Manager Identity & Access Management
- Merrick Bank
- Woodbury (Long Island)
- 2w ago
- Full-Time
- On-site
Join our team - and take the next step in achieving a fulfilling career!
What We Do
At CardWorks, we aim to help people connect with possibility and opportunity using our financial servicing expertise. Building meaningful, long-term relationships with consumers, our employees, and our clients is what matters most.
Who We Are
CardWorks, Inc. is a diversified consumer finance service provider and parent company of CardWorks Servicing, LLC, Merrick Bank and Carson Smithfield, LLC.
CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans. We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees.
Merrick Bank is an FDIC-insured Utah Industrial Loan Bank. Merrick operates three main business lines: credit cards, recreational lending, and merchant services.
Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management.
Position Summary:
The IAM Manager is responsible for the day‑to‑day leadership, execution, and continuous improvement of identity and access management (IAM) detective controls and supporting automation. This role leads a technical team that operates access monitoring, certifications, reconciliations, and alerting capabilities that detect unauthorized or inappropriate access across the enterprise.
The manager ensures IAM detective controls operate effectively, consistently, and in compliance with internal security standards and regulatory expectations. This role partners closely with IAM engineering, cybersecurity operations, risk management, internal audit, and application teams to mature controls through automation, improved data quality, and scalable processes.
The ideal candidate combines people leadership, operational discipline, and technical understanding of IAM controls, with a strong focus on reducing manual effort, improving detection capabilities, and maintaining audit readiness.
Essential Functions:
Leadership & Operational Management
Expectation: Lead the daily operations of a technical IAM controls team, ensuring consistent execution, accountability, and reliable delivery of detective access management services.
Provide day‑to‑day leadership, supervision, and direction for a team responsible for IAM detective controls and automation.
Set clear performance expectations, prioritize work, manage workload distribution, and support ongoing skill development of team members.
Serve as the escalation point for complex operational issues, control failures, or security‑relevant findings.
Ensure consistent execution of IAM detective control processes in alignment with policies, standards, and documented procedures.
IAM Detective Control Execution
Expectation: Ensure detective IAM controls operate effectively and consistently to identify unauthorized or inappropriate access in a timely manner.
Oversee the execution of detective access management controls, including access certifications, authentication configuration reviews, access monitoring, and exception handling.
Ensure controls effectively detect unauthorized access, inappropriate privilege assignments, and policy violations.
Coordinate timely investigation, escalation, and remediation of access issues identified through detective controls.
Maintain operational ownership of control results, tracking issues through remediation and closure.
Detective IAM Controls & Security Operations Support
Expectation: Actively supports monitoring, investigation, and response activities related to IAM security signals.
Support detective IAM controls, including logging, alerting, and access review evidence collection
Monitor IAM and PAM activity for anomalous or unauthorized behavior
Assist with identity‑related investigations, incidents, and penetration testing efforts
Gather and analyze IAM and PAM data for audits, incident response, and forensic activities
Collaborate with security teams during access‑related security events to assess impact and remediate issues
Automation & Process Optimization
Expectation: Drive improvements to control effectiveness, efficiency, and scalability through automation and process maturity.
Assist with efforts to automate IAM detective control execution, reporting, and evidence collection.
Identify opportunities to reduce manual processes, spreadsheet dependency, and point‑in‑time reviews through automation and workflow improvements.
Partner with IAM engineering and platform teams to improve control data accuracy, metadata completeness, and tool reliability.
Drive continuous improvement of control processes through standardization, automation, and operational metrics.
Compliance, Audit, & Risk Support
Expectation: Maintain audit‑ready IAM detective controls that meet regulatory, risk, and internal security expectations.
Ensure IAM detective controls align with regulatory, audit, and internal risk management requirements.
Coordinate audit preparation activities, including evidence collection, documentation, and control walkthroughs.
Respond to audit inquiries and remediation requests related to IAM detective controls.
Partner with risk, compliance, and audit teams to identify control gaps and implement corrective actions.
Cross‑Functional Collaboration & Reporting
Expectation: Act as the operational liaison between IAM detective control operations and key security, technology, and risk stakeholders.
Collaborate with IAM engineering, security operations, infrastructure, and application teams to support access monitoring and control effectiveness.
Provide regular reporting on control performance, issues, trends, and improvement initiatives to leadership and stakeholders.
Participate in IAM governance and security forums to represent detective control operations and provide operational insights.
Support security incident investigations and access‑related risk assessments as needed.
Education and Experience
Bachelor’s degree in Information Security, Information Technology, Computer Science, or a related discipline; or an equivalent combination of education and relevant experience.
6 to 8 years of progressive experience in Identity and Access Management, information security operations, or IT control functions.
2 or more years of experience leading or managing a technical team, including responsibility for operational delivery, performance management, and prioritization of work.
Hands‑on experience operating or overseeing IAM detective controls such as access certifications, access monitoring, reconciliations, or identity‑related alerting.
Experience supporting audit, risk, and compliance activities within a regulated industry; financial services experience preferred.
Experience driving process maturity and automation initiatives to reduce manual effort and improve control reliability.
Familiarity with IAM platforms, access data models, automation tools, and identity‑related logging or reporting capabilities.
Working knowledge of regulatory and control frameworks such as SOX, SOC1, SOC2, or similar security and compliance standards.
Summary of Qualifications
Proven ability to lead and develop technical teams in an operational security or IAM environment.
Strong understanding of identity and access management controls, particularly detective and monitoring controls.
Experience driving process improvement and automation to enhance control effectiveness and efficiency.
Solid understanding of audit, risk, and compliance expectations related to IAM.
Ability to analyze access data, interpret control results, and drive remediation efforts.
Strong organizational skills with the ability to manage multiple priorities and deadlines.
Effective communicator capable of working with technical teams, auditors, and non‑technical stakeholders.
Demonstrated commitment to operational excellence, continuous improvement, and secure access practices.
Ideally, the qualified candidate will work at the following location(s): Woodbury, NY; South Jordan, UT. A hybrid work model or fully remote model can be considered based on hiring manager decision and priorities of the role.
The salary range for this position, if located in NY Metro/NY State is $153,384 to $138,045. However, please note that the salary range will vary for other geographic areas.
#INDHP
Our Employee Value Proposition
We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.
We are an equal opportunity employer, and we evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status or any other legally protected characteristic. We will conduct a thorough background check for all hires in compliance with applicable laws.