Manager, Identity and Access Management (IAM)

Location: 

West Palm Beach, FL, US

Req ID:  41766
Date:  Aug 21, 2026

Florida Crystals Corporation is a fully integrated cane sugar company. Florida Crystals regeneratively farms sugarcane and rice in South Florida, where it owns two sugar mills, a sugar refinery, a packaging and distribution center, Florida's only rice mill, a compost facility, and one of the largest renewable power plants of its kind in the U.S., which uses sugarcane fiber to generate eco-friendly energy that powers its sugar operations. Florida Crystals owns one of the largest Regenerative Organic Certified® farms in the U.S. and its Florida Crystals® products are the only ROC™ sugar grown and milled sugar in the country. Florida Crystals owns ASR Group International, Inc., a holding company that conducts operations through its subsidiaries. The ASR Group® family of companies make up the world’s largest refiner and marketer of cane sugar. Florida Crystals is headquartered in West Palm Beach, Florida. Learn more at www.FloridaCrystalsCorp.com.

 

 

OVERVIEW

 

The Identity and Access Management (IAM) Manager reports to the Sr. Director, Information Security (CISO) and serves as the enterprise leader for the IAM program across Florida Crystals / ASR Group. The role owns the strategy, roadmap, and day-to-day execution of Identity and Access Management, including Microsoft Entra ID and Entra ID Governance, SAP Security across ECC, S/4HANA, and SAP RISE, privileged access, joiner/mover/leaver processes, access certifications, and audit readiness.

 

The primary focus is to mature and operate the IAM program with a strong emphasis on expert-level SAP Security, identity governance, and audit-defensible controls. This role leads a hybrid team consisting of an in-house Senior SAP Security Administrator, an in-house Senior IAM Engineer focused on Entra ID Governance, and an outsourced team of SAP Security administrators executing SAP permissions changes under tight SLAs. The IAM Manager partners closely with SAP BASIS and functional teams, Enterprise Architecture, HRIS, Internal Audit, and business leadership to advance the IAM architecture and execute the multi-year identity, governance, and SAP Security roadmap.

 

 

Detailed Roles & Responsibilities

  • Lead, coach, and develop a hybrid IAM team, including in-house engineers and an outsourced SAP Security administration team of seven, with clear SLAs, quality standards, and escalation paths.
  • Own the multi-year IAM roadmap aligned to the Zero Trust and enterprise security strategy, covering SAP Security, Entra ID Governance, privileged access, and access certification modernization.
  • Serve as the enterprise SAP Security subject-matter expert across ECC, S/4HANA, BW/BI, RISE, Fiori, CIS, IAS, SolMan, and GRC Access Control (ARA, ARM, BRM, EAM), including role design methodology, SoD ruleset, mitigation controls, and derivation strategy.
  • Direct the outsourced SAP admin team on day-to-day security operations, including role creation and change, user provisioning, license type assignment, FUE tracking, SU53/ST01 tracing, transport strategy, and emergency (firefighter) access.
  • Oversee SoD analysis and remediation, critical authorization reviews, EWA security findings, and SAP Security Notes patching cadence in partnership with SAP Basis.
  • Lead SAP Security work streams for upgrades, S/4HANA transformations, greenfield and brownfield conversions, Fiori rollouts, and M&A integrations or divestiture carve-outs.
  • Own the Microsoft Entra ID Governance platform, including entitlement management, access packages, access reviews, lifecycle workflows, and Privileged Identity Management (PIM), and drive the broader IGA strategy.
  • Drive automation of joiner/mover/leaver processes across HRIS (SuccessFactors), Entra, Active Directory, SAP, and downstream SaaS applications, applying least-privilege and zero-trust principles.
  • Define and enforce access certification cadences for privileged, sensitive, and regulated application access, and mature RBAC/ABAC models, conditional access, and least-privilege enforcement enterprise-wide.
  • Lead the IAM response to internal audit, external audit (ITGC), SOX-style controls, NIS 2, GDPR, and cyber insurance requirements, including control design, evidence collection, and remediation.
  • Set priorities across competing operational, audit, and project demands with clear risk-based rationale, and defend those priorities to executive stakeholders.
  • Serve as the escalation point for P1/P2 IAM and SAP Security incidents, including access outages, privilege misuse, and identity-related breach response, in coordination with SOC/MDR and IR partners.
  • Deliver executive-ready updates, business cases, and steering committee materials for the CISO, CIO, CTO, CFO, Internal Audit, and business leadership.
  • Manage vendor and MSP relationships supporting the IAM function, including SOW scoping, performance reviews, and commercial negotiations.
  • Maintain IAM policies, standards, work instructions, RACIs, and reference architectures; ensure they are current, enforced, and audit-defensible.
  • Provide mentorship and technical guidance to IAM, SAP, infrastructure, and application teams on identity, access, and SAP Security best practices.
  • Stay current on threats, regulatory trends, and technologies affecting IAM, IGA, and SAP Security, and evaluate new solutions that support the program’s objectives.

