ForgeApply
Try it free

ForgeApply · Job listing

Sr Manager, Identity Operations & Engineering

WEX

Portland, ME | Chicago, US$152k – $173konsite

See all 43 open roles at WEX

Tailor your resume for this WEX job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for WEX's site. Free trial, no card required.

About this role

About the Team & Role We are seeking a critical thinker with a strategic mindset to serve as the enterprise "Process Owner" for WEX’s identity lifecycle. Currently, WEX is undertaking a strategic modernization effort to automate identity lifecycles, eliminate manual ticket-driven provisioning, and migrate to a cloud-native identity governance architecture centered on SailPoint Identity Security Cloud (ISC).

As the Process Owner, you will define the strategy, prioritization, and technical readiness of our Identity and Access Management (IAM) initiatives. You must have a demonstrated history of success in managing complex identity programs and translating technical IAM concepts into tangible business value. A critical component of this position involves heavy partnership with WEX Application Owners to ensure their systems' identity management payloads are standardized, sanitized, and ready for integration. Your operations and engineering teams will prioritize, build, and test these integrations, working in lockstep with the Information Security SailPoint Administration/Configuration team. While your team engineers the data and tests the payloads, you will rely on your strong partnership with the Information Security team to execute the final platform configurations and deployments based on your prioritized backlog.

How you’ll make an impact Process Ownership & Identity Governance • Act as the primary Process Owner and single accountable leader for WEX’s Joiner, Mover, and Leaver (JML) identity lifecycle outcomes.

• Co-host WEX's IAM Governance Council alongside a designated leader from Information Security to drive policy reviews, prioritize the enterprise IAM backlog, and align on risk reduction.

• Define the business and technical requirements for automated lifecycle workflows, such as establishing "Birthright" access tied to Workday attributes and event-triggered Mover processes.

• Act as the primary Process Owner and single accountable leader for WEX’s IAM engineering and provisioning outcomes, breaking down silos between Security Engineering, Tech Operations, and Infrastructure.

• Operationalize WEX's IAM Governance Council to drive policy reviews, continuous improvement cycles, and establish measurable KPIs/KRIs (e.g., provisioning SLAs, MTTR for terminations, automated coverage).  

IAM Engineering & Operations Management • Lead and develop a blended group consisting of an IAM Operations team and an IAM Engineering team (including Active Directory engineers).

• Establish a seamless, continuous partnership with the Information Security SailPoint Administration/Configuration team, handing off fully tested integration data and guiding their platform configurations to meet your team's operational requirements.

• Support the architectural migration from legacy on-premise SailPoint IdentityIQ (IIQ) to the SailPoint Identity Security Cloud (ISC) SaaS platform.

• Centralize all access requests natively within SailPoint ISC, decommissioning the legacy Employee Service Portal (ESP/JSM) for IAM requests and eliminating manual fulfillment routing.

• Transition WEX from delayed termination batch-syncs to event-driven termination processing, ensuring immediate, end-to-end access revocation across all target systems upon employee separation.

• Ensure all engineering, integration, and operational work fully adheres to established ITSM/ITIL standards.

• Foster a culture of continuous improvement, automation, and toil reduction across all identity processes, leveraging metrics to optimize system performance and reduce manual administrative overhead.

• Oversee the health, security, and lifecycle management of enterprise directory services, ensuring high availability and robust integration with SailPoint for unified identity governance.

• Define architectural standards for directory services, focusing on modernizing infrastructure, optimizing group policy management, and streamlining authentication protocols to support a zero-trust environment.  

Application Owner Partnership & Integration Testing • Serve as the primary technical liaison to Application Owners, driving the campaign to onboard hundreds of disconnected WEX applications into the SailPoint ISC ecosystem.

• Define the application onboarding framework, establishing a tiered, risk-based prioritization backlog.

• Partner with application teams to design, extract, and standardize identity data payloads, ensuring identities correlate accurately to Global Workday IDs (WIDs).

• Oversee the "connector factory" preparation process: Your engineering team will build integration data maps, perform payload sanitization, and conduct pre-production testing before formally passing the validated package to InfoSec for configuration.  

Identity Operations & Provisioning Automation (UAP) • Transform daily identity operations by centralizing all access requests natively within SailPoint, decommissioning legacy manual routing, and transitioning WEX from delayed batch-syncs to event-driven termination processing.

• Drive continuous toil reduction by replacing the high volume of manual service desk tickets with automated, API-driven provisioning workflows.

• 5. Strategic ABAC/RBAC Prioritization & Preventative Security

• Experience designing and implementing access control frameworks (RBAC, ABAC, or hybrid models) to support least-privilege security architectures.

• Make ABAC/RBAC a top organizational priority by partnering with business leaders to develop a mature, scalable role model.

• Drive a massive entitlement rationalization exercise across WEX's ~10,600 entitlements to establish a clean, business-friendly self-service request catalog.

• Design roles that enforce Segregation of Duties (SoD) boundaries so toxic combinations cannot exist within a single role definition, utilizing critical thinking to balance security with operational efficiency.

• Decommission external spreadsheet-based role tracking by consolidating all role definit

Salary insight

The midpoint of this range ($163k) is about 6% above the median disclosed salary for Boston roles listed on ForgeApply ($154k across 2,206 jobs).

See full Operations salary data for Boston

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this WEX role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Operations Jobs · Operations Jobs in Boston · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)