep expertise in Active Directory, Microsoft Entra ID, and single sign-on, who can both set the strategic direction for identity management and work directly in the environment to implement it. The role will evaluate, select, and implement a modern IAM platform, and will partner closely with our Enterprise Architecture function on broader technology alignment.
Key Responsibilities:
- Evaluate AMETEK's current identity and access management practices and develop a roadmap for maturing the program, including near-term improvements and a longer-term target architecture.
- Lead the requirements definition, vendor evaluation, and selection process for a modern IAM platform.
- Define and advance AMETEK’s identity-centric Zero Trust architecture for AMETEK, with emphasis on, including least privilege access, conditional access, continuous verification, and risk-based authentication.
- Partner with Security Architecture, Network, Endpoint, Cloud, and Enterprise Architecture teams to align identity controls IAM, device posture, segmentation, application access, segmentation, and data protection controls under a Zero Trust operating model.
- Develop policies and maintain standards for adaptive access, privileged access, service accounts, machine identities, third-party access, and other non-human identity use cases.
- Integrate IAM controls with endpoint security, security monitoring, vulnerability management, and incident response processes to improve visibility, and enforcement, and response across the environment.
- Establish measurable Zero Trust maturity measures, goals and metrics, such as MFA coverage, conditional access adoption, privileged access reduction, stale account remediation, access review completion, and response to high-risk sign-in response.
- Design and implement the target-state identity lifecycle architecture, covering onboarding, role changes, and offboarding across the employee lifecycle.
- Serve as the subject matter expert for Active Directory and Microsoft Entra ID, including hybrid identity, conditional access, and directory synchronization.
- Own and continuously improve single sign-on architecture across SAML, OIDC, and OAuth 2.0, integrating enterprise and divisional applications.
- Establish access certification, role-based access control, and privileged access management practices as the program matures.
- Partner with Enterprise Architecture, HR systems, and Corporate Technology Services on integration standards and cross-domain alignment.
- Support the identity and access components of merger and acquisition integrations as AMETEK continues to grow.
- Coordinate with security, compliance, and internal audit on access control requirements relevant to AMETEK's regulated business environments.
- Be a hands-on contributor in the environment day to day, particularly during the program's early stages, not solely an advisory or architectural resource.
- Build and lead AMETEK's Identity and Access Management team, including defining the team structure, hiring, and developing team members as the function grows.
Required Qualifications:
- Eight or more years of progressive experience in identity and access management, including experience building or significantly maturing an IAM function.
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field is required; equivalent professional experience will be considered in lieu of a degree
- Master's degree in a related field is preferred.
- Deep, hands-on expertise with Active Directory and Microsoft Entra ID, including hybrid join, conditional access, and directory synchronization tools such as Entra Connect.
- Practical experience designing or implementing Zero Trust identity controls, including least privilege, conditional access, MFA, privileged access management, device compliance-based access, and risk-based access policies.
- Strong understanding of modern identity security patterns across workforce, privileged, third-party, service account, and machine identity use cases.
- Proven experience designing and implementing single sign-on using SAML, OIDC, and OAuth 2.0 across a multi-application enterprise environment.
- Direct experience with at least one enterprise IAM or identity governance platform selection and implementation, from requirements through go-live.
- Experience assessing an existing identity environment and improving its security posture as part of a broader modernization effort.
- Strong scripting and automation background (PowerShell, Python, or similar).
- Experience integrating human resources systems of record with downstream identity provisioning processes.
- Working knowledge of role-based access control, access certification, and privileged access management concepts.
- Demonstrated willingness to work hands-on in the environment day to day, particularly in the first six to twelve months.
- Strong written and verbal communication skills, with the ability to explain identity architecture decisions to both technical staff and business stakeholders.
- Proven people leadership experience, including hiring, developing, and managing a technical team, ideally having built a team or function from an early stage.
- Demonstrated ability and willingness to use AI tools to improve productivity, decision-marking, work quality, and to reduce costs. The successful candidate must be able to identify appropriate AI use cases and critically evaluate AI-generated outputs
Preferred Qualifications:
- Experience in a large, decentralized, multi-division manufacturing or industrial company with an active mergers and acquisitions history.
- Familiarity with regulated-environment access control frameworks such as CMMC, ITAR, or NIST 800-171.
- Relevant certifications such as Microsoft Identity and Access Administrator (SC-300), or vendor certifications from SailPoint, Saviynt, or Okta.
- Experience standing up or maturing an identity governance program.
#LI-BM1
Nearest Major Market: Philadelphia