IAM / Automation Lead
Description
Covetrus is a global animal-health technology and services leader dedicated to empowering veterinary practice partners to drive improved health and financial outcomes. We bring together products, services, and technology into a single platform that connects our customers to the solutions and insights they need to work best. Our passion for the well-being of animals and those who care for them drives us to advance the world of veterinary medicine.
IAM / Automation Lead
Information Technology • Full-Time • Remote
About the Role
As the IAM / Automation Lead, you will own the strategy, operations, and roadmap for enterprise Identity & Access Management (IAM) — protecting our workforce, applications, and data by ensuring the right people have the right access at the right time.
This is a high-impact, senior level role reporting to the Senior Director of IT. You will serve as the organization’s subject-matter expert and technical lead for enterprise IAM, partnering closely with IT, HR, Legal, and Compliance, and driving continuous maturity of our identity posture across cloud and on-premises environments. The role carries a heavy focus on automation and self-service — reducing manual operations, improving the end-user experience, and strengthening our cybersecurity posture while delivering cost savings.
Key Responsibilities
- Serve as the North American Center of Excellence (COE) lead for IAM, partnering with global COE counterparts to align standards, tooling, and best practices — ensuring IAM responsibilities and services are delivered consistently on a global basis
- Serve as the technical lead for IAM integration on current and future mergers, acquisitions, and divestitures (M&A)
- Lead the design, implementation, and operations of IAM programs including SSO, MFA, PAM, IGA, and directory services
- Deliver measurable cost savings and operational efficiencies by leading product evaluations, tools consolidations, and IAM initiatives back by data-driven financial business cases
- Enforce compliance with IAM policies and standards; Create procedures aligned to NIST, CIS, ISO 27001, SOX, and other applicable frameworks
- Own user lifecycle management: joiner/mover/leaver (JML) execution, access provisioning, role engineering, and automated de-provisioning
- Drive automation and self-service capabilities across the IAM function — including automated access requests, approvals, and provisioning — to reduce manual operations and improve the end-user service experience
- Partner with End User Services and the Service Desk to identify and automate away manual, ticket-based access requests, replacing them with self-service and automated workflows
- Deliver automated entitlement and permission reviews across SaaS, cloud, and on-prem applications
- Mature Privileged Access Management (PAM) adoption, including vault adoption, session monitoring, and just-in-time (JIT) access
- Partner with Cyber and Network Operations on global user controls, including Zero Trust and SSO group management — leading identity-centric network access controls and conditional access policy development
- Build and maintain integrations between IAM platforms, HR systems (HCM), ticketing systems, and downstream applications via SCIM, LDAP, and API connectors
- Define KPIs and metrics for access hygiene, orphaned accounts, and privilege sprawl; report SLA performance and program health to leadership quarterly
- Partner across teams to advance the IAM roadmap, and support IAM vendor relationships, licensing, and contract renewals in collaboration with Cyber and Procurement
- Serve as a technical mentor to IAM engineers and analysts, sharing best practices in design, implementation, and troubleshooting
- Support audits (SOX, SOC 2, ISO 27001) with evidence of quarterly access reviews, control narratives, and remediation tracking
- Drive IAM roadmap planning with a 12–18 month horizon, balancing security uplift with employee experience
-
Technologies & Platforms
Identity Governance & Administration (IGA)
- Okta Identity Governance
- Microsoft Entra ID Governance
- One Identity Manager
Single Sign-On & Federation
- Okta Workforce Identity (SSO, MFA, Lifecycle Management, Workflows)
- Microsoft Entra ID (Azure AD) — Conditional Access, PIM, Entitlement Management
Privileged Access Management (PAM)
- CyberArk PAM Suite (Vault, PSM, PVWA, CPM, Conjur)
- BeyondTrust Password Safe / Privileged Remote Access
- Delinea Secret Server / Privileged Access Service
- HashiCorp Vault (secrets management)
Directory Services
- Microsoft Active Directory (AD) & Active Directory Federation Services (ADFS)
- Microsoft Entra ID (Azure AD)
- LDAP / OpenLDAP
Cloud & Infrastructure Platforms
- AWS IAM, AWS Identity Center (SSO), AWS Cognito
- Microsoft Azure — Entra ID, Managed Identities, RBAC
- Kubernetes RBAC and workload identity
Protocols & Standards
- SAML 2.0, OAuth 2.0, OpenID Connect (OIDC)
- SCIM 2.0 (automated provisioning/deprovisioning)
- LDAP / LDAPS, Kerberos, RADIUS
- FIDO2 / WebAuthn (phishing-resistant MFA)
ITSM, SIEM & Adjacent Tools
- ServiceNow (self-service access catalog, automated request fulfillment, ITSM integration)
- Splunk / Microsoft Sentinel (identity threat detection, UEBA)
- CrowdStrike Falcon Identity Protection
- Workday / SAP SuccessFactors (HRIS integration for JML)
- Jira / Confluence (project tracking, runbooks)
Education and Experience
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent professional experience will be considered in lieu of a degree.
- 8+ years of progressive experience in information security or information technology, including 4+ years focused specifically on Identity and Access Management (IAM), with a demonstrated track record of applying automation and engineering discipline to reduce risk and manual effort
- 3+ years serving as a senior or lead technical contributor on an IAM function or program within a mid-to-large enterprise environment (5,000+ employees), with direct accountability for security outcomes and operational metrics
- Hands-on engineering experience designing, building, and operating enterprise IAM automation — including workflow engines, API/SCIM-based provisioning pipelines, and self-service access solutions that eliminate manual, ticket-based processes
- Experience integrating joiner/mover/leaver (JML) automation with an HRIS platform (e.g., Workday, SAP SuccessFactors, or similar) to drive straight-through processing and eliminate manual provisioning touchpoints
- Experience automating access certification/recertification campaigns at enterprise scale, reducing audit preparation time and manual reviewer effort
- Experience supporting compliance and security audits (SOX, SOC 2, ISO 27001, HIPAA, or equivalent), with a focus on building repeatable, automated evidence-collection and control-monitoring processes
- Experience managing PAM programs and vault platforms (e.g., CyberArk, BeyondTrust, Delinea) in production, including automating credential rotation, session monitoring, and just-in-time access to shrink the enterprise attack surface
- Demonstrated success building data-driven business cases that translate automation and tooling consolidation into measurable cost savings and licensing efficiencies
- Relevant industry certifications preferred (e.g., CISSP, CIAM, SC-300, Okta Certified Professional, or equivalent)
Competencies (Skills and Abilities)
Automation & Engineering
- Strong engineering mindset: able to design, script, and deploy automated identity workflows (SCIM, LDAP, REST/API connectors) rather than relying on manual or ticket-driven processes
- Proven ability to identify high-friction, manual IAM operations and re-architect them into scalable, self-service, automated solutions
- Skilled in building automated provisioning, de-provisioning, and entitleme