Responsibilities
- Own the full identity service catalogue, including joiner, mover, and leaver processing, access requests, entitlement and group administration, privileged account issuance, certificate services, and application onboarding, along with the associated service level commitments.
- Define the engineering and operations roadmap and serve as the technical design authority for core identity platforms: Entra ID with hybrid directory services, Okta, identity governance and administration, privileged access management, PKI and certificate lifecycle, federation and single sign-on, and modern authentication.
- Manage operational disciplines for identity services, including incident and problem management for outages, change control, capacity and availability planning, and a documented escalation and on-call model that operates across time zones.
- Design, implement, and maintain IAM policies, procedures, and standards to ensure the confidentiality, integrity, and availability of sensitive data and resources.
- Lead and manage a team of 1-3 identity engineers and analysts, building coverage so that every platform has more than one engineer in more than one region who can safely operate it.
- Drive reduction of standing privileges across the estate by running access certification and recertification cycles, enforcing segregation of duties and least privilege, eliminating orphaned and dormant accounts, and applying the same lifecycle discipline to service, workload, and other non-human identities as to people.
- Act as identity manager, working with the team to support internal audit, external audit, and client or scheme assessments including SWIFT CSP, by producing evidence on request, owning remediation actions, and closing findings to agreed dates.
- Automate routine service tasks such as provisioning and deprovisioning driven from authoritative HR sources, policy and role-based entitlement instead of ticket-by-ticket approval, and instrumented reporting so identity risk is visible without manual data pulls.
- Own identity data quality and metrics, including account ownership, lifecycle state, entitlement mapping, and application registration, as the foundation for every downstream control, report, and detection.
- Lead directory and tenant consolidation and legacy platform decommissioning, including absorbing acquired identity estates onto the strategic Entra ID and Okta platforms, working directly with application teams that depend on those platforms rather than routing every migration through the identity team.
- Collaborate with cross-functional teams including security architecture, security operations, enterprise IT, HR, compliance, and the business to assess IAM requirements and develop solutions that meet business needs.
- Manage external partners and vendors against their commitments, and contribute to forecasting and planning for identity licensing, tooling, and headcount.
- Maintain IAM process documentation, including end-user guidance, runbooks, and team processes and procedures, to a standard that allows work to move between regions without loss.
Requirements
- 10+ years of overall professional experience, including at least 6 years in identity and access management and 3+ years leading and directly managing an IAM team, with accountability for both a production service and an engineering backlog; experience in financial services is a plus.
- Proven experience designing, implementing, and managing complex IAM processes and solutions within large organizations.
- Deep, current, hands-on knowledge of both core platforms: Microsoft Entra ID and Active Directory in a hybrid estate (tenant and forest design, synchronization, conditional access, privileged role management, and entitlement models) and Okta (policy architecture, authentication journeys, application integration, lifecycle management, and federation at scale).
- Production delivery experience across at least three of: identity governance and administration tooling, privileged access management such as CyberArk, PKI and certificate lifecycle management, federation and single sign-on, and multi-factor or passwordless authentication.
- Knowledge and implementation of key security concepts such as RBAC, zero trust, identity lifecycle automation, least privilege, and identity governance, along with command of underlying protocols SAML 2.0, OIDC, OAuth 2.0, SCIM, Kerberos, and LDAP.
- Automation and scripting ability sufficient to lead engineers credibly, for example with PowerShell, Microsoft Graph, and Okta management APIs, and practical use of source control, pipelines, and configuration-as-code applied to identity change.
- Demonstrated operational management discipline including service level definition and reporting, incident, problem, and change management, and oversight of vendors or managed service providers.
- Direct experience owning identity controls through audit, including preparing evidence, defending design decisions to auditors or regulators, and closing findings.
- Understanding of a broad range of general information security domains, including networking, cybersecurity, governance and risk, and cloud.
- Strong leadership skills with a track record of successfully leading distributed and cross-functional teams across time zones, including offshore or GCC-based staff.
- Excellent communication and interpersonal skills to effectively collaborate with technical and non-technical stakeholders.
Work Arrangement
Hybrid — India, UK, US, Latam
Team
Team distributed across UK, US and Latam locations; participation in an escalation and on-call rotation should be expected.
Other
- 4 days' work from office
- Working hours aligned to India business hours, with overlap into CET / BST.
- Team distributed across UK, US and Latam locations; participation in an escalation and on-call rotation should be expected.
- Travel requirements, for leadership meetings and conferences.