 

 

Work Experience

  • 10+ years of progressive IAM experience in large, multi-entity enterprises, with at least 6 years of hands-on SAP Security at an expert level (ECC and S/4HANA required).
  • 3+ years leading teams, including demonstrated experience managing outsourced or offshore administration teams under formal SLAs.
  • Significant experience designing and operating IAM and identity governance controls at scale, including Microsoft Entra ID, Entra ID Governance, Active Directory, and privileged access management.
  • Proven experience leading IAM and SAP Security audits (ITGC, SOX-style, NIS 2, or equivalent) from planning through remediation.
  • Direct experience integrating authoritative HR sources (such as SAP SuccessFactors) into IAM lifecycle automation for joiner/mover/leaver processes.

 

Education Requirements

  • Bachelor’s Degree in Information Systems, Computer Science, Engineering, or equivalent experience.
  • In lieu of a Bachelor’s Degree, 10+ years of relevant field experience will be considered.
  • Relevant certifications preferred, such as SAP Certified Technology Associate – SAP System Security and Authorizations, CISSP, CISM, CISA, or Microsoft Identity and Access Administrator (SC-300).

 

Essential Capabilities

  • Expert-level SAP Security expertise, including role design, SoD, GRC Access Control (ARA, ARM, BRM, EAM), firefighter access, and SAP audit support across ECC and S/4HANA.
  • Strong working knowledge of Microsoft Entra ID and Entra ID Governance, including entitlement management, access reviews, lifecycle workflows, PIM, and conditional access.
  • Solid understanding of identity and access management, identity governance, privileged access, and zero-trust-aligned architectures across on-prem and cloud environments.
  • Demonstrated ability to lead outsourced administration teams under formal SLAs while maintaining quality, security, and audit-readiness.
  • Strong organization and planning discipline, including roadmaps, capacity plans, RACIs, runbooks, and executive status reporting.
  • Excellent written and verbal executive communication, with the ability to influence CISO, CIO, CFO, Internal Audit, and business leadership.
  • Ability to set and defend priorities across competing operational, audit, and project demands with clear, risk-based rationale.
  • Ability to create clear, concise documentation targeted at IT leadership, business stakeholders, auditors, and technical teams.
  • Strong collaboration and leadership skills, with the ability to drive alignment on identity, access, and SAP Security decisions across cross-functional teams.

 

 

Location of Role

USA Remote, able to work from 8AM to 5PM Eastern Time Zone (USA, Florida), with occasional off-hours support for P1/P2 incidents, audit deadlines, and major project cutovers. West Palm Beach, FL area preferred.

 

 

 

 

 

 

 

We are an equal opportunity employer. We do not discriminate on the basis of race, color, creed, religion, gender, sexual orientation, gender identity, age, national origin, disability, veteran status or any other category protected under federal, state, or local law.  All employment is decided on the basis of qualifications, merit, and business need. 


Nearest Major Market: Palm Beach
Nearest Secondary Market: Miami