Head of Information Security

Sanderson

Greater London

Hybrid

GBP 32,288,000 - 41,513,000

Full time

19 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sanderson seeks a Senior Manager in Identity & Access Management (IAM) on a contract basis (initial 6 months) to lead IAM across the business. You will report to the Head of Information Security and engage with C-suite stakeholders and external auditors.

You will shape IAM strategy, operating model, and team, covering lifecycle, SSO, MFA, RBAC, PAM and workload identities using Entra ID and Active Directory.

Qualifications

  • Experience representing a technology or security function at executive risk and governance forums.
  • Ability to explain complex technical risk clearly to non-technical senior audiences.
  • Background in programmes with board-level visibility and reporting.
  • Confident facing external auditors, managing audit engagement and remediation actions.
  • Gravitas to engage with senior executives and auditors and escalate risk appropriately.

Responsibilities

  • Executive, board and audit engagement: represent IAM at risk and governance forums and manage audit engagement.
  • Governance and control: own IAM policies and controls meeting regulatory expectations.
  • Strategy and operating model: set IAM strategy and define operating model incl. org, roles, ways of working.
  • IAM services: oversee lifecycle, authentication standards, RBAC and PAM, workload identity.
  • Team leadership: lead and develop the IAM team and adjust structure as needed.
  • Initial focus: engage with external auditors, build evidence-based IAM state, report to execs and board.

Skills

Executive liaison
Audit engagement
Stakeholder mgmt
IAM strategy
Leadership
Risk governance
Regulatory knowledge
Identity architectures
Entra ID
Active Directory
RBAC
PAM
SSO
MFA
JML

Tools

Microsoft Entra ID
Active Directory

Job description

Senior Manager, Identity & Access Management (IAM)
  • Type: Contract, initial 6 months with scope to extend
  • Rate: Up to £900 Inside IR35
  • Location: Bristol or London - 1/2 Days per week onsite
  • Reporting to: Head of Information Security (CISO)
  • Key stakeholders: C-suite, executive risk and governance forums, external auditors
  • Start: ASAP
Overview

One of the UK's largest investment managers is looking for an experienced Identity & Access Management leader to join on a contract basis. Reporting directly to the Head of Information Security (CISO), the Senior Manager will be accountable for all of IAM across the business. They will also be its senior representative with C-suite stakeholders and external auditors.

Identity controls are a significant part of a wider control improvement programme that is closely followed at board level. IAM is also under close, ongoing scrutiny from external auditors. The role has been set at Senior Manager level to reflect this.

The successful candidate will need the credibility and gravitas to lead IAM discussions at executive risk and governance forums. They will need to face off to auditors with confidence. They will also need to give senior leadership an accurate, balanced view of IAM risk and control progress. Alongside this, they will lead the IAM team and set the function's operating model and strategy over the coming years.

The IAM function

The IAM team is responsible for Identity & Access Management across two areas:

  • Colleague identity: the identities people use to log on to systems
  • Workload identity: the identities systems and applications use to communicate with each other

Its remit covers the identity lifecycle, authentication, authorisation, privileged access management (PAM) and governance. Microsoft Entra ID is the main identity platform, alongside Active Directory.

Key responsibilities

Executive, board and audit engagement:

  • Represent IAM at executive risk and governance forums, taking accountability for IAM risk and control positions
  • Build strong working relationships with C-suite stakeholders, giving them an accurate, balanced view of IAM risk and escalating issues when needed
  • Produce clear reporting on IAM risk, control status and remediation progress for executive committees, and contribute to board-level reporting
  • Act as the senior point of contact for external auditors on IAM, managing engagement from planning and evidence requests through to agreeing and closing actions
  • Lead IAM's input into the control improvement programme, working with the third-party partners delivering it and the external auditors monitoring its progress
  • Make sure commitments made to executives and auditors are delivered, evidenced and sustained

Governance and control:

  • Own IAM policies, standards and controls, making sure they meet regulatory and audit expectations
  • Drive the uplift of identity controls across colleague and workload identity
  • Maintain IAM risk and control metrics that stand up to executive and audit scrutiny

Strategy and operating model:

