Senior IAM Lead
Job description
About the role
Nexthink is seeking an experienced Identity and Access Management (IAM) Lead to spearhead the identity strategy and enhance operational excellence within the corporate identity perimeter. This pivotal position involves leading a dedicated team of senior engineers who are responsible for establishing the platforms, policies, and engineering standards that dictate how employees, contractors, service accounts, and non-human identities access and utilize resources within Nexthink's corporate environment. The IAM Lead will collaborate closely with the Chief Information Security Officer (CISO) on policy formulation and standards, while also partnering with the IT department to ensure effective operational delivery, overseeing engineering execution from start to finish.
Key facts
What you'll do
- Develop and manage the IAM governance framework, including principles, standards, decision-making rights, and operational cadence, to serve as a robust foundation for the IAM program.
- Create and sustain a multi-year IAM roadmap that aligns capability development with business risks and investor expectations.
- Formulate a strategy for application prioritization and SaaS onboarding, determining which systems will be governed first, the standards to be applied, and the timelines for implementation.
- Establish role-based access control (RBAC) governance standards and define the target access model across the corporate landscape.
- Oversee external specialist engagements, such as role mining and access-model optimization, while maintaining internal accountability for outcomes and standards.
- Design and implement an enterprise access review and certification framework that is periodic, risk-based, and thoroughly documented.
- Conduct regular access certifications for in-scope applications, ensuring all processes are backed by audit-ready evidence.
- Set up and manage quarterly privileged access reviews, working towards minimizing standing admin access in all relevant environments.
- Collaborate with application owners to enforce access governance over key business applications, including Workday, NetSuite, and Salesforce.
- Lead Segregation of Duties (SoD) analysis by defining conflict rules, identifying and resolving SoD conflicts, and ensuring ongoing monitoring.
- Support compliance with SOX, ISO 27001, and SOC 2 audits by providing documented controls, evidence, and tracking remediation efforts, serving as the primary IAM liaison to Internal Audit.
- Direct the design of roles in NetSuite and rationalize permissions in Salesforce to ensure alignment with the principle of least privilege and clear role definitions.
- Own the engineering standards and roadmap for Microsoft Entra ID and Okta, enforcing Single Sign-On (SSO) standards across the SaaS ecosystem.
- Promote the adoption of passwordless and non-phishable Multi-Factor Authentication (MFA) for all employee and privileged access scenarios.
- Design and operationalize Just-In-Time admin access using tools such as Intune, Entra PIM, and Okta privileged access.
- Serve as the technical escalation point for IAM incidents and high-severity access requests.
- Build and maintain an inventory of non-human identities, including service accounts, API keys, and OAuth applications, while defining standards for ownership, rotation, and deprovisioning.
Requirements
- A minimum of 8 years of experience in identity and access management, with at least 2 years in a leadership role focused on IAM governance or strategy.
- Proven success in designing and managing access governance frameworks, including access reviews, RBAC models, and entitlement rationalization at an enterprise level.
- Hands-on experience with Segregation of Duties and access governance for business applications such as Workday, NetSuite, or Salesforce.
- Operational knowledge of Microsoft Entra ID and Okta, including Conditional Access, federation, SCIM, and OIDC/SAML.
- Familiarity with privileged access management tools and a history of reducing standing admin access and orphaned accounts.
- Experience in managing non-human identity governance, including service accounts and secrets management.
- Understanding of compliance frameworks such as ISO 27001, SOC 2, or SOX, with the ability to design controls and produce audit-ready documentation.
- Strong communication skills to convey governance and technical decisions to senior business stakeholders, finance teams, and internal audit. Proficiency in English is essential.
Nice to have
- Experience with cloud IAM solutions and their integration into enterprise environments.
- Familiarity with data protection regulations and their implications for IAM practices.
- Knowledge of emerging IAM technologies and trends.
Skills & tools
- IAM governance frameworks
- Microsoft Entra ID and Okta
- Role-based access control (RBAC)
- Segregation of Duties (SoD) analysis
- Compliance standards (SOX, ISO 27001, SOC 2)
- Multi-Factor Authentication (MFA)
Practical notes
Nexthink is a pioneer in the Digital Employee Experience (DEX) market, providing organizations with comprehensive visibility across their IT environments. With a diverse workforce of over 1,000 employees spanning five continents, Nexthink fosters a culture of collaboration and innovation. The company is committed to diversity, equity, and inclusion, with team members representing over 75 nationalities.
If you are seeking a dynamic work environment with ample challenges and opportunities for growth, this position could be the perfect fit for you. Nexthink offers a competitive compensation package, including a permanent contract, private health insurance, and flexible working hours. Employees enjoy unlimited vacation days in addition to standard holidays, along with various perks such as gym subsidies and reimbursement for language classes. Join us and be part of a team that values creativity and teamwork while making a significant impact in the digital workplace.