JobMatch
← Back to jobs

IAM Transformation Lead

N-iX

European Unionlead
Posted
today
Source
N-iX (greenhouse)

Skills

Stakeholder ManagementOnboardingSecurity

Description

A multi-company group is building its IAM capability across several portfolio companies, each with its own IT function. The governance framework, the target operating model and the IAM control set are designed, and selection of an IGA platform is in the last stages of an RFP. This role takes that foundation and turns it into something that operates: a platform in production, applications onboarded, roles defined, and controls producing evidence on a cadence. It is a build role in a federated group, not the stewardship of an established function. The person joining inherits a programme in motion, with the design work done and the delivery ahead of them. How the role operates The function is new and has no precedent to inherit. There is no IAM function above this role to escalate into, and for most decisions there is no prior ruling to point at. The role sets its own agenda, brings its own proposals to the forums it runs. The role leads a project team of two IAM business analysts and three IAM integration engineers. It is not a solo role, but it is the only role accountable for the outcome. The holder sets the team’s direction and priorities and carries the programme themselves, with no programme manager or PMO between them and delivery. Purpose of the role Own the IAM Target Operating Model end to end, from governance framework and control design through to delivery of the IAM platform and its adoption across the portfolio companies. Lead the IAM project team. Accountable for the group IAM maturity position and for the regulatory and internal compliance behind it. Key responsibilities Leading the team • Lead a project team of two IAM business analysts and three IAM integration engineers, setting direction, priorities and the expected standard of work. • Allocate the team across governance workstreams and platform integration, and rebalance as the programme moves from design into delivery. • Build the team’s capability in a function where most practices are being established for the first time. • Hold the implementation partner and any managed services to the same standard as the internal team. Programme delivery and IAM platform • Set the IAM programme agenda and bring proposals and decisions to the governance forums, rather than waiting for direction. • Own delivery of the IAM platform implementation: scope, plan, milestones, budget and dependencies, with no PMO to carry them. • Direct the implementation partner and managed services alongside the internal integration capacity. • Translate IAM requirements into platform configuration, and own the decisions where the two do not match. • Own application onboarding across the in-scope portfolio: sequencing, connector delivery, testing and cutover. • Own the commercial relationship after signature, including licence metric, identity counts, true-ups and change control. • Report delivery progress, risks and decisions to the steering committee and to executive stakeholders. Governance, policy and operating model • Own and maintain the IAM policies, standards and procedures. • Own the IAM Target Operating Model across process, tooling and organisation. • Define IAM decision rights, accountabilities and escalation paths, and keep them current as the function grows. • Ensure alignment with regulatory and internal requirements, including ISO 27001 and DORA. Risk, control and compliance • Own the IAM control set: control objectives, design, execution cadence and evidence model. • Move the controls from design into operation, and from Test of Design through to Test of Effectiveness. • Own the IAM risk register and exception management. • Coordinate IAM audits and regulatory reviews. • Own the group IAM maturity position against the parent company’s IAM maturity framework, including the annual self-assessment and the agreed maturity trajectory. • Define and track IAM KPIs and maturity metrics. Portfolio company engagement • Secure adoption of the group IAM operating model across the portfolio companies, each with its own IT function and its own priorities. • Get IAM domain owners, business owners and application owners named, and keep them engaged in reviews, approvals and authorization concepts. • Work with HR, service desk and infrastructure teams in each company on the joiner, mover and leaver process and the data behind it. • Operate through influence rather than line authority across company boundaries. Role and access model • Own the business role model: design principles, taxonomy, eligibility and lifecycle. • Own authorization concepts across the in-scope applications, and the application criticality and entitlement risk classification behind them. • Own segregation of duties: rule design, conflict analysis and exception handling. Oversight and reporting • Approve deviations and exceptions to IAM standards. • Provide guidance to the portfolio companies and application owners. • Report IAM posture, risk and progress to senior management and to the parent company. What success looks like in the first twelve months • The IAM platform is in production, with the first wave of applications connected. • The Priority controls are operating on their defined cadence and producing evidence. • Authorization concepts are approved across the in-scope application portfolio. • IAM domain owners are named and active in every portfolio company. • The group maturity position has reached the agreed target. • The programme plan for the following year is set, funded and agreed with the steering committee, on the holder’s own proposal. Required experience and expertise • 8+ years in IAM, information security, governance or risk, with at least 2 years in a lead or ownership role. • Evidence of having built an IAM or control function where one did not exist, rather than taking over one that was already running. • Delivery of at least one IGA platform implementation end to end, including vendor and implementation partner management. • Experience leading a mixed team of analysts and engineers, setting priorities across governance and technical delivery at the same time. • Able to run the programme as its own project manager: plan, milestones, budget, risks and steering, with no PMO behind them. • Able to get decisions out of senior stakeholders who do not report to them, and to keep those decisions made. • Deep working knowledge of IAM: joiner, mover and leaver, role and entitlement design, segregation of duties, access reviews and privileged access. • Experience operating in complex, federated or multi-entity organisations, where adoption is negotiated rather than mandated. • Comfortable working directly with access data: able to take a large directory or application extract and turn it. into a finding or a role model without waiting for someone else to analyse it. • Experience with regulatory and control frameworks, and with audit and evidence expectations. • Proven stakeholder management at executive level, and the ability to put IAM risk in business terms. • Languages: English mandatory, Spanish and German are a plus. Desirable • Experience reporting into a parent company against a defined maturity framework. • Microsoft Entra ID and Active Directory at multi-tenant or multi-forest scale. • HR-driven identity lifecycle from an HCM platform. • Privileged access management implementation experience. We offer*: - Flexible working format - remote, office-based or flexible - A competitive salary and good compensation package - Personalized career growth - Professional development tools (mentorship program, tech talks and trainings, centers of excellence, and more) - Active tech communities with regular knowledge sharing - Education reimbursement - Memorable anniversary presents - Corporate events and team buildings - Other location-specific benefits *not applicable for freelancers

JobMatch aggregates public listings. Always apply through the original posting.