  • Set the multi-year strategy and roadmap for IAM, and secure support for it from the CISO and executive stakeholders
  • Define and update the IAM operating model, covering:
  • how the function is organised
  • roles and responsibilities
  • ways of working with the wider technology and security teams
  • Assess the maturity of IAM capabilities and lead the work to improve them

IAM services:

  • Oversee the identity lifecycle, including joiner, mover and leaver (JML) processes and access reviews
  • Own authentication standards, including SSO and MFA
  • Lead RBAC modernisation and wider authorisation controls, with a focus on least privilege
  • Own the PAM model and the controls around privileged accounts and access
  • Oversee workload identity, including service accounts and other non-human identities

Team leadership:

  • Lead and develop the IAM team, supporting individual development and career progression
  • Review whether the team structure fits the function's needs and lead any restructuring required
  • Work closely with the CISO and existing IAM management
Initial focus

Over the initial contract, the main areas of focus are expected to be:

  • Taking ownership of IAM engagement with external auditors and at executive risk and governance forums
  • Building an evidence-based view of the current state of IAM controls and the improvement work underway
  • Setting up regular IAM reporting for executive and board-level audiences
  • Reviewing the team structure and operating model, and setting out any changes needed
  • Providing leadership and direction for the IAM team
Skills and experience

Executive, board and audit engagement:

  • Experience representing a technology or security function at executive risk and governance forums
  • Experience working with C-suite stakeholders, including explaining complex technical risk clearly to non-technical senior audiences
  • Background in programmes with board-level visibility, including contributing to board-level reporting
  • Confident facing off to external auditors, including managing audit engagement, evidence and remediation actions
  • The gravitas to hold their ground with senior executives and auditors, and to escalat risk appropriately

Leadership and operating model:

  • Experience leading IAM in a heavily regulated environment with high levels of audit and risk scrutiny
  • Experience of operating model updates, maturity work and team restructuring
  • Experience leading and developing teams

Technical knowledge:

  • Strong understanding of identity architectures, SSO, MFA and PAM models
  • Working knowledge of Microsoft Entra ID and Active Directory
  • Good understanding of identity governance, including JML processes, access reviews and RBAC
  • Understanding of workload identity and how system-to-system access is secured

Regulatory knowledge:

  • Knowledge of DORA, ISO 27001 and NIST, and how they translate into IAM control requirements
  • Experience demonstrating compliance with regulatory control expectations to auditors and senior stakeholders
  • Experience with One Identity or CyberArk would be useful. A strong grasp of core IAM concepts matters more than specific tooling.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity And Access Manager, Security
Identity And Access Manager, Security

FDO Consulting • Greater London

Hybrid
GBP 75,000 - 85,000
Bonus
Benefits
Identity And Access Manager, PAM, Security
Identity And Access Manager, PAM, Security

FDO Consulting • Slough

Hybrid
GBP 70,000 - 85,000
Identity & Access Management Workstream Lead (IAM/IDAM)
Identity & Access Management Workstream Lead (IAM/IDAM)

TEC Partners Limited • Greater London

Hybrid
GBP 33,579,000 - 34,778,000
IAM Integration & Remediation Lead
IAM Integration & Remediation Lead

Exceed Cyber limited • Greater London

Hybrid
GBP 180,000 - 234,000
Identity and Access Management Lead
Identity and Access Management Lead

Medical Protection Society • Leeds

On-site
GBP 56,000 - 71,000
Discretionary bonus 10-20%
11% pension contribution
25 days annual leave
+6
Identity and Access Management (IAM) Security Engineer
Identity and Access Management (IAM) Security Engineer

Dianaduggan • Greater London

Hybrid
GBP 110,000 - 130,000
Umbrella pay framework
IAM Technical Lead
IAM Technical Lead

GCS Recruitment • Deepcar

On-site
GBP 90,000 - 130,000
Identity Access Management Architect Engineer Cyber Consulting
Identity Access Management Architect Engineer Cyber Consulting

Oliver James Associates Ltd. • Greater London

Hybrid
GBP 80,000 - 120,000
Flexible benefits packages
Car allowances
Bonuses
+1
Identity Management Consultant
Identity Management Consultant

Eames Consulting • Greater London

Hybrid
GBP 70,000 - 110,000
Identity Management Consultant
Identity Management Consultant

Spencer Rose • Bristol

On-site
GBP 80,000 - 95,000