Biibhrremote

Salary
$152,000–$220,000from the description
Posted
Jul 13, 2026
Location
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

This role leads access management service delivery within a corporate cybersecurity function, owning the policies, standards, and processes that govern how employees and systems are granted, maintained, and removed from application access globally. A key near-term focus is automating privileged account lifecycle management, while the longer-term goal is driving adoption of access automation across independent application teams. The position suits an experienced IAM professional with a background in program management, authorization models, and regulatory compliance such as SOX and GxP.

Senior level · 7+ years · Remote · Bachelor's required · Full-time

Must have (2)
IAMRBAC
Nice to have (3)
ABACSOXGxP

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 15,300 people nationally plausibly meet what this posting asks for (information security analysts). range 9,200–23,000

Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.

What won't set you apart
IAM45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The title 'Associate Director' carries no standard seniority-band word (Junior/Mid/Senior/Staff/Principal), so the title states no level. The job level field in the posting reads 'Management', but the role is primarily a hands-on IAM service-delivery and program-management position rather than a people-management role with direct reports, budget, and hiring authority — hence 15-1212 (Information Security Analysts) is preferred over 11-3021 (Computer and Information Systems Managers), though the latter is a genuine runner-up given the leadership framing.

The hard experience gate is '7+ years of focused Access Management experience'; the '10+ years of cybersecurity experience' is explicitly marked preferred in the posting.

RBAC and ABAC are described as core authorization models within the required Access Management scope; RBAC is treated as a required conceptual gate while ABAC appears more as illustrative context.

SOX and GxP compliance familiarity appear under the Preferred Skills section and are marked accordingly.

IAM automation and process improvement experience appear under Preferred Skills and are not separately listed as a skill to avoid duplication with the required Access Management gate, but are noted here as a meaningful differentiator the posting calls out.

No specific tooling platforms (e.g., SailPoint, Saviynt, CyberArk, Okta) are named in the posting despite the role's depth — the BAM (Biogen Access Management) platform is proprietary/internal.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Access Management.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