We're Hiring: Senior Access Governance Specialist
Location: United Arab Emirates (Remote)
Employment Type: Full-Time
Experience Level: Senior
Work Arrangement: Fully Remote
About UsWe are a globally focused organization committed to strengthening cybersecurity, identity management, access controls, and technology governance across diverse digital environments. Our teams collaborate across Information Security, Identity and Access Management, IT, Compliance, Risk, Internal Audit, Human Resources, Engineering, and business functions to ensure that access to systems and information is appropriately governed and protected.
Our security and governance teams combine policy, technology, risk management, analytics, and operational controls to maintain secure access throughout the employee, contractor, application, and third-party lifecycle.
The RoleWe are seeking an experienced Senior Access Governance Specialist to lead access governance, identity governance, access certification, segregation of duties, privileged-access oversight, access-risk management, and identity-related compliance activities.
The ideal candidate will provide strong governance and analytical oversight across user and application access, ensuring that access rights are appropriate, authorized, periodically reviewed, properly documented, and aligned with business responsibilities, security policies, regulatory requirements, and risk-management objectives.
Key Responsibilities
- * Develop and maintain access-governance strategies, policies, standards, procedures, and control frameworks.
- Establish governance requirements for user, privileged, application, service, contractor, and third-party access.
- Define access-governance processes across the identity and access lifecycle.
- Establish appropriate controls for joiner, mover, and leaver access management.
- Coordinate periodic user-access reviews and certification campaigns.
- Manage access-certification processes across business applications, infrastructure, cloud platforms, and critical information systems.
- Define review populations, certification requirements, approval workflows, deadlines, and escalation procedures.
- Monitor completion of access reviews and follow up on overdue certifications.
- Analyze access-review results and identify inappropriate, excessive, orphaned, dormant, or conflicting access.
- Coordinate removal or modification of access identified as inappropriate during certification activities.
- Establish and maintain role-based access-control governance.
- Support the development and maintenance of business roles, technical roles, application roles, and entitlement structures.
- Review role definitions to ensure they accurately reflect business responsibilities and least-privilege principles.
- Identify opportunities to simplify, standardize, and rationalize access roles.
- Govern segregation-of-duties requirements and access conflicts.
- Develop and maintain segregation-of-duties rules, risk definitions, and mitigating controls.
- Assess access conflicts and coordinate remediation or documented risk acceptance.
- Support privileged-access governance and oversight.
- Review privileged accounts, administrative access, elevated entitlements, and sensitive system privileges.
- Coordinate with Privileged Access Management teams to ensure appropriate controls are implemented.
- Monitor privileged-access certification, approvals, exceptions, and periodic reviews.
- Establish governance requirements for service accounts, shared accounts, technical accounts, and non-human identities.
- Ensure appropriate ownership, business justification, lifecycle controls, and periodic review of non-human identities.
- Review access requests and ensure appropriate authorization and approval requirements are defined.
- Establish governance controls for emergency, temporary, break-glass, and elevated access.
- Monitor temporary access and ensure it expires according to approved requirements.
- Review access exceptions, compensating controls, and risk acceptances.
- Maintain accurate records of access-governance decisions, approvals, certifications, exceptions, and remediation activities.
- Develop access-governance metrics, dashboards, and management reports.
- Monitor access-risk indicators and identify emerging governance issues.
- Analyze access data to identify unusual entitlement patterns, excessive privileges, inactive accounts, conflicting access, and potential control weaknesses.
- Support identity analytics and risk-based access-review prioritization.
- Work with IAM teams to improve identity lifecycle processes and access provisioning controls.
- Collaborate with Human Resources to ensure employment-status and organizational changes are accurately reflected in access processes.
- Coordinate with application owners, system owners, data owners, and business managers to validate access requirements.
- Partner with Information Security and Risk teams to assess access-related risks and control gaps.
- Support cloud-access governance across infrastructure, applications, platforms, and cloud-native services.
- Establish governance requirements for access across SaaS applications and externally hosted platforms.
- Support access governance for third-party, supplier, consultant, and partner identities.
- Ensure third-party access has appropriate business sponsorship, defined scope, time limits, and periodic review.
- Review identity and access controls following organizational restructures, acquisitions, system implementations, migrations, and major technology changes.
- Support access-governance requirements for new applications and technology implementations.
- Participate in security architecture and solution reviews where identity and access controls are relevant.
- Develop and maintain access-control matrices, governance documentation, process maps, and control descriptions.
- Establish control requirements for access provisioning, modification, revocation, certification, and monitoring.
- Support internal and external audits by providing access-governance evidence, reports, control documentation, and remediation updates.
- Coordinate responses to audit findings and regulatory observations relating to identity and access governance.
- Track access-control remediation activities through completion and validate corrective actions.
- Monitor compliance with internal access policies and applicable regulatory requirements.
- Conduct periodic governance assessments to identify weaknesses in access-management processes.
- Develop and implement continuous-improvement initiatives for access governance.
- Identify opportunities to automate access reviews, certification campaigns, entitlement analysis, and governance reporting.
- Work with IAM and technology teams to improve identity-governance platforms, workflows, and integrations.
- Support implementation and optimization of Identity Governance and Administration solutions.
- Evaluate access-governance technologies, analytics capabilities, and automation opportunities.
- Define business and governance requirements for access-governance tools and technology enhancements.
- Develop training and guidance for managers, application owners, system owners, and access approvers.
- Promote awareness of least privilege, segregation of duties, access accountability, and identity security.
- Provide senior management with regular reporting on access risks, certification performance, control effectiveness, exceptions, and remediation.
Key Performance Indicators
- * Access-certification completion rate
- On-time access-review completion
- Overdue certification rate
- Access-review remediation rate
- Inappropriate-access removal rate
- Excessive-access reduction
- Dormant-account remediation rate
- Orphan-account remediation rate
- Privileged-access certification completion
- Segregation-of-duties conflict resolution rate
- Open access-conflict aging
- Access exception closure rate
- Temporary-access expiration compliance
- Joiner access-provisioning compliance
- Mover access-modification compliance
- Leaver access-revocation compliance
- Access-request approval accuracy
- Access-policy compliance
- Least-privilege compliance
- Role-definition accuracy
- Role-rationalization progress
- Access-governance control effectiveness
- Access-related audit finding closure
- Access-risk remediation time
- Third-party access review completion
- Service-account review completion
- Non-human identity governance coverage
- Privileged-account governance coverage
- Cloud-access governance coverage
- SaaS access-governance coverage
- Access-review campaign cycle time
- Access-governance automation rate
- Manual access-review reduction
- Access-governance data quality
- Access inventory completeness
- Entitlement ownership coverage
- Access-risk identification rate
- Access exception aging
- Governance reporting timeliness
- Stakeholder certification satisfaction
- Identity-governance platform adoption
- Recurring access-control issue reduction
- Audit and regulatory compliance
- Access-related security-risk reduction
Ideal CandidateThe successful candidate should have strong experience in access governance, identity governance, IAM, information security, access controls, IT risk, or cybersecurity governance, preferably within complex enterprise, financial-services, technology, telecommunications, professional-services, or highly regulated environments.
The candidate should demonstrate:
- Strong understanding of identity and access governance principles.
- Proven experience managing access-certification and access-review programs.
- Strong knowledge of role-based access control and least-privilege principles.
- Experience managing segregation-of-duties frameworks and access conflicts.
- Strong understanding of joiner, mover, and leaver identity processes.
- Experience governing privileged, service, shared, technical, and non-human identities.
- Experience with Identity Governance and Administration platforms and access-certification