
Senior Identity and Access Control Lead
- Cambridge
- Permanent
- Full-time
- Lead execution of identity lifecycle processes including user provisioning, de-provisioning, and Joiner-Mover-Leaver (JML) workflows
- Enforce role-based access control (RBAC), segregation of duties (SoD), and provisioning standards across enterprise systems
- Coordinate periodic access reviews, privileged access monitoring, and emergency/firefighter access governance
- Maintain audit-ready documentation and demonstrate operational effectiveness of access control processes
- Collaborate with application owners, control stakeholders, and internal/external auditors to validate identity-related ITGCs
- Recommend improvements to strengthen access governance, documentation, and evidence traceability
- Mentor junior access control analysts and contribute to establishing a sustainable Identity Control capability within the first line of defence
- Guide stakeholders on access control standards and remediation activities
- Bachelor’s or Master’s degree in Information Security, Information Technology, or a related discipline
- 5+ years of experience in identity governance, access management, or IT compliance
- Strong understanding of RBAC, SoD principles, and identity-related general IT controls
- Hands-on experience with SAP, Salesforce, Oracle, Workday, or similar enterprise platforms
- Familiarity with PCAOB/SOX frameworks and access control requirements
- Experience using Microsoft 365 (Teams, SharePoint), ServiceNow, or identity management tools
- Strong verbal and written communication skills, including experience with audit and stakeholder interaction
- Certifications such as CIAM, CAMS, CRISC, or equivalent
- Experience supporting PCAOB/SOX readiness programs in regulated environments
- Exposure to identity access governance platforms or user provisioning tools
- Understanding of GDPR, cloud access models, or data access risk
- Knowledge of ITIL, NIST, or other governance and control frameworks