Cyber Product Owner - Identity & Access Management (IAM)
Role details
Job location
Tech stack
Job description
As Cyber Product Owner for Identity & Access Management (IAM), you'll play a critical role in ensuring British Airways' authentication and access platforms deliver secure, efficient and user-friendly experiences for colleagues and customers.
This is a hands-on product role. You'll be expected to bring deep practical experience of IAM tooling and the ability to engage confidently on how identity platforms are designed, configured, implemented and operated in real environments. This role requires more than strategy or governance - you'll need to know your tools and how they work in practice.
What you'll do:
- Provide technical cyber leadership across BA's IAM products, including platforms such as Active Directory, Entra ID and multi-factor authentication
- Own the product vision, strategy and roadmaps for IAM, translating business and security needs into clear outcomes and measurable KPIs
- Work hands-on with IAM capabilities, validating implementation approaches, guiding configuration decisions and shaping how tools are used in production
- Assess, implement and promote IAM features that strengthen security, improve user experience and drive adoption
- Create and maintain IAM reference architectures, design patterns and technical guidance
- Lead cyber and security reviews to ensure consistency, quality and alignment to BA security principles
- Act as a subject-matter expert on IAM, supporting delivery assurance and wider cyber initiatives
- Engage with stakeholders to understand operational pain points and continuously improve authentication and authorisation journeys
- Develop and maintain an up-to-date threat model and risk view of the IAM landscape
Requirements
- Strong hands-on experience with enterprise IAM tooling - you can demonstrate practical knowledge of how identity platforms are configured, operated and improved, not just managed at a high level
- Deep understanding of identity, authentication and access management
- Ability to explain complex IAM and security topics clearly to technical and non-technical audiences
- Experience translating security requirements into deliverable product changes
- A structured, analytical approach with confidence balancing security, usability and delivery
- Proactive, pragmatic mindset with a focus on continuous improvement and operational resilience
Your experience:
- Proven experience delivering and operating IAM products in a large or complex environment
- Strong practical experience with identity platforms such as Active Directory and Entra ID, including authentication
- Experience defining IAM strategies and roadmaps and working closely with engineers and suppliers to deliver them
- Track record of improving security posture while enabling business outcomes
- Cybersecurity qualifications or certifications are desirable