At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
EY – Cybersecurity Manager, Identity & Access Management (IAM)
Overview
As Manager in EY’s Cybersecurity practice, you will play a key role in delivering Identity and Access Management (IAM) services across multiple client environments. We are seeking cybersecurity professionals with expertise in Identity Governance and Administration (IGA), Access Management (AM), and Privileged Access Management (PAM) such as Microsoft Entra ID, IBM Security Verify Governance, IBM Security Verify Access, Delinea Secret Server, SailPoint Identity or other leading IAM technologies.
The role involves implementing, administering, and optimizing IAM solutions that enable secure user access, enforce governance controls, manage privileged accounts, and support regulatory compliance across IT and Operational Technology (OT) environments.
The Opportunity
We are seeking cybersecurity professionals with 12+ years of experience in Identity and Access Management, Identity Governance, Access Management, Privileged Access Management, or Cybersecurity Consulting.
The ideal candidate will possess strong technical expertise in identity lifecycle management, role-based access controls, authentication and authorization mechanisms, privileged account governance, and IAM operational processes.
Key Responsibilities
Identity Governance & Administration
- Implement and administer IGA solutions such as Microsoft Entra ID, Saviynt, IBM, SailPoint Identity and Oracle Identity Governance.
- Configure identity lifecycle management processes, including joiner, mover, and leaver workflows.
- Manage user provisioning, deprovisioning, role management, and access certification campaigns.
- Design and maintain role-based access control (RBAC) models.
- Support Segregation of Duties (SoD) analysis and policy enforcement.
- Perform access reviews, user entitlement analysis, and compliance reporting.
- Integrate governance workflows with enterprise applications and directories.
- Support audit and regulatory compliance requirements.
Access Management & Federation
- Deploy and administer access management platforms such as IBM Security Verify Access, Microsoft Entra ID, Okta or Ping Identity.
- Configure authentication and authorization policies for enterprise applications.
- Implement Single Sign-On (SSO), Multi-Factor Authentication (MFA), and adaptive access controls.
- Support federation technologies including SAML, OAuth 2.0, OpenID Connect, and WS-Federation.
- Integrate applications with centralized authentication platforms.
- Troubleshoot authentication, authorization, and federation-related issues.
- Support secure remote access and external identity integrations.
- Participate in access management modernization and transformation initiatives.
Privileged Access Management
- Administer Delinea Secret Server platforms for privileged credential management.
- Manage privileged account onboarding, credential vaulting, and password rotation.
- Configure privileged session management and privileged access workflows.
- Support discovery and onboarding of privileged accounts across servers, databases, applications, and network devices.
- Implement least-privilege principles and privileged-access governance controls.
- Monitor privileged account activities and support audit requirements.
- Assist in remediation of privileged-access risks and compliance findings.
- Support PAM integrations with enterprise identity systems.
OT Privileged Access Management
- Support PAM implementation across Operational Technology and industrial environments.
- Secure privileged access to OT assets, systems, and administrative accounts.
- Enforce access governance controls for critical OT infrastructure.
- Support compliance and operational requirements while maintaining security controls.
- Collaborate with OT engineering and security teams during onboarding and implementation activities.
IAM Operations & Security Governance
- Support IAM operational activities across multiple client environments.
- Participate in identity governance, compliance, audit, and risk management initiatives.
- Develop and maintain IAM operational procedures, standards, and documentation.
- Conduct entitlement reviews, access risk assessments, and remediation activities.
- Support security incidents involving identity and access misuse.
- Collaborate with application, infrastructure, cloud, and security teams.
- Participate in IAM transformation, cloud identity, and Zero Trust initiatives.
- Contribute to process improvement and automation efforts.
Skills and Attributes for Success
- Strong understanding of Identity Governance, Access Management, and Privileged Access Management concepts.
- Knowledge of authentication, authorization, federation, and access-control technologies.
- Experience with RBAC, SoD, access certification, and identity lifecycle management.
- Familiarity with Zero Trust and Identity-Centric Security principles.
- Understanding of Active Directory, LDAP, Microsoft Entra ID, and enterprise identity architectures.
- Knowledge of compliance frameworks and regulatory requirements affecting IAM.
- Strong analytical and troubleshooting skills.
- Excellent communication and stakeholder management capabilities.
- Ability to manage multiple client engagements simultaneously.
To Qualify for the Role, You Must Have
- B. Tech, M. Tech, or equivalent degree in Cybersecurity, Computer Science, Information Security, or related disciplines.
- 12+ years of relevant experience in Identity and Access Management.
- Hands-on experience with:
- IBM Security Verify Governance; experience with SailPoint or Oracle Identity Governance is preferred
- IBM Security Verify Access; experience with Microsoft Entra ID, Okta or Ping Identity is preferred
- Delinea Secret Server
- Strong understanding of:
- Identity Governance & Administration (IGA)
- Access Management (AM)
- Privileged Access Management (PAM)
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Role-Based Access Control (RBAC)
- Segregation of Duties (SoD)
- Experience integrating IAM solutions with enterprise applications and directories.
- Understanding of SAML, OAuth 2.0, OpenID Connect, LDAP, and Active Directory.
- Strong verbal and written communication skills.
What We Look For
Professionals who are passionate about identity security and access governance, possess strong technical and analytical capabilities, and demonstrate a proactive approach to securing enterprise identities and privileged access. Successful candidates will have a strong customer-focused mindset, excellent problem-solving skills, and the ability to deliver high-quality IAM services while collaborating effectively within global cybersecurity teams.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.