Senior Manager - Identify & Access Management

Hargreaves Lansdown
Bristol, UK
11 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Active Directory Cloud Computing Cyber Security Identity and Access Management OpenID Role-Based Access Control Azure Active Directory Security Assertion Markup Language (SAML) IT General Controls (ITGC) Cyberark Sentry

Job description

As the Senior Manager - Identity & Access Management you will own the strategy, transformation and continuous maturity of HL’s Identity and Access Management (IAM) capability for colleague and workload identities - spanning identity lifecycle, authentication, authorisation, Privileged Access Management (PAM) and Identity Governance & Administration (IGA).

The role elevates IAM as a strategic control, sets the direction and standards adopted across engineering and platform teams, drives a multi-year transformation programme, and provides executive-level representation to internal committees, external audit and regulators - ensuring HL’s IAM capability is resilient, regulator-ready and enabling of secure, efficient access at scale.

What you will be doing

  • Own the multi-year IAM, PAM and IGA strategy, target operating model and capability maturity roadmap for colleague and workload identities, developed in partnership with Security Architecture and Cyber Defence.
  • Lead the transformation of HL’s IAM capability, driving material uplift in automation, self-service, joiner-mover-leaver reengineering, RBAC modernisation, PAM control effectiveness and identity governance maturity.
  • Set and steward the enterprise IAM standards, patterns and policies adopted across engineering and platform teams - ensuring least privilege, zero-trust identity principles and segregation of duties are consistently embedded by design.
  • Own privileged access strategy and outcomes, including vaulting, session isolation, credential rotation and Just-in-Time / Just-Enough-Access controls - with day-to-day PAM operation delegated to specialist team leads.
  • Own the access governance strategy - including recertification cadence, role modelling, entitlement definitions and exception handling - retaining accountability for outcomes and regulatory evidence while delegating execution.
  • Represent IAM at executive, risk and governance forums and act as HL’s principal IAM interface to external audit and regulators on Identity-related matters.
  • Own the IAM investment case, vendor strategy and multi-year budget, ensuring spend, tooling and partner choices deliver measurable capability, control and efficiency outcomes.
  • Influence and drive change across senior engineering, platform and product leaders to embed IAM standards and secure-by-design identity outcomes at pace and scale
  • Lead, develop and retain a high-performing IAM team, owning the capability’s talent strategy, succession planning and continuous uplift of technical and delivery skills at senior levels.
  • Report on IAM performance, control effectiveness and transformation outcomes through clear KRIs, KPIs and management information tailored for engineering, executive, risk and regulatory audiences.

Requirements

  • Extensive senior leadership track record in Identity & Access Management, Privileged Access Management and Identity Governance & Administration, gained in a complex, regulated environment (financial services strongly preferred).
  • Demonstrable experience leading a multi-year IAM/PAM/IGA transformation programme end-to-end, including target operating model design, tooling modernisation and measurable maturity uplift.
  • Deep working knowledge of enterprise IAM platforms (e.g. OneIdentity) and PAM platforms (e.g. CyberArk Privilege Cloud) - including operating models, integration patterns and control outcomes.
  • Strong grasp of modern authentication and authorisation architectures - including SSO, MFA, OIDC/SAML, RBAC, ABAC and workload identity federation across Microsoft Entra ID, Active Directory and AWS IAM.
  • Executive presence and comfort operating at senior committee level - including presenting IAM strategy, control effectiveness and remediation to executive committees, board risk committees, external audit and regulators.
  • Practical knowledge of relevant regulatory and control expectations impacting identity controls, including FCA/PRA Operational Resilience, DORA, ICO expectations, ITGC scrutiny, ISO 27001 and NIST CSF.
  • Proven ability to influence senior engineering, platform and product leaders to drive change and adoption of enterprise standards without direct authority - building consensus at scale across a complex delivery landscape.
  • Demonstrable experience owning multi-year IAM investment cases, vendor strategy and budget - with a track record of translating capability ambition into commercial outcomes.
  • Strong people leadership credentials, including building, developing and retaining senior IAM/PAM talent, and creating career pathways within a technical capability.
  • Excellent written and verbal communication skills, with the ability to translate complex identity concepts for engineering, product, risk and executive audiences.
  • Advanced security or IAM certifications expected (e.g. CISSP, CISM, CIDPRO, CyberArk Sentry, Microsoft SC-300) - reflecting the strategic control nature of the role.

Benefits & conditions

Based in Bristol head office, BS2 0TR. This role is permanent, full time, 37.5 hours per week, Monday to Friday. We offer a hybrid flex working pattern with a minimum of 2 days in the office per week., * Discretionary annual bonus* and annual pay review

  • 25 days* holiday plus bank holidays and 1-day additional Christmas closure
  • Option to purchase an additional 5 days holiday**
  • Flexible working options available, including hybrid working
  • Enhanced parental leave
  • Pension scheme up to 11% employer contribution
  • Income Protection and Life insurance (4 x salary core level of cover)
  • Private medical insurance*
  • Health care cash plans - including optical, dental, and outpatient care
  • Health screening programme
  • Help@hand - confidential support including mental health counselling and remote GP
  • Wellhub - unlimited access to fitness providers and wellness coach sessions
  • Variety of travel to work schemes with bike storage and shower facilities
  • Inhouse barista and deli serving subsidised coffee and sandwiches
  • Two paid volunteering days per year

  • dependant on role level

** only available to select during our annual benefits window, in November each year

About the company

Here at HL, we’re the UK’s number 1 investment platform for private investors, based in Bristol. For more than 40 years we’ve helped investors save time, tax and money on their investments.

To achieve our mission, we believe we have a workplace like no other, with constant learning, dynamic teams, and a great ethos. We’re steered by core values that promote service, quality, innovation, and opportunity in everything we do.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:22 min

Overview of the Sentry error and performance monitoring platform

Priscila Oliveira · World Congress 2023

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · World Congress 2023

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

3:21 min

Installing and configuring the Sentry JavaScript SDK for applications

Priscila Oliveira · World Congress 2023

Videos

See all

Related articles

See all