Data Access Governance Architect - strong IAM expertise
- Own the data access governance program from discovery to implementation and operation.
- Act as the central technical authority and owner for the data access governance framework, particularly for customer tenant data.
- Partner with Legal, Product, and Sales to discover, interpret, and define critical data access use-cases and constraints required by contracts and regulations.
- Lead cross-functional workshops to map data flows, define access roles (RBAC), and secure stakeholder buy-in.
- Develop and report on program KPIs to measure the state of access controls, risk reduction, and compliance.
- Architect and design the technical data access framework, including scalable RBAC models, policies, and integrations.
- Lead the hands-on implementation and integration of our central IAM platform (e.g., Okta, Entra ID) to enforce the access policies you design.
- Design, build, and maintain automated Joiner, Mover, and Leaver (JML) workflows to ensure secure user lifecycle management.
- Engineer and operate data discovery and classification tools to identify and map sensitive data flows.
- Engineer, implement, and manage the firm's Data Loss Prevention (DLP) and data discovery/classification tools to map and protect sensitive data flows.
- Own and maintain the central registry of data and access constraints to ensure and demonstrate compliance.
- Serve as the primary technical escalation point and final approver for complex data access requests, handling exceptions to the defined policies.
- Drive the program-level rollout of the data access governance model, working with Engineering and Infrastructure to get controls implemented.
- Manage and coordinate all periodic user access certification campaigns for sensitive data, ensuring timely completion and sign-off.
- Develop and report on program KPIs to measure the state of access controls and compliance.
- Experience: At least seven (7) years of proven experience in a hands-on role spanning IAM, data security, or security architecture.
- Education: Bachelor's Degree in a relevant field or equivalent work experience.
- Core Knowledge: Strong, demonstrated understanding of core IAM principles (Least Privilege, RBAC, JML) and data security concepts.
- Hands-On IAM: Hands-on experience with major IAM platforms (e.g., Okta, SailPoint, Entra ID) and their integration.
- Technical Skills:
- Strong knowledge of authentication and authorization standards (SAML, OAuth, OpenID Connect, SCIM).
- Proficiency in at least one scripting language (e.g., PowerShell, Python) or a query language (SQL).
- Expertise in designing and operating Data Loss Prevention (DLP), data discovery, and classification tools.
- Core Competencies:
- Proven program management skills; the ability to manage competing priorities, drive projects to completion, and hold stakeholders accountable.
- A strong investigative mindset, with the ability to find and document requirements from non-technical stakeholders.
- Excellent communication skills and the ability to act as a central point of authority with confidence.
- High degree of attention to detail and strong documentation skills.
- Compliance: Knowledge of data protection regulations and compliance frameworks (e.g., GDPR, CCPA, ISO27001, SOC2, HIPAA etc.) and their technical application.
- TA Interview
- CISO Interview
- Set of 3 team interviews, including a panel
- Flexible remote and hybrid working options
- Competitive Salary and a variable component tied to personal and company performance
- Company equity
- Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
- Generous PTO and paid holidays
- Mental health benefits
- 2 MAD Days per year (Make A Difference Days for paid volunteering)
Emplois Recommandés
Ingénieur Plomberie H/F
A propos de Profila: Profila est une société de conseil en Ingénierie et en Recrutement, spécialisée dans le Bâtiment, le Génie Civil et l'Industrie. Notre société créée en 2009, s'illustre aujour…
Data Engineer / Data Analyst (H/F)
mc2i is an independent consulting firm that supports its key clients with their digital transformation projects. For over 35 years, we've been active in diverse sectors and areas, including Human …
Agent de caisse-Ressourcerie H/F -CDD
Apprentis d'Auteuil est un acteur engagé de l'économie sociale et solidaire, uvre d'église, qui développe des programmes d'accueil et d'accompagnement, d'éducation, de formation et d'insertion, auprè…
FP&A Analyst H/F
Vous cherchez un environnement professionnel stimulant basé sur l'autonomie et la confiance ? Pennylane vous offre l'opportunité de grandir au sein d'une entreprise en pleine croissance. Ici, v…
Digital Media Manager
Kering seeks a Digital Media Manager in Paris to lead and optimize digital media channels, collaborating with global media agencies and brand teams. This role requires over 10 years of senior digital …
Développeur(se) Fullstack JAVA - Services Financiers F/H
Développeur(se) Fullstack JAVA - Services Financiers F/H Description de poste Développement front-end, Back-end, Fullstack,... Ca vous parle ? Nous rejoindre, c’est intégrer une communauté te…
Carrier Relations Manager
As Carrier Relations Manager at Onoff, you will play a key role in shaping and strengthening our global network of telecom partnerships. Your mission is to build strategic, trusted relationships with…
Infirmier en Réanimation - H/F
Infirmier en Réanimation - H/F req877 Notre établissement : L'Hôpital Fondation Adolphe de Rothschild est un établissement hospitalo-universitaire de référence dans le domaine des pathologies tête et …
Avocat Fiscalité International H/F
Le poste de Avocat Fiscalité International H/F En tant qu'Avocat(e) Fiscalité International(e), vous interviendrez sur une variété de dossiers, aussi bien en matière transactionnelle, dans l'acc…
architecte informatique SAP BDD HANA (IT)
Intitulé du poste : Architecte SAP Basis / HANA Contexte : Notre client évolue dans un environnement SAP critique et à forts enjeux de performance. Le consultant interviendra sur un double environnem…