Point your AI agent at freehire and let it find you a job.

Get the CLI →

tiaa

NewBe an early applicant

Lead Information Security Operations Specialist

Discussion

The Lead Information Security Operations Specialist leads the organization's IAM Access Certification program, ensuring that user access across applications and platforms adheres to the principle of least privilege. Working under limited supervision, this individual contributor role serves as the subject matter expert for access governance, driving the design, implementation, and continuous improvement of certification campaigns, Segregation of Duties (SoD) controls, and Role Based Access Control (RBAC) frameworks. This role partners closely with application teams, Lines of Business, and enterprise IAM leadership to ensure consistent, high-quality access governance across both centralized and decentralized applications, including support for the organization's transition from SailPoint IdentityIQ to Saviynt.




Key Responsibilities and Duties

  • Leads the end-to-end strategy and execution of the IAM Access Certification program, ensuring certification campaigns are conducted with consistent cadence and rigor across both centralized (IGA-onboarded) and decentralized applications.

  • Leads application scoping efforts to determine onboarding eligibility to the centralized IGA platform and, where applicable, identifies the appropriate integration type.

  • Oversees the build-out, implementation, and ongoing operational health of Segregation of Duties (SoD) rules and Role Based Access Control (RBAC) profiles, partnering with application teams and Lines of Business who are responsible for defining the underlying SoD and RBAC requirements.

  • Leads user access review campaigns to enforce the principle of least privilege, ensuring individuals retain only the access required to perform their job responsibilities.

  • Applies the same access certification standards, cadence, and rigor to decentralized applications not onboarded to the centralized IGA platform, including those currently managed through manual, email, or spreadsheet-based processes, and drives improvements to standardize and streamline these processes over time.

  • Identifies and implements opportunities to leverage AI-enabled capabilities, including those native to Saviynt, to improve certification efficiency and accuracy through outlier detection, access recommendations, and other intelligent review mechanisms.

  • Establishes and matures certification practices for Non-Human Identities (NHIs), including service accounts and AI agents, ensuring appropriate ownership, review, and governance controls are in place.

  • Serves as the subject matter expert on IAM access governance, providing mentorship and guidance to other IT security team members supporting the certification program.

  • Supports the organization's migration from SailPoint IdentityIQ to Saviynt, including validating that access certification, SoD, and RBAC capabilities are properly configured and operational within the new platform.

  • Coordinates with internal audit and information security assessment teams to identify weaknesses in access governance processes and strengthens existing controls accordingly.

  • Conducts analysis of organizational needs and goals to guide the ongoing development of access certification, SoD, and RBAC capabilities.

  • Identifies and evaluates emerging data access control technologies, techniques, and safeguards relevant to identity governance and access certification.

Educational Requirements

  • University (Degree) Preferred

Work Experience

  • 5+ Years Required; 7+ Years Preferred

Physical Requirements

  • Physical Requirements: Sedentary Work


Career Level
8IC

Required Skills

  • 5+ years of IT or information security experience
  • 3+ years of experience leading or supporting Identity Governance and Administration (IGA) programs, including access certification campaigns
  • Hands-on experience with Saviynt and/or SailPoint IdentityIQ
  • Demonstrated experience implementing or overseeing Segregation of Duties (SoD) rules and Role Based Access Control (RBAC) frameworks
  • Strong understanding of the principle of least privilege and its application within enterprise access governance programs
  • Experience partnering with cross-functional teams, including application owners and Lines of Business, to gather and translate access governance requirement

Preferred Skills

  • Direct hands-on experience with Saviynt strongly preferred, given the organization's active migration from SailPoint IdentityIQ
  • Experience leading application scoping and onboarding processes for an enterprise IGA platform
  • Experience applying access certification controls to decentralized or manually managed applications outside of a centralized IGA tool
  • Experience leveraging AI or machine learning capabilities to streamline access reviews, including outlier detection and access recommendation engines
  • Experience governing access for Non-Human Identities (NHIs), such as service accounts, bots, or AI agents
  • Bachelor's degree in Information Security, Computer Science, or a related field

Related Skills

Accountability, Adaptability, Business Continuity Planning, Cloud Computing Security, Collaboration, Communication, Compliance, Consultative Communication, Cybersecurity, Detail-Oriented, General Risk Management, Network Security, Prioritizes Effectively

Anticipated Posting End Date:

2026-09-15

Base Pay Range: $108,000/yr - $130,000/yr

Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location. In addition to base salary, the competitive compensation package may include, depending on the role, participation in an incentive program linked to performance (for example, annual discretionary incentive programs, non-annual sales incentive plans, or other non-annual incentive plans).

_____________________________________________________________________________________________________

Company Overview

Every worker deserves a secure retirement. For more than 100 years, TIAA has delivered it for millions of people. Founded to help educators retire with dignity, today weʼre a market-leading retirement company fueled by world-class asset management. But weʼre not just another legacy financial services firm. Weʼre fighting harder than ever before for our clients and the many Americans who need us.

Our Culture of Impact

At TIAA, we're on a mission to build on our 100+ year legacy of delivering for our clients while evolving to meet tomorrow's challenges. We equip our associates with future-focused skills and AI tools that enable us to advance our mission. Together, we are fighting to ensure a more secure financial future for all and for generations to come. We are guided by our values: Champion Our People, Be Client Obsessed, Lead with Integrity, Own It, and Win As One. They influence every decision we make and how we work together to serve our clients every day. We thrive in a collaborative in-office environment where teams work across organizational boundaries with shared purpose, accelerating innovation and delivering meaningful results. Our workplace brings together TIAA and Nuveen's entrepreneurial spirit, where we work hard and work together to create lasting impact. Here, every associate can grow through meaningful learning experiences and development pathways—because when our people succeed, our impact on clients' lives grows stronger.

Benefits and Total Rewards

The organization is committed to making financial well-being possible for its clients, and is equally committed to the well-being of our associates. That’s why we offer a comprehensive Total Rewards package designed to make a positive difference in the lives of our associates and their loved ones. Our benefits include a superior retirement program and highly competitive health, wellness and work life offerings that can help you achieve and maintain your best possible physical, emotional and financial well-being. To learn more about your benefits, please review our Benefits Summary.

Equal Opportunity

We are an Equal Opportunity Employer. TIAA does not discriminate against any candidate or employee on the basis of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other legally protected status.

Our full EEO & Non-Discrimination statement is on our careers home page, and you can read more about your rights and view government notices here.

Accessibility Support

TIAA offers support for those who need assistance with our online application process to provide an equal employment opportunity to all job seekers, including individuals with disabilities.

If you are a U.S. applicant and desire a reasonable accommodation to complete a job application please use one of the below options to contact our accessibility support team:

Phone: (800) 842-2755

Email: accessibility.support@tiaa.org

Drug and Smoking Policy

TIAA maintains a drug-free and smoke/free workplace.

Privacy Notices

For Applicants of TIAA, Nuveen and Affiliates residing in US (other than California), click here.

For Applicants of TIAA, Nuveen and Affiliates residing in California, please click here.

For Applicants of TIAA Global Capabilities, click here.

For Applicants of Nuveen residing in Europe and APAC, please click here.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available