- Location
- CZE - Praha - Multiple Opcos, Czechia · USA - Brea - Multiple OpCo
- Type
- Full-time
- Department
- Administration
- Seniority
- Lead
- Experience
- 2+ years
- Education
- Bachelor
- Source
- Workday
Description
Job Description:
We are seeking a strategic and execution-focused Identity Governance & Administration (IGA) Lead to drive and mature enterprise identity governance capabilities across workforce and customer identity environments. This role owns the strategy, operating model, governance framework, and roadmap for delivering secure, scalable, and auditable access management across the organization.
This position will balance security, compliance, automation, and user experience while driving modernization across identity lifecycle management, entitlement governance, and authentication controls.
PRIMARY DUTIES AND RESPONSIBILITIES:
Identity Governance Strategy & Leadership
- Define and lead enterprise IGA strategy, roadmap, operating model, and maturity plan
- Establish governance frameworks across workforce, privileged, third-party, machine, AI, and customer identities
- Act as primary owner for access governance risk, control effectiveness, and audit readiness
Workforce & Customer Identity Governance
- Oversee lifecycle processes including joiner, mover, leaver, contractor, and partner access
- Govern access across enterprise apps, cloud, SaaS, privileged systems, and critical platforms
- Lead RBAC/ABAC initiatives including role mining, engineering, and lifecycle management and toxic combination identification
- Define customer identity governance standards including registration, identity proofing, consent, delegated administration, entitlement management, and lifecycle controls (activation, inactivity, deletion, retention)
- Ensure alignment with privacy, regulatory, and user experience requirements
- Advance adoption of passwordless and phishing-resistant authentication
- Collaborate with the Detection team to mature identity threat detection capabilities through behavioral analytics
Leadership & Stakeholder Management
- Build and lead a high-performing identity governance function
- Provide executive reporting on access risk, governance maturity, and remediation progress
- Partner across Security, IT, HR, Legal, Privacy, Product, Engineering, and business teams
- Define KPIs/KRIs including provisioning SLAs, certification quality, remediation aging, SoD violations, and risk trends
- Ensure audit-ready reporting, repeatable evidence, and control assurance
Job Requirements:
Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or a related field; Equivalent industry experience, military service, professional certifications, and demonstrated leadership experience are valued equally
One or more of the following certifications: Microsoft Certified: Identity and Access Administrator Associate; Microsoft Cybersecurity Architect Expert; SailPoint IdentityIQ / ISC Certifications; Saviynt Certifications; Certified Identity and Access Manager (CIAM)
7+ years leading enterprise IAM/IGA programs
2+ years of experience managing MSPs
Experience supporting large-scale global organizations with multiple business units, acquisitions, and complex application ecosystems
Hands-on experience with a leading IGA platform (SailPoint, Saviynt, Entra ID Governance, or Okta)
Deep expertise in: Joiner/Mover/Leaver processes; Access certifications; Entitlement management; RBAC/ABAC; Segregation of Duties (SoD); Access request and approval workflows; Identity lifecycle management
PREFERRED SKILLS & EXPERIENCE:
Prior ownership of enterprise identity governance strategy and roadmap
Experience building or transforming an IGA program from low maturity to optimized maturity
Experience supporting M&A integration and identity consolidation programs
CISSP, CISM, CRISC, CCSP certification(s)
#LI-PG1
Operating Company:
CorporateEnvista is a global leader in the dental industry, uniting more than 30 trusted brands—including DEXIS, Kerr, Nobel Biocare, and Ormco—under one mission: partnering with dental professionals to improve patients’ lives. With a heritage of category-defining innovation, our brands have shaped modern dentistry: Nobel Biocare introduced the first dental implant, Ormco is a pioneer in both traditional and digital orthodontics, DEXIS has long been at the forefront of 2D, 3D and intraoral imaging, and Kerr has supported clinicians for over 135 years. Our high-performing culture is underpinned by our CIRCLe Values and the Envista Business System. Guided by these, we deliver a comprehensive portfolio of technologies, consumables, and services that empower clinicians to provide confident, efficient care—today and for the future. Learn more at http://envistaco.com.
Envista and its family of companies (Envista) will not accept unsolicited resumes from any source other than directly from a candidate. Envista will consider unsolicited referrals and/or resumes submitted by vendors such as search firms, staffing agencies, professional recruiters, fee-based referral services and recruiting agencies (Agency) to have been referred by the Agency free of charge and Envista will not pay a fee for any placement resulting from the receipt such unsolicited resumes. An Agency must obtain advance written approval from Envista's internal Talent Acquisition or Human Resources team to submit resumes, and then only in conjunction with a valid fully-executed contract approved by the Global Talent Acquisition leader and in response to a specific job opening. Envista will not pay a fee to any Agency that does not have such agreement and written approval in place.