About the Role
Lead the design and implementation of enterprise identity and access management (IAM) solutions, defining the architecture for identity governance, authentication, authorization, and privileged access across cloud and on-prem environments. This role ensures alignment with business goals and regulatory requirements, and is responsible for coordinating and integrating into other IT, Cybersecurity, and business solutions.
Responsibilities
- Architect and design scalable IAM solutions including SSO, MFA, identity federation, IDV, IGA and privileged access management
- Develop and maintain identity architecture blueprints, standards, and roadmaps
- Collaborate with engineering, compliance, and business teams to translate security requirements into technical designs, including authorization mappings
- Collaborate with detection and response teams and the scaling of ITDR services
- Lead technical evaluations of IAM tools and platforms, and oversee their integration
- Partner with cybersecurity engineers and architects on integrating IAM into the IT and cybersecurity tooling ecosystem (e.g. SOC, Data Security, AI, Network, etc.)
- Ensure new identity solutions align with zero trust principles, data protection policies, and compliance frameworks (e.g., NIST, ISO, GDPR)
- Provide technical leadership to incident response and identity-related threat mitigation when required
- Stay current with emerging IAM technologies, trends, and threats
- Evaluate and incorporate emerging technologies such as passwordless authentication, continuous adaptive trust, or AI-driven access decisions while creating and optimizing associated process with associated teams
- Manage vendor relationships
- Define KPIs and metrics with IAM Program lead to measure IAM program effectiveness
- Comply with corporate policies, procedures, and security standards while performing assigned duties
- Contribute to a strong Environmental Health and Safety (EHS) culture by following safety policies, identifying hazards, and engaging in continuous improvement
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, or related field (completed and verified prior to start)
- Ten (10) years experience in enterprise identity management in a private, public, government or military environment
- Experience operating in a multi-national and large enterprise
- Ability to design and articulate identity, authentication, authorization, and lifecycle management solutions for modern IT systems (APIs, containers, agentic agents, etc.)
- Understanding of API gateways (mTLS, SPIFFE/SPIRE), and token management
- Experience with IAM platforms (e.g., Azure AD / Entra, Saviynt, CyberArk, etc.)
- Strong knowledge of cloud identity (AWS, Azure, GCP) and hybrid environments
- Familiarity with regulatory and compliance standards (HIPAA, SOX, PCI-DSS)
- Excellent written communication and stakeholder engagement skills
- Excellent ability to document complex technical solutions for consumption at a variety of levels
- Experience supporting a manufacturing company with IT and OT
- Experience integrating identity into larger cybersecurity systems and workflows
- Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status)
- All US-based 3M full time employees will need to sign an employee agreement as a condition of employment with 3M. This agreement lays out key terms for using 3M Confidential Information and Trade Secrets, and includes provisions on conflicts of interest and invention assignment. Employees at Job Grade 7 or equivalent and above may also have obligations regarding non-competition and non-solicitation.
- Must provide education and work history by uploading a resume or entering the information into the application fields directly.
Skills
- SSO
- MFA
- Identity federation
- IDV
- IGA
- Privileged access management
- Zero trust principles
- Data protection policies
- NIST
- ISO
- GDPR
- Passwordless authentication
- Continuous adaptive trust
- AI-driven access decisions
- Identity protocols (SAML, OAuth, OpenID Connect, LDAP, Kerberos, etc.)
- Non-human identities (service accounts, machine identities, AI agents, delegated authentication flows)
- Cloud identity (AWS, Azure, GCP)
- Cybersecurity
- ITDR services
Location
- Maplewood, MN
- Austin, TX
Work Type
- On-site
Experience Level
- Ten (10) years experience in enterprise identity management
Education Level
- Bachelor’s degree in Cybersecurity, Computer Science, or related field
Salary/Compensations
- $221,591 - $270,834
Benefits
- Medical, Dental & Vision
- Health Savings Accounts
- Health Care & Dependent Care Flexible Spending Accounts
- Disability Benefits
- Life Insurance
- Voluntary Benefits
- Paid Absences
- Retirement Benefits
About the Company
- 3M is a place where you can collaborate with other curious, creative 3Mers.
- Learn more about 3M’s creative solutions to the world’s problems at www.3M.com or on Instagram, Facebook, and LinkedIn @3M.
Equal Opportunity
- 3M does not discriminate in hiring or employment on the basis of race, color, sex, national origin, religion, age, disability, veteran status, or any other characteristic protected by applicable law.
