Manager of Identity Access Management (IAM)
About the Team
Technology Services team is responsible for developing and maintaining the bank's technology infrastructure, software systems, and applications. This team works closely with other business units in the bank to ensure that the technology systems are aligned with the bank's strategic goals and objectives. Currently, the Technology Services team is undergoing a transformation program aimed at improving the efficiency and effectiveness of its operations. The program involves a review of the team's processes, systems, and organizational structure with the goal of identifying areas for improvement and implementing best practices. The transformation program is also aimed at increasing the team's agility and responsiveness to changes in the business environment. This will enable the team to better meet the changing needs of the bank's customers and adapt to new technologies and emerging trends in the financial services industry. Overall, the Technology Services team plays a critical role in enabling the bank to provide high-quality services to its customers and remain competitive in a rapidly evolving market. The transformation program is an important step in ensuring that the team is well-positioned to meet the bank's current and future needs.
Primary Functions:
The Head of End User Computing and Identity Access Management (EUC & IAM) will be responsible for overseeing and managing the organization's identity and access management program. The primary focus will be on developing and implementing strategies, policies, and procedures to ensure the secure and efficient management of user identities and their access privileges across various systems, applications, and resources.
Duties and Responsibilities
Strategy and Planning:
o Develop and execute an IAM strategy aligned with the organization's overall security and compliance objectives.
o Collaborate with key stakeholders to define and implement IAM policies, standards, and procedures.
o Stay updated on industry best practices, emerging technologies, and regulatory requirements related to IAM.
IAM System Implementation and Management:
o Lead the selection, implementation, and maintenance of IAM systems, tools, and technologies.
o Design and manage the overall IAM architecture, ensuring scalability, flexibility, and resilience.
o Oversee user provisioning, deprovisioning, and access recertification processes.
o Implement and enforce strong authentication and authorization mechanisms.
Identity Lifecycle Management:
o Define and maintain identity lifecycle processes, including user onboarding, role changes, and offboarding.
o Develop and enforce user provisioning and deprovisioning workflows.
o Implement and maintain automated processes for identity synchronization and attribute management.
Access Control and Privilege Management:
o Develop and enforce access control policies based on the principle of least privilege.
o Implement role-based access control (RBAC) and entitlement management mechanisms.
o Conduct periodic access reviews and audits to ensure compliance and detect potential risks.
Security and Risk Management:
o Identify and assess IAM-related risks and vulnerabilities and develop appropriate mitigation strategies.
o Collaborate with the security team to monitor and respond to security incidents related to IAM.
o Establish and maintain strong relationships with internal audit teams and regulatory bodies.
Team Management and Leadership:
o Lead and mentor a team of IAM professionals, providing guidance, training, and performance evaluations.
o Foster a culture of collaboration, innovation, and continuous improvement within the IAM team.
o Coordinate with other IT and security teams to ensure seamless integration and alignment of IAM practices.
Qualification
Bachelor’s Degree in Information Technology or any related field
Years of Experience
15 years working experience
Specific Skills / Knowledge and Certification Required
Extensive experience in identity access management, with a focus on design, implementation, and management of IAM systems with at least 5 years in a leadership role.
Strong knowledge of IAM principles, standards, and frameworks (e.g., ISO/IEC 27001, NIST Cybersecurity Framework).
Familiarity with IAM technologies, such as identity governance and administration (IGA), single sign-on (SSO), and multi-factor authentication (MFA).
Proficiency in IAM-related protocols and standards (e.g., SAML, OAuth, OpenID Connect).
Experience with IAM solutions from major vendors (e.g., Oracle, Microsoft, SailPoint, Okta).
Solid understanding of security principles and best practices.
Excellent leadership, communication, and stakeholder management skills.
Industry certifications like CISSP, CISM, or CISA are desirable.