Data Access Governance Architect - strong IAM expertise

Paris
Shift is the leading AI platform for insurance. Shift combines generative, agentic, and predictive AI to transform underwriting, claims, and fraud and risk - driving operational efficiency, exceptional customer experiences and measurable business impact. Trusted by the world's leading insurers, Shift delivers AI when and where it matters most, at scale and with proven results.

Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.

DESCRIPTION

As the Data Access Governance Architect, you will own and drive the end-to-end data access governance program. You are the single point of ownership responsible for defining the "who, what, and why" of data access, architecting the technical solution, and managing the program to implement it.

This is a critical, hands-on leadership role. You won't just design the framework; you will act as the primary authority, investigate the use-cases, build the technical controls, and run the program. You are the "go-to" expert and owner for who can access what data, why, and how. As part of the Information Security department, this role reports to the CISO.

RESPONSIBILITIES

Program Leadership & Use-Case Management
  • Own the data access governance program from discovery to implementation and operation.
  • Act as the central technical authority and owner for the data access governance framework, particularly for customer tenant data.
  • Partner with Legal, Product, and Sales to discover, interpret, and define critical data access use-cases and constraints required by contracts and regulations.
  • Lead cross-functional workshops to map data flows, define access roles (RBAC), and secure stakeholder buy-in.
  • Develop and report on program KPIs to measure the state of access controls, risk reduction, and compliance.
Technical Architecture & Engineering
  • Architect and design the technical data access framework, including scalable RBAC models, policies, and integrations.
  • Lead the hands-on implementation and integration of our central IAM platform (e.g., Okta, Entra ID) to enforce the access policies you design.
  • Design, build, and maintain automated Joiner, Mover, and Leaver (JML) workflows to ensure secure user lifecycle management.
  • Engineer and operate data discovery and classification tools to identify and map sensitive data flows.
  • Engineer, implement, and manage the firm's Data Loss Prevention (DLP) and data discovery/classification tools to map and protect sensitive data flows.
Governance Operations & Assurance
  • Own and maintain the central registry of data and access constraints to ensure and demonstrate compliance.
  • Serve as the primary technical escalation point and final approver for complex data access requests, handling exceptions to the defined policies.
  • Drive the program-level rollout of the data access governance model, working with Engineering and Infrastructure to get controls implemented.
  • Manage and coordinate all periodic user access certification campaigns for sensitive data, ensuring timely completion and sign-off.
  • Develop and report on program KPIs to measure the state of access controls and compliance.
SKILLS & BACKGROUND
  • Experience: At least seven (7) years of proven experience in a hands-on role spanning IAM, data security, or security architecture.
  • Education: Bachelor's Degree in a relevant field or equivalent work experience.
  • Core Knowledge: Strong, demonstrated understanding of core IAM principles (Least Privilege, RBAC, JML) and data security concepts.
  • Hands-On IAM: Hands-on experience with major IAM platforms (e.g., Okta, SailPoint, Entra ID) and their integration.
  • Technical Skills:
    • Strong knowledge of authentication and authorization standards (SAML, OAuth, OpenID Connect, SCIM).
    • Proficiency in at least one scripting language (e.g., PowerShell, Python) or a query language (SQL).
    • Expertise in designing and operating Data Loss Prevention (DLP), data discovery, and classification tools.
  • Core Competencies:
    • Proven program management skills; the ability to manage competing priorities, drive projects to completion, and hold stakeholders accountable.
    • A strong investigative mindset, with the ability to find and document requirements from non-technical stakeholders.
    • Excellent communication skills and the ability to act as a central point of authority with confidence.
    • High degree of attention to detail and strong documentation skills.
  • Compliance: Knowledge of data protection regulations and compliance frameworks (e.g., GDPR, CCPA, ISO27001, SOC2, HIPAA etc.) and their technical application.
HIRING PROCESS
  • TA Interview
  • CISO Interview
  • Set of 3 team interviews, including a panel
#LI-RH1 #LI-HYBRID

To support our permanent, full time employees at every stage of their careers and lives, we provide a competitive total rewards and benefits package. Here are the global benefits we'd like to highlight:
  • Flexible remote and hybrid working options
  • Competitive Salary and a variable component tied to personal and company performance
  • Company equity
  • Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
  • Generous PTO and paid holidays
  • Mental health benefits
  • 2 MAD Days per year (Make A Difference Days for paid volunteering)
Additional benefits may be offered by country - ask your recruiter for more information. Intern and Apprentice position are eligible for some of these benefits - ask your recruiter for more details.

