Senior Iam Lead
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any application or network, before employees notice the issue. As the first solution to allow IT to progress from reactive problem solving to proactive optimization, Nexthink enables its more than 1,500 customers to provide better digital experiences to more than 25+ million employees. Dual headquartered in Lausanne, Switzerland and Boston, Massachusetts, Nexthink has 9 offices worldwide.
Job Description
We are looking for an IAM and Access Control Lead to drive the identity strategy and operational excellence of Nexthink's corporate identity perimeter. This role leads a small team of senior engineers responsible for the platforms, policies and engineering standards that govern how every employee, contractor, service account and non-human identity gains, uses, and loses access across Nexthink's corporate environment.
You will partner with the CISO function on policy and standards, and with IT on operational delivery, owning the engineering execution end to end.
IAM Governance & Strategy
- Define and own the IAM governance model - principles, standards, decision rights, and operating cadence -as the durable internal foundation for the program.
- Develop and maintain the multi-year IAM roadmap, sequencing capability build against business risk and investor expectations.
- Establish the application prioritization and SaaS onboarding strategy: which systems are governed first, to what standard, and on what timeline.
- Define role-based access control (RBAC) governance standards and the target access model across the corporate estate.
- Scope, commission, and steer external specialist engagements (e.G. role mining, access-model optimization), retaining internal ownership of outcomes and standards.
Access Reviews & Certification
- Design and operate the enterprise access review and certification framework - periodic, risk-based, and fully evidenced.
- Run recurring access certifications across in-scope applications with documented, audit-ready evidence trails.
- Establish and operate quarterly privileged access reviews; drive standing admin toward zero for all in-scope environments.
Business Application Access & Segregation of Duties
- Establish access governance over core business applications - Workday, NetSuite, and Salesforce - in partnership with the application owners.
- Lead Segregation of Duties (SoD) analysis: define the conflict ruleset, identify and remediate SoD conflicts, and operate ongoing monitoring.
- Support SOX, ISO 27001, and SOC 2 audit readiness with documented controls, evidence, and remediation tracking; serve as IAM's primary interface to Internal Audit.
- Lead NetSuite role design and Salesforce permission rationalization to align entitlements with least privilege and clean role definitions.
Identity Platform Operations
- Own the engineering standards and roadmap for Microsoft Entra ID and Okta.
- Define and enforce SSO standards across the SaaS estate, including SAML/OIDC integrations and SCIM provisioning.
- Drive passwordless and non-phishable MFA adoption across all employee and privileged access scenarios.
Privileged Access & Just-In-Time Admin
- Design and operationalise Just-In-Time admin access (Intune, Entra PIM, Okta privileged access).
- Act as the technical escalation point for IAM incidents and high-severity access requests.
Non-Human Identity (NHI) Governance
- Build and operate the inventory of service accounts, API keys, OAuth applications, and machine identities.
- Define ownership, rotation, and deprovisioning standards for every NHI; eliminate orphaned and over-privileged service accounts across SaaS, GitHub, and cloud IAM.
Primary Metrics
- Access certification completion rate and cycle timeliness
- SoD conflicts identified vs. remediated (and open-conflict ageing)
- SaaS estate onboarding coverage against the governance roadmap
- SSO coverage across the SaaS estate; MFA exception rate
- Privileged access SLA and standing-admin count
- Orphaned account count