Senior Identity and Access Governance (IGA) Consultant (Associate, Contract)
Intelance is an independent technology, AI and cyber assurance firm. We advise regulated and complex organisations on enterprise architecture, cyber security, identity and access, data governance and technology assurance.
We are expanding our associate network and are looking for a Senior Identity and Access Governance (IGA) Consultant to support two upcoming client engagements in financial and professional services. Both engagements focus on confirming who should access sensitive information across core systems, designing a clear role and access model, and supporting access certification and segregation of duties work. This is a contract role, delivered mainly remotely, with occasional client facing workshops.
Tasks
Working under the Engagement Lead and the Cyber, Identity and Access Lead, you will:
- Review how access is currently granted across core business systems, including users, roles, groups, privileged accounts and service accounts.
- Identify where access is broader than required and document the associated risks.
- Carry out role mining and design role based access models, access matrices and least privilege structures.
- Support access certification and recertification exercises so managers can make informed decisions.
- Complete segregation of duties analysis and document conflicts and mitigating controls.
- Define joiner, mover and leaver controls, and access request, approval and review processes.
- Support the review of how AI tools and connectors access internal information, alongside the Cyber, Identity and Access Lead.
- Prepare clear findings, role descriptions and evidence suitable for internal stakeholders and external audit.
- Maintain the implementation backlog and support testing and evidence review as client system owners make changes.
Requirements
Essential experience and skills:
- Proven experience delivering identity and access management (IAM) or identity governance and administration (IGA) work in regulated or complex organisations.
- Strong track record in role design, role mining, access matrices, role based access control and least privilege.
- Hands on experience of access certification, recertification and segregation of duties analysis.
- Good understanding of joiner, mover and leaver processes and access request and approval controls.
- Familiarity with core enterprise and identity platforms, for example Active Directory, Entra ID, SharePoint and cloud data platforms such as Snowflake.
- Ability to translate business access needs into practical system requirements and clear documentation.
- Confident working with business, compliance, technology and audit stakeholders.
- Self sufficient and comfortable working remotely across more than one engagement.
- Awareness of data protection requirements, for example UK GDPR.
Desirable:
- Experience supporting external audit or assurance work.
- Exposure to AI access, connectors and data governance.
- Relevant certifications, for example CISM, CISSP, SailPoint, Saviynt, Microsoft identity certifications or ISO 27001.