At Shift we strive to be a diverse and inclusive workforce. We welcome applications from and hire people who will contribute to the diversity of our company, without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria.

Shift Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email [email protected] and we will work with you to meet your accessibility needs.

Please be aware of scammers and only trust correspondence that comes from emails ending in "shift-technology.com". We will never do initial outreach to you via Whatsapp/Text/SMS, never ask for banking information or personal identification numbers (ex. Social Security Number) as part of our recruitment process.

Shift Technology does not accept unsolicited CVs from recruiters or employment agencies in response to the Shift Technology Careers page or a Shift Technology social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Shift Technology.
Publié le 2026-02-15

Emplois Recommandés

Employé de rayon fruits et légumes (F/H)

Carrefour
Paris 17e

Rejoignez Carrefour et participez à une aventure qui fait la différence ! Nous avons une mission simple : rendre le meilleur accessible à tous, tout en nous engageant pour une distribution responsabl…

Voir les Détails
Publié le 2026-01-30

Responsable du développement web et mobile H/F

TEAM IS
Paris

Description En postulant à cette offre, vous aurez l'opportunité de rejoindre une entreprise innovante dans le secteur de l'assurance et de la gestion de patrimoine (AssurTech), proposant des solu…

Voir les Détails
Publié le 2026-01-15

Senior QA Engineer

Payplug
Paris

Description Payplug est la solution de paiement française pensée pour les commerçants, e-commerçants de toutes tailles et fintechs. Avec notre plateforme technologique de pointe, nos outils d…

Voir les Détails
Publié le 2025-12-06

Expert Coach Agile - H/F

Talan
Paris

Description de la mission Vous serez recruté en tant que Coach Agile pour la BU Tech For Business qui accompagne ses clients dans la réalisation de leurs projets de transformation digitale chez de…

Voir les Détails
Publié le 2026-01-30

COLLABORATEUR COMPTABLE SENIOR PRIVATE EQUITY (H/F)

MOMENTI
Paris 8e

A propos de MOMENTI: Envie de relever un nouveau défi professionnel ? Nous recrutons ! MOMENTI, cabinet de recrutement et de chasse de têtes, accompagne aujourd'hui un cabinet d'expertise comptable e…

Voir les Détails
Publié le 2026-01-30

Ingénieur Intégration et Validation - IDF - ASAP - Mission freelance (H/F)

Yalink
Paris 20e

Présentation de l'entreprise Avec plus de 250 clients et 10 000 freelances inscrits , Yalink est la première plateforme de freelancing dans l'ingénierie de la construction des infrastructures de tr…

Voir les Détails
Publié le 2026-02-12

Senior Data Scientist (IT)

TO B SERVICES
Paris

Au sein d'un acteur à la pointe de l'innovation dans le secteur des médias de détail, en tant que plateforme SaaS pionnière. Votre mission ? Vous intégrerez la nouvelle équipe data basée à Paris …

Voir les Détails
Publié le 2026-02-12

Psychiatre service 92g17 ph ou pc - h/f

GROUPE HOSPITALIER PAUL GUIRAUD
Paris

Description entreprise : ~ Le groupe hospitalier Fondation Vallée - Paul Guiraud, l’établissement support du GHT « Psy Sud Paris », acteur important de la psychiatrie publique en Île-de-France, ré…

Voir les Détails
Publié le 2026-02-12

TECHNICIEN DE PRESTATIONS H/F

CPAM DE PARIS
Paris

L'Assurance Maladie de PARIS est chargée d' assurer la protection face à la maladie de 2,5 millions d'assurés, en finançant plus de 14 milliards d'euros de dépenses de santé par an. Rejoindre l' A…

Voir les Détails
Publié le 2026-02-09

Mécanicien automobile Paris & IDF F/H

Rm Interim - Toulouse
Paris

Description du poste : RM Intérim division Automobile recherche pour un de ses clients, concession, un Mécanicien Automobile (gros travaux) H/F pour renforcer ses équipes. Au sein de l'équipe, vous au…

Voir les Détails
Publié le 2026-02-06