30 jul
|
PVH (Tommy Hilfiger/Calvin Klein)
|
Madrid
30 jul
PVH (Tommy Hilfiger/Calvin Klein)
Madrid
We are looking for an IAM and Access Control Lead to drive the identity strategy and operational excellence of Nexthink's corporate identity perimeter. This role leads a small team of senior engineers responsible for the platforms, policies and engineering standards that govern how every employee, contractor, service account and non-human identity gains, uses, and loses access across Nexthink's corporate environment.
You will partner with the CISO function on policy and standards, and with IT on operational delivery, owning the engineering execution end to end.
Key Responsibilities
IAM Governance & Strategy
- Define and own the IAM governance model - principles, standards, decision rights, and operating cadence -as the durable internal foundation for the program.
- Develop and maintain the multi-year IAM roadmap, sequencing capability build against business risk and investor expectations.
- Establish the application prioritization and SaaS onboarding strategy: which systems are governed first, to what standard, and on what timeline.
- Define role-based access control (RBAC) governance standards and the target access model across the corporate estate.
- Scope, commission, and steer external specialist engagements (e.g. role mining, access-model optimization), retaining internal ownership of outcomes and standards.
Access Reviews & Certification
- Design and operate the enterprise access review and certification framework - periodic, risk-based, and fully evidenced.
- Run recurring access certifications across in-scope applications with documented, audit-ready evidence trails.
- Establish and operate quarterly privileged access reviews; drive standing admin toward zero for all in-scope environments.
Business Application Access & Segregation of Duties
- Establish access governance over core business applications - Workday, NetSuite,
and Salesforce - in partnership with the application owners.
- Lead Segregation of Duties (SoD) analysis: define the conflict ruleset, identify and remediate SoD conflicts, and operate ongoing monitoring.
- Support SOX, ISO 27001, and SOC 2 audit readiness with documented controls, evidence, and remediation tracking; serve as IAM's primary interface to Internal Audit.
- Lead NetSuite role design and Salesforce permission rationalization to align entitlements with least privilege and clean role definitions.
Identity Platform Operations
- Own the engineering standards and roadmap for Microsoft Entra ID and Okta.
- Define and enforce SSO standards across the SaaS estate, including SAML/OIDC integrations and SCIM provisioning.
- Drive passwordless and non-phishable MFA adoption across all employee and privileged access scenarios.
Privileged Access & Just-In-Time Admin
- Design and operationalise Just-In-Time admin access (Intune, Entra PIM, Okta privileged access).
- Act as the technical escalation point for IAM incidents and high-severity access requests.
Non-Human Identity (NHI) Governance
- Build and operate the inventory of service accounts, API keys, OAuth applications, and machine identities.
- Define ownership, rotation, and deprovisioning standards for every NHI; eliminate orphaned and over-privileged service accounts across SaaS, GitHub, and cloud IAM.
Primary Metrics
- Access certification completion rate and cycle timeliness
- SoD conflicts identified vs. remediated (and open-conflict ageing)
- SaaS estate onboarding coverage against the governance roadmap
- SSO coverage across the SaaS estate; MFA exception rate
- Privileged access SLA and standing-admin count
- Orphaned account count; NHI owner coverage
Requirements
- 8+ years in identity and access management, including 2+ years leading IAM governance, strategy, or a senior technical IAM function.
- Demonstrable track record designing and operating access governance - access reviews/certification, RBAC models, and entitlement rationalisation at enterprise scale.
- Hands-on experience with Segregation of Duties and access governance over business applications such as Workday, NetSuite, or Salesforce.
- Operational expertise in Microsoft Entra ID and Okta - Conditional Access, federation, SCIM, OIDC/SAML.
- Experience with privileged access tooling (Entra PIM, Okta privileged access, JIT admin) and a record of reducing standing admin and orphaned accounts.
- Experience with non-human identity governance - service accounts, OAuth apps, secrets management.
- Compliance and audit fluency: ISO 27001, SOC 2, or SOX - able to design controls and produce audit-ready evidence.
- Ability to communicate governance and technical decisions clearly to senior business stakeholders, Finance, and Internal Audit. Fluent English.
- Fluent English.
We are the pioneers and trailblazers of a general IT Market Category (DEX) that is shaping the future of how the world works, giving our customers' IT Teams total digital visibility across their enterprise. Our innovative solutions integrate real-time analytics, automation, and employee feedback across all endpoints. This enables our IT teams to solve complex t
#J-18808-Ljbffr
📌 Senior IAM Lead (Madrid)
🏢 PVH (Tommy Hilfiger/Calvin Klein)
📍 Madrid