Descripción de la oferta
Experteer Overview Por favor, presente su candidatura sin demora si su perfil encaja bien con este puesto, debido al alto nivel de interés. As IAM and Access Control Lead, you will shape Nexthink's corporate identity strategy and run the IAM program end-to-end. You’ll lead a small team of senior engineers to implement RBAC, access reviews, and non-human identity governance across the corporate estate, partnering with CISO and IT. You’ll drive the roadmap, standards, and external engagements to ensure secure, compliant access. This role offers impact at scale, influencing audits, SaaS onboarding, and privileged access practices across a global organization. You will work in a security-focused, cross-functional environment to protect critical systems while enabling business agility.Compensaciones / Beneficios• Define and own the IAM governance model and multi-year roadmap• Establish RBAC governance standards and target access model• Oversee external engagements for role mining and access-model optimization• Design and operate enterprise access reviews and certification framework• Lead SoD analysis and ongoing monitoring for business applications• Support SOX, ISO 27001, and SOC 2 audit readiness with documented controls• Lead NetSuite role design and Salesforce permission rationalization• Own the engineering standards for Microsoft Entra ID and Okta• Define SSO standards, SAML/OIDC integrations, and SCIM provisioning• Drive passwordless and MFA adoption across employee and privileged access• Design and operationalize Just-In-Time admin access• Act as escalation point for IAM incidents and high-severity requests• Build and operate inventory and lifecycle controls for non-human identitiesResponsabilidades• 8+ years in identity and access management, including 2+ years in governance/leadership• Experience designing and operating access governance at enterprise scale• Hands-on SoD analysis for apps like Workday, NetSuite, or Salesforce• Operational xcskxlj expertise with Microsoft Entra ID and Okta (Conditional Access, federation, SCIM, OIDC/SAML)• Experience with privileged access tooling (Entra PIM, Okta PA, JIT admin)• Experience with non-human identity governance (service accounts, OAuth apps, secrets management)• Compliance/audit fluency: ISO 27001, SOC 2, or SOX• Ability to communicate governance decisions to senior stakeholdersRequisitos principales• Permanent contract with competitive compensation• Hybrid work model• Private health insurance (Sanitas)• Unlimited vacation + 3 volunteer days• Meal vouchers• Gym subsidy up to 25 EUR/month