Identity Access Management (IAM) Governance & Compliance role.
English is a must
Key Responsibilities
Identity Access Management (IAM) Governance & Compliance
- Ensure the governance and compliance of the IAM Target Operating Model (TOM) in alignment with Group Information Security Framework
- Monitor and enforce IAM policies, standards, and procedures across the organization
- Ensure and monitor user access review processes and recertification processes to ensure least privilege and segregation of duties (SoD)
- Oversee IAM control effectiveness through regular assessments and reviews
- Collaborate with IAM operations teams to ensure proper implementation of role-based access control (RBAC) and privileged access management (PAM)
- Track and report IAM-related risks, exceptions, and remediation activities
- Ensure compliance with regulatory requirements related to identity and access (e.g., GDPR, DORA, NIS2)
Secure Software Development Lifecycle (SDLC) Governance
- Establish and maintain governance frameworks for secure SDLC practices across development teams
- Define and enforce security requirements at each phase of the software development lifecycle
- Ensure integration of security testing (SAST, DAST, SCA) into CI/CD pipelines
- Review and validate security architecture and threat modeling for new applications and services
- Monitor compliance with secure coding standards and guidelines
- Provide guidance and training to development teams on secure development practices
Cloud Security Infrastructure & DevSecOps Compliance
- Ensure compliance of cloud security infrastructure with Group Information Security Framework and industry best practices
- Govern the implementation of security controls in cloud environments (IaaS, PaaS, SaaS)
- Monitor and enforce DevSecOps practices including infrastructure-as-code (IaC) security scanning
- Oversee cloud security posture management (CSPM) and cloud workload protection
- Ensure proper configuration management and hardening of cloud resources
- Validate compliance with cloud security benchmarks (e.g., CIS Benchmarks, CSA CCM)
- Collaborate with cloud engineering teams to embed security into deployment pipelines
General Governance & Compliance
- Align all activities with the Group Information Security Framework (GISF) and relevant policies
- Prepare and present compliance reports, dashboards, and KPIs to management
- Support internal and external audits related to information security
- Manage and track security exceptions, risk acceptances, and remediation plans
- Contribute to the continuous improvement of information security governance processes
- Liaise with Group Information Security, Risk Management, and Compliance functions
Application Confirmation
You're applying for the role below: