JobHabor

Senior Director, Identity & Access Management

Ifs
Location
Staines-upon-Thames, England, United Kingdom
Workplace
Hybrid
Employment
Full Time
Salary
Apply on the employer’s site

Posted today

This role owns the Identity and Access Management (IAM) strategy for the IFS platform ecosystem. It leads the Authentication (AuthN) and Authorization (AuthZ) platforms that secure Nexus, Kairos, IFS.ai, Cloud Services, and future platform investments — balancing security, scale, compliance, and a straightforward experience for customers and developers.

The leader builds and runs a high-performing engineering organization through two engineering managers, and partners closely with Product, Architecture, Security, Compliance, Cloud Operations, and Customer Services to keep IAM capability ahead of the platform's needs.

Key responsibilities

Authentication

  • Identity provider integration and federation
  • SSO architecture and delivery
  • OAuth 2.0 and OpenID Connect platforms
  • Customer identity onboarding
  • SCIM provisioning and identity lifecycle management
  • User and group management
  • Tenant onboarding and offboarding
  • Session management and token services
  • Identity governance and compliance
  • Authentication observability and operational excellence
  • High availability and disaster recovery for authentication services

Authorization

  • Enterprise authorization platform strategy
  • RBAC, ABAC, ReBAC, and ACL models
  • Permission management platform
  • Entitlement management
  • Centralized and decentralized authorization patterns
  • Policy administration capabilities
  • Authorization enforcement frameworks
  • Row-level security capabilities
  • Audit and compliance controls
  • Authorization interoperability across the IFS product suite
  • Developer enablement — libraries, SDKs, and templates
  • Platform adoption across application teams

Leadership responsibilities

  • Set the strategic direction for IAM across the platform ecosystem and represent it in the wider engineering and product strategy
  • Own platform architecture governance for AuthN and AuthZ, ensuring designs meet security, scale, and compliance requirements
  • Uphold engineering excellence — code quality, reliability, and sound technical decision-making across both teams
  • Champion security and compliance as design constraints from the start, not afterthoughts
  • Represent the IAM customer experience — secure, fast, and easy to use — in every platform decision
  • Own reliability and operational excellence for AuthN and AuthZ services, including on-call and incident response posture
  • Drive adoption of AI-assisted engineering practices to lift team productivity
  • Partner across Product, R&D, and Cloud Operations to align IAM investment with the wider platform roadmap

People responsibilities

  • Lead a two-tier organization through two direct-report engineering managers — Authentication and Authorization — each running their own engineering team
  • Coach and develop the engineering managers, building their capability to lead and grow their teams
  • Own hiring, performance management, and career development across the IAM organization
  • Shape team structure and role design to match platform scope as it grows
  • Build a global, distributed team culture that works effectively across time zones
  • Create clear paths for talent development and succession within the IAM leadership team

Commercial responsibilities

  • Own the IAM organization's budget, including headcount planning and vendor spend
  • Evaluate and select third-party identity and authorization technologies, weighing build-versus-buy trade-offs against cost, risk, and time to value
  • Justify platform investment with a clear view of cost, risk reduction, and business impact
  • Manage vendor relationships and contracts tied to IAM tooling and services
  • Prioritize the roadmap to deliver the best return on engineering investment across AuthN and AuthZ

Required

  • Software engineering experience, with a strong foundation in distributed systems
  • Proven experience in engineering leadership roles, with direct accountability for team and platform outcomes
  • Proven experience leading through managers, not only leading engineers directly
  • Deep domain expertise in identity and access management — authentication, authorization, or both
  • Experience building and operating SaaS or cloud platforms at enterprise scale
  • A background in security architecture, with working knowledge of threat modeling and secure design principles
  • Experience leading platform engineering teams that serve other engineering teams as customers
  • Familiarity with compliance frameworks relevant to enterprise SaaS, such as SOC 2, ISO 27001, or GDPR
  • Experience leading globally distributed teams across multiple time zones

Preferred

  • Hands-on experience with a major cloud provider — Azure, AWS, or GCP
  • Familiarity with Zero Trust architecture principles
  • Working knowledge of OAuth 2.0, OpenID Connect, SAML, and SCIM
  • Experience with modern authorization technologies, including policy engines and ABAC/ReBAC frameworks
  • Exposure to identity governance and administration (IGA) solutions
  • A security certification such as CISSP or CISM, or equivalent experience

Skills and competencies

  • Customer centricity — designs IAM capability around how customers and developers actually work.
  • Collaboration — builds trust and alignment across Product, Architecture, Security, and Operations.
  • Accountability — owns outcomes for the platform and the teams that build it.
  • Courageous leadership — makes and defends hard calls on security and architecture trade-offs.
  • Continuous improvement — treats reliability and process as things to keep refining, not fixed.
  • Strategic thinking — connects day-to-day platform decisions to the longer-term IFS roadmap.
  • Results orientation — stays focused on measurable outcomes, not activity.
  • Talent development — invests in growing managers and the engineers behind them.
  • Innovation mindset — stays open to new approaches in identity and authorization without chasing novelty for its own sake.

Success measures

  • Enterprise-wide adoption of IAM platforms across Nexus, Kairos, IFS.ai, and Cloud Services
  • Measurable reduction in security risk across authentication and authorization surfaces
  • Improved developer productivity through self-service IAM capabilities, SDKs, and templates
  • Faster customer and tenant onboarding and provisioning
  • Increased standardization of authorization patterns across the product suite
  • Improved audit and compliance readiness
  • High availability and resilience of AuthN and AuthZ services, measured against agreed service-level objectives
  • Improved customer satisfaction tied to identity and access experiences

We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.

Skills

  • IAM
  • Nexus
  • SSO
  • OAuth 2.0
  • OpenID Connect
  • SCIM
  • RBAC
  • ABAC
  • SOC 2
  • ISO 27001
  • GDPR
  • Azure
  • AWS
  • GCP
  • Zero Trust
  • SAML
  • CISSP

More jobs at Ifs

All 150

Similar roles