Contract : 6 Months - Freelance
Start : ASAP (August)
Role Overview
The GRC & Authorization Consultant is responsible for managing and governing user access, roles, authorizations, and Segregation of Duties (SoD) within an Application Management Services (AMS) environment.
The consultant will work closely with AMS functional and technical teams, business process owners, security teams, service management, and client stakeholders to ensure that authorization-related activities are controlled, traceable, and delivered in line with agreed SLAs.
Key Responsibilities
- Authorization Management within AMS
- Manage and govern application roles, user authorizations, and access-control requirements as part of ongoing AMS support.
- Assess authorization requirements arising from incidents, service requests, change requests, enhancements, and business changes.
- Ensure access is granted according to approved business requirements and the principle of least privilege.
- Review and approve proposed changes to roles and authorization structures in line with agreed governance processes.
- Support the creation, modification, testing, and retirement of roles where required.
- Ensure appropriate documentation and approvals exist before authorization changes are moved into production.
- Work with functional and technical AMS teams to resolve authorization-related issues.
Access Governance & Reviews
- Support periodic user access reviews and access-certification activities.
- Coordinate with business owners to confirm that existing access remains appropriate.
- Identify and remediate obsolete, excessive, duplicate, or conflicting access.
- Support joiner, mover, and leaver processes from an authorization-governance perspective.
- Review privileged and sensitive access within applications supported by the AMS service.
- Ensure temporary and emergency access is appropriately controlled and removed when no longer required.
GRC & Compliance
- Maintain authorization controls in accordance with client security policies and applicable compliance requirements.
- Maintain audit-ready evidence for access requests, approvals, role changes, SoD reviews, and mitigating controls.
- Support internal and external audits relating to user access and logical security.
- Respond to audit findings and coordinate authorization-related remediation actions.
- Maintain relevant GRC documentation, control descriptions, procedures, and operating evidence.
- Ensure AMS processes continue to meet agreed compliance and control standards following application or organisational changes.
The GRC & Authorization Consultant will be responsible for supporting and maintaining:
- User authorization and role-governance processes.
- Segregation of Duties rules and conflict assessments.
- Role and authorization change requests.
- Authorization-related incident and problem resolution.
- Access review and recertification activities.
- Privileged and sensitive-access governance.
- Mitigating and compensating controls.
- Audit and compliance evidence.
- Authorization-related risks and remediation tracking.
- Role design and authorization documentation.
- Operational procedures and support documentation.
- SLA/KPI reporting for authorization-related AMS activities.
Skills & Experience
- Strong experience in GRC, application authorization, Identity & Access Management, or access governance.
- Experience working within an AMS, managed services, or application-support environment.
- Strong understanding of role-based access control and least-privilege principles.
- Strong knowledge of Segregation of Duties controls and risk management.
- Experience analysing and resolving authorization-related incidents and service requests.
- Experience managing role and access changes within controlled change-management processes.
- Experience supporting user access reviews and recertification.
- Experience working with business process owners, functional teams, technical teams, and security stakeholders.
- Understanding of audit requirements relating to logical access and authorization controls.
- Ability to work within defined SLAs, ticketing processes, and service-management procedures.
- Strong analytical, documentation, and stakeholder-management skills.
Role Boundary
The role is specifically responsible for GRC and authorization governance within the AMS service, including roles, access controls, Segregation of Duties, and associated compliance activities.
The role is not intended to own wider GRC activities across the organisation or general application support.