Level: M3
About the Role
As an Associate Director, IT Security, you will provide leadership and guidance to managers, supervisors, and senior professionals. You will be accountable for the performance and results of multiple related departments or areas, overseeing the implementation of advanced security measures and critical defense strategies across the organization — with a strategic focus on Non-Human Identity (NHI) governance and emerging AI agent identity risk.
Key Responsibilities
Leadership & Governance
- Provide leadership and direction to multiple IT security departments.
- Oversee development and implementation of long-term security strategies.
- Coordinate large-scale security responses and complex investigations.
- Develop and enforce governance frameworks for IT security across departments.
- Direct initiatives to identify and mitigate significant security risks.
- Facilitate cooperation and communication across IT and business departments.
- Lead enterprise-wide security training and awareness initiatives.
- Ensure strict adherence to regulatory and compliance requirements.
- Present security findings and recommendations to executive leadership.
- Manage budgets, resources, and security investments effectively.
NHI Program Design and Delivery
- Define and execute the NHI program roadmap across four phases: Foundation (discovery and inventory), Govern (controls and standards), Automate (lifecycle automation and CIEM integration), and AI Identity (agent governance).
- Build and maintain the NHI inventory register — a continuously updated record of all non-human identities across AD, Entra ID, AWS, Azure, GCP, and CI/CD platforms.
- Define the NHI risk classification model — tiering all NHIs by blast radius, sensitivity, and governance maturity.
- Produce monthly NHI program metrics — inventory coverage, orphan rate, vault onboarding %, secret age, and rotation compliance.
CI/CD Pipeline and Container Identity
- Own CI/CD pipeline identity governance — migrating GitHub Actions and Azure DevOps pipelines to OIDC federation (keyless authentication) and eliminating stored pipeline secrets.
- Define and enforce pipeline identity standards — minimum permission scoping, federated credential design, and deployment identity governance.
- Own AKS and EKS workload identity architecture — ensuring containerized workloads authenticate via federated identity rather than stored credentials.
- Deploy Secrets Store CSI driver and equivalent patterns to enable vault-injected secrets for Kubernetes workloads without credential storage.
AI Agent Identity Governance
- Design the AI agent identity model — identity structure, permission scoping, accountability attribution, and lifecycle governance for AI agents operating within the enterprise.
- Own LLM API key governance — inventorying, vaulting, and enforcing rotation for API keys across OpenAI, Anthropic, Azure OpenAI, Gemini, and other LLM platforms.
- Govern MCP server identity and access controls — maintaining an approved MCP server registry and enforcing access via managed settings and policy.
- Build the AI agent audit trail — ensuring all AI-initiated actions are logged, attributed to a human authorizer, and included in compliance evidence packs.
- Lead shadow AI discovery — identifying corporate credentials used in unapproved AI tools and publishing the approved AI tool access policy.
Skills
- Executive Leadership — guiding multiple departments toward common security goals.
- Strategic Management — formulating and overseeing strategic security initiatives.
- Complex Incident Handling — managing large-scale, sophisticated security incidents.
- Governance Knowledge — deep understanding of security governance frameworks and implementation.
- Advanced Risk Assessment — high-level risk identification and mitigation.
- Interdepartmental Liaison — uniting diverse teams and departments.
- Program Management — designing and leading comprehensive security training programs.
- Budget Management — managing security budgets and optimizing resource allocation.