
Access Controls Manager
- London
- Permanent
- Full-time
- Design and enforce access controls to ensure compliance with key group policies, including the Identity and Access Management policy, to enforce the Principle of Least Privilege and ensure access risks are kept to a minimum
- Support and implement robust access controls for our technology landscapes, including on-premise and cloud applications
- Understand and review segregation of duties requirements and embed them in security role designs
- Drive segregation of duties assessments for role changes and new developments
- Maintain and enhance segregation of duties rulesets, collaborating with technical specialists to manage ruleset updates
- Support configuration and implementation of access governance tools for access risk management
- Assess risks, conduct root cause analysis, and implement good practice solutions for access control issues
- Provide 1st line support to internal and external partners during review of access management controls
- Responsibility for operating the user access reviews process across in-scope Technology Applications
- Troubleshoot and resolve security issues quickly and efficiently
- Provide regular updates on assigned tasks and highlight any issues/dependencies
- Support security requirements gathering and evaluation for in-scope applications
- Responsibility for producing documentation for access controls including the approach taken, role design matrices (where applicable) and access control procedures
- Responsibility for maintaining the access controls library in the internal controls management system for in-scope applications
- Prepare training content where applicable and support knowledge transition activities
- Be a trusted guide for other internal teams in designing effective access control
- Strong, robust, and consistent access controls operation across in-scope applications
- Continued reduction in user access management related incidents
- Positive audit results and a continued reduction in control deficiencies
- Effective stakeholder management and collaboration across teams
- Ability to understand and review segregation of duties reports and remediate risks from roles and role assignments
- Understanding of authorization concepts and good practices with hands-on experience
- Practical knowledge of General IT controls and security principles, particularly in access controls but also including change management procedures
- Good understanding of business processes and key risk areas, and how access management controls play a part in mitigating these
- Good understanding of access governance tools and technologies
- Minimum of 3 years of related work experience in a multi-national company
- Excellent verbal and written communication skills
- Ability to work autonomously under pressure and tight deadlines while maintaining professionalism
- Proficient in Microsoft Office applications
- Professional certifications such as CISA, CRISC, CISSP, CISM, or other relevant security certifications
- Experience in a multi-tiered organisation with a deep understanding of how technology is applied across different levels
- Experience with SAP GRC Access Control or similar access management tools
- Experience using AuditBoard for internal controls management
- Freedom & flexibility: colleagues rate us highly for the flexibility and trust they receive and most of us balance time in the office with time working remotely
- Great community: a welcoming culture with in-person and online social events, our fantastic Walk the World charity day and active diversity and inclusion networks •
- Broader impact: take up to four days per year to volunteer, with charity match funding available too.
- Career opportunity: the opportunity to develop your career with bespoke training and learning, mentoring platforms and on-demand access to thousands of courses on LinkedIn Learning. When it's time for the next step, we encourage and support internal job moves.
- Time out: 25 days annual leave, rising to 27 days after two years, plus a birthday leave day and the chance to work from (almost!) anywhere for up to four weeks a year
- A flexible range of personal benefits to choose from, plus company funded private medical cover
- A ShareMatch scheme that allows you to become an Informa shareholder with free matching shares
- Strong wellbeing support through EAP assistance, mental health first aiders, a healthy living subsidy, access to health apps and more
- Recognition for great work, with global awards and kudos programmes
- As an international company, the chance to collaborate with teams around the world