Senior Manager, Identity & Access Management (IAM)
- Type: Contract, initial 6 months with scope to extend
- Rate: Up to £900 Inside IR35
- Location: Bristol or London - 1/2 Days per week onsite
- Reporting to: Head of Information Security (CISO)
- Key stakeholders: C-suite, executive risk and governance forums, external auditors
- Start: ASAP
Overview
One of the UK's largest investment managers is looking for an experienced Identity & Access Management leader to join on a contract basis. Reporting directly to the Head of Information Security (CISO), the Senior Manager will be accountable for all of IAM across the business. They will also be its senior representative with C-suite stakeholders and external auditors.
Identity controls are a significant part of a wider control improvement programme that is closely followed at board level. IAM is also under close, ongoing scrutiny from external auditors. The role has been set at Senior Manager level to reflect this.
The successful candidate will need the credibility and gravitas to lead IAM discussions at executive risk and governance forums. They will need to face off to auditors with confidence. They will also need to give senior leadership an accurate, balanced view of IAM risk and control progress. Alongside this, they will lead the IAM team and set the function's operating model and strategy over the coming years.
The IAM function
The IAM team is responsible for Identity & Access Management across two areas:
- Colleague identity: the identities people use to log on to systems
- Workload identity: the identities systems and applications use to communicate with each other
Its remit covers the identity lifecycle, authentication, authorisation, privileged access management (PAM) and governance. Microsoft Entra ID is the main identity platform, alongside Active Directory.
Key responsibilities
Executive, board and audit engagement:
- Represent IAM at executive risk and governance forums, taking accountability for IAM risk and control positions
- Build strong working relationships with C-suite stakeholders, giving them an accurate, balanced view of IAM risk and escalating issues when needed
- Produce clear reporting on IAM risk, control status and remediation progress for executive committees, and contribute to board-level reporting
- Act as the senior point of contact for external auditors on IAM, managing engagement from planning and evidence requests through to agreeing and closing actions
- Lead IAM's input into the control improvement programme, working with the third-party partners delivering it and the external auditors monitoring its progress
- Make sure commitments made to executives and auditors are delivered, evidenced and sustained
Governance and control:
- Own IAM policies, standards and controls, making sure they meet regulatory and audit expectations
- Drive the uplift of identity controls across colleague and workload identity
- Maintain IAM risk and control metrics that stand up to executive and audit scrutiny
Strategy and operating model:
- Set the multi-year strategy and roadmap for IAM, and secure support for it from the CISO and executive stakeholders
- Define and update the IAM operating model, covering:
- how the function is organised
- roles and responsibilities
- ways of working with the wider technology and security teams
- Assess the maturity of IAM capabilities and lead the work to improve them
IAM services:
- Oversee the identity lifecycle, including joiner, mover and leaver (JML) processes and access reviews
- Own authentication standards, including SSO and MFA
- Lead RBAC modernisation and wider authorisation controls, with a focus on least privilege
- Own the PAM model and the controls around privileged accounts and access
- Oversee workload identity, including service accounts and other non-human identities
Team leadership:
- Lead and develop the IAM team, supporting individual development and career progression
- Review whether the team structure fits the function's needs and lead any restructuring required
- Work closely with the CISO and existing IAM management
Initial focus
Over the initial contract, the main areas of focus are expected to be:
- Taking ownership of IAM engagement with external auditors and at executive risk and governance forums
- Building an evidence-based view of the current state of IAM controls and the improvement work underway
- Setting up regular IAM reporting for executive and board-level audiences
- Reviewing the team structure and operating model, and setting out any changes needed
- Providing leadership and direction for the IAM team
Skills and experience
Executive, board and audit engagement:
- Experience representing a technology or security function at executive risk and governance forums
- Experience working with C-suite stakeholders, including explaining complex technical risk clearly to non-technical senior audiences
- Background in programmes with board-level visibility, including contributing to board-level reporting
- Confident facing off to external auditors, including managing audit engagement, evidence and remediation actions
- The gravitas to hold their ground with senior executives and auditors, and to escalat risk appropriately
Leadership and operating model:
- Experience leading IAM in a heavily regulated environment with high levels of audit and risk scrutiny
- Experience of operating model updates, maturity work and team restructuring
- Experience leading and developing teams
Technical knowledge:
- Strong understanding of identity architectures, SSO, MFA and PAM models
- Working knowledge of Microsoft Entra ID and Active Directory
- Good understanding of identity governance, including JML processes, access reviews and RBAC
- Understanding of workload identity and how system-to-system access is secured
Regulatory knowledge:
- Knowledge of DORA, ISO 27001 and NIST, and how they translate into IAM control requirements
- Experience demonstrating compliance with regulatory control expectations to auditors and senior stakeholders
- Experience with One Identity or CyberArk would be useful. A strong grasp of core IAM concepts matters more than specific tooling.