About this role
Salary: £62,000 - 90,000 per year
Requirements: Extensive senior leadership track record in Identity & Access Management, Privileged Access Management and Identity Governance & Administration in a complex, regulated environment, with financial services strongly preferred.Demonstrable experience leading a multi-year IAM/PAM/IGA transformation programme end-to-end, including target operating model design, tooling modernisation and measurable maturity uplift.Deep working knowledge of enterprise IAM platforms such as OneIdentity and PAM platforms such as CyberArk Privilege Cloud, including operating models, integration patterns and control outcomes.Strong grasp of modern authentication and authorisation architectures, including SSO, MFA, OIDC/SAML, RBAC, ABAC and workload identity federation across Microsoft Entra ID, Active Directory and AWS IAM.Executive presence and comfort operating at senior committee level, including presenting IAM strategy, control effectiveness and remediation to executive committees, board risk committees, external audit and regulators.Practical knowledge of regulatory and control expectations impacting identity controls, including FCA/PRA Operational Resilience, DORA, ICO expectations, ITGC scrutiny, ISO 27001 and NIST CSF.Proven ability to influence senior engineering, platform and product leaders to drive change and adoption of enterprise standards without direct authority.Demonstrable experience owning multi-year IAM investment cases, vendor strategy and budget, translating capability ambition into commercial outcomes.Strong people leadership credentials, including building, developing and retaining senior IAM/PAM talent and creating career pathways within a technical capability.Excellent written and verbal communication skills, with the ability to translate complex identity concepts for engineering, product, risk and executive audiences.Advanced security or IAM certifications expected, such as CISSP, CISM, CIDPRO, CyberArk Sentry or Microsoft SC-300. Responsibilities: Own the multi-year IAM, PAM and IGA strategy, target operating model and capability maturity roadmap for colleague and workload identities, developed in partnership with Security Architecture and Cyber Defence.Lead the transformation of our IAM capability, driving material uplift in automation, self-service, joiner-mover-leaver reengineering, RBAC modernisation, PAM control effectiveness and identity governance maturity.Set and steward the enterprise IAM standards, patterns and policies adopted across engineering and platform teams, ensuring least privilege, zero-trust identity principles and segregation of duties are consistently embedded by design.Own privileged access strategy and outcomes, including vaulting, session isolation, credential rotation and Just-In-Time / Just-Enough-Access controls, with day-to-day PAM operation delegated to specialist team leads.Own the access governance strategy, including recertification cadence, role modelling, entitlement definitions and exception handling, while retaining accountability for outcomes and regulatory evidence and delegating execution.Represent IAM at executive, risk and governance forums and act as our principal IAM interface to external audit and regulators on identity-related matters.Own the IAM investment case, vendor strategy and multi-year budget, ensuring spend, tooling and partner choices deliver measurable capability, control and efficiency outcomes.Influence and drive change across senior engineering, platform and product leaders to embed IAM standards and secure-by-design identity outcomes at pace and scale.Lead, develop and retain a high-performing IAM team, owning the capabilitys talent strategy, succession planning and continuous uplift of technical and delivery skills at senior levels.Report on IAM performance, control effectiveness and transformation outcomes through clear KRIs, KPIs and management information tailored for engineering, executive, risk and regulatory audiences. Technologies: AWSActive DirectoryCloudEmbeddedIAMSupportRBACSAMLSecuritySentry More:
We are HL, the UKs number 1 investment platform for private investors, based in Bristol. For more than 40 years we have helped investors save time, tax and money on their investments. We offer a permanent, full-time role of 37.5 hours per week, Monday to Friday, with a hybrid flex working pattern and a minimum of 2 days in the office each week. Our head office is in Bristol (BS2 0TR). We offer a 3-stage interview process including a presentation. We provide a workplace focused on constant learning, dynamic teams and strong core values around service, quality, innovation and opportunity. Our benefits include a discretionary annual bonus and annual pay review, 25 days holiday plus bank holidays and a Christmas closure day, the option to purchase extra holiday, enhanced parental leave, pension contributions up to 11% employer contribution, income protection and life insurance, private medical insurance, healthcare cash plans, health screening, confidential support services, wellbeing access, travel schemes, bike storage and showers, subsidised coffee and sandwiches, and two paid volunteering days per year. We are an inclusive employer that values diversity and may offer flexible or part-time working.
last updated 35 week of 2026