Identity Security & Governance Director
- Salary
- $184K–$231KUSD per year
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 25, 2026
At Zimmer Biomet, we believe in pushing the boundaries of innovation and driving our mission forward. As a global medical technology leader for nearly 100 years, a patient’s mobility is enhanced by a Zimmer Biomet product or technology every 8 seconds.
As a Zimmer Biomet team member, you will share in our commitment to providing mobility and renewed life to people around the world. To support our talent team, we focus on development opportunities, robust employee resource groups (ERGs), a flexible working environment, location specific competitive total rewards, wellness incentives and a culture of recognition and performance awards. We are committed to creating an environment where every team member feels included, respected, empowered and recognised.
What You Can Expect
The Director, Identity Security & Governance provides global leadership for enterprise identity security strategy, identity governance and administration (IGA), privileged access governance and identity risk management across Information Technology, Medical Device product development and Operational Technology environments.
Reporting within Information Security, this role is accountable for assessing identity and access risks before establishing controls, policies, standards and a multi-year roadmap that reduces risk, supports business and product transformation and protects human, non-human and AI-enabled identities across a complex global environment. This leader owns the strategic direction and security governance for identity lifecycle, access certification, role and entitlement governance, segregation of duties, privileged access, risk-based authentication and authorization, identity threat detection, service and workload identities, machine identities and identities used by AI agents and automated workflows. The role partners closely with Infrastructure, Enterprise Architecture, Applications, Human Resources, Internal Audit, medical device product development, manufacturing and OT teams to align identity controls with Zero Trust principles, regulatory obligations, product-security needs and enterprise priorities.
How You'll Create Impact
- Create, maintain and execute enterprise identity security and governance strategy, target-state control architecture & investment roadmap aligned with cybersecurity strategy, business transformation, device product development, manufacturing and OT priorities
- Lead enterprise identity governance and administration (IGA) program, inc. joiner-mover-leaver governance, access requests & approvals, access certifications, role & entitlement governance, birthright access, segregation of duties, external identities & evidenence
- Define enterprise security requirements for ZeroTrust access, strong phishing-resistant authentication, Conditional Access, device trust, session controls, privileged access, least privilege & risk-based authorization in IT, product-development and OT environment
- Establish governance for non-human identities, including service accounts, workload and machine identities, secrets and certificates, with accountable ownership, least privilege, lifecycle, rotation, monitoring, recertification and retirement requirements.
- Establish security & governance requirements for identities used by AI systems, AI agents and automated workflows, including identity issuance, delegated authority, tool access, authorization boundaries, credential handling, monitoring, traceability and termination
- Define identity threat detection and response strategy, priority risk scenarios, detection and telemetry requirements, escalation criteria and response playbooks in partnership with Security Operations, product cybersecurity, Infrastructure and OT stakeholders
- Establish enterprise identity operating model and governance cadence with Infrastructure, HR, Enterprise Architecture, application owners, product-development & OT leaders; define decision rights, security standards, risk acceptance, exception management
- Demand prioritization and transparent risk-based sequencing.
- Lead, coach & develop globally distributed identity security & governance team; manage contractors & service providers; define & report risk, security & delivery measures including lifecycle timeliness, privileged access coverage, non-human and AI identity coverage
- Control effectiveness, exceptions, incidents and roadmap value realization
- Publish and govern an approved enterprise identity security and governance strategy, target-state control architecture and sequenced multi-year roadmap with clear investment, risk and dependency decisions across IT, medical device product development and OT
- Improve identity posture through measurable gains in lifecycle governance, access ownership, certification quality, segregation of duties, strong authentication, privileged access, control effectiveness and identity threat readiness
- Establish measurable governance and lifecycle control for non-human identities and identities used by AI systems, AI agents and automated workflows
- Create sustainable global operating model that clarifies security-governance, platform-operation and risk-ownership responsibilities across Information Security, Infrastructure, HR, application teams, product-development, manufacturing, OT and service partners
- Build a high-performing identity security and governance organization with clear roles, strong technical and risk depth, succession coverage and effective internal and external delivery capacity
What Makes You Stand Out
- Demonstrated strategic identity security and governance leadership in a large, complex, global and matrixed enterprise, with the ability to convert business, product, manufacturing and security objectives into a funded multi-year roadmap and executable portfolio
- Deep knowledge of identity governance and administration, including identity lifecycle, access requests and approvals, access certification, role and entitlement models, segregation of duties, external identities and control evidence
- Broad experience with identity technologies such as Microsoft Entra ID Governance, privileged access management, identity orchestration, directory services, secrets management, certificate/public key infrastructure and identity threat detection platforms
- Strong command of authentication and authorization architecture, privileged access, passwordless and phishing-resistant authentication, federation, RBAC/ABAC and standards including SAML, OAuth 2.0, OpenID Connect, SCIM and LDAP
- Ability to assess identity and access risks and lead security programming using Zero Trust, least privilege, secure-by-design, defense-in-depth and risk-based control principles across IT, medical device product development and OT environments
- Experience governing non-human identities, including service accounts, workload identities, machine identities, secrets and certificates, and addressing their distinct ownership, lifecycle, privilege and monitoring risks
- Understanding of identity and authorization risks introduced by AI systems, AI agents and automated workflows, including delegated authority, tool access, credential use, traceability and human accountability
- Experience building accountable operating models across Information Security, Infrastructure, Human Resources, application teams, product-development, product cybersecurity, manufacturing, OT, Internal Audit and managed service providers
- Executive-level communication, facilitation and influence skills; ability to explain material identity risk, investment choices, control trade-offs and outcomes to senior technical, product, manufacturing and business leaders
- Demonstrated financial and vendor management capability, including budget planning, business cases, licensing, contracts, sourcing strategy, service-level management and value realization
- Data-driven leadership with experience establishing KPIs, KRIs, control measures, dashboards and governance routines that demonstrate risk reduction, adoption, control effectiveness and roadmap progress
- Working familiarity with SAP authorization concepts & ERP access-governance requirements (e.g., role-based access, segregation of duties, access certification, privileged access, and audit/compliance controls)
- Ability to partner effectively with SAP, JD Edwards, business-process, and application owners to assess access risks and establish appropriate governance and control requirements
Your Background
- Bachelor's Degree and 8 years of relevant experience, or Associate's Degree and 10 years of relevant experience, or High School Diploma or Equivalent and 12 years of relevant experience AMER
- 12+ years of progressive professional experience in identity and access management, cybersecurity, technology risk, infrastructure, product security, cloud or related enterprise technology disciplines
- 7+ years of direct responsibility for enterprise identity security strategy, identity governance and administration, privileged access, identity architecture or related security programs in a large-scale, hybrid and globally distributed environment
- 5+ years of people leadership experience, including responsibility for managers and/or senior professionals, contractors and managed service partners
- 5+ years of hands-on or accountable leadership experience with Microsoft Entra ID/Azure AD and one or more enterprise IGA, PAM, secrets-management or identity security platforms
- Demonstrated experience creating and delivering multi-year strategies, roadmaps, operating models and security improvement programs with measurable outcomes across multiple technology domains
- Relevant certifications are preferred, such as Microsoft identity/security credentials, CISSP, CISM, CRISC, CCSP or vendor-specific IGA/PAM certifications
Travel Expectations
- Up to 20%
- Expected compensation for the role is: $184,000 - 231,000 base salary per year plus performance bonuses.
EOE/M/F/Vet/Disability