IAM Snr Manager\Director
Send a job offer directly to this candidate
Technically-sophisticated security professional with 25+ years of experience providing high-quality IAM expertise and guidance to internal project teams and clients. Adept at developing roadmaps and implementation plans as well as creating IAM solution blueprints. Expert in producing high-level designs for technical and process solutions for multiple IAM domains.
Talent for aligning security plans, policies, and procedures with security standards/operational goals. Known for introducing the use of security metrics to mitigate the vulnerability by addressing risks/violations and implementing improved protocols.
Head of Enterprise IAM Engineering & Operations at Fidelity (2024-01 – Present)
Serving as a Head of IAM for seamless execution of IAM and PAM\IGA to assist in reducing risks by utilizing CyberArk, MFA, Sailpoint IDN. Developing the strategy to deliver & drive the right outcomes for a secure group, on prem and in cloud environments. Created roadmaps, implement KPIs, and drove change. Managing teams of approx. 100 staff worldwide. Communicating to stakeholders at all levels, directly reporting to CISO, Risk Boards.
Head of IAM Engineering & Operations - IAM at NationalGrid (2022-01 – 2024-01)
Serving as a Head of IAM for seamless execution of IAM and PAM\IGA to assist in reducing risks by utilizing CyberArk, MFA, Sailpoint IIQ. Developing the strategy to deliver & drive the right outcomes for a secure group, on prem and in cloud environments. Created roadmaps, implement KPIs, and drive change from a failed delivery by professional services to a delivering service. Took the program that was still in early life support with defects to a production environment onboarding over 90 applications both connected & disconnected within 10 months both non-sox & sox. With a roadmap to continue onboarding for the next 12-24 months.
Taken a basic CyberArk delivery & produced KPI's & moved the program from an onboard only to a fully managed service with session management. Managing teams of approx. 100 staff. Communicating to stakeholders at all levels.
SNR Technical Security Analyst – IAM at Sainsbury's (2019-01 – 2022-01)
Served as Technical lead for seamless execution of IAM and PAM\IDAM to assist in reducing risks by utilizing CyberArk, MFA, ProofPoint, Netskope, Centrify, and PKI. Design and support the group to drive the right outcomes for a securer group on prem and in cloud environments. Create HLD and LLD designs as well as implement KPIs, and drive change from basic human onboarding to programmatic onboarding that increased process efficiency.
Devise and implement CyberArk Remote Access, EPM, AAM, PTA & Conjur to reduce risk as expedient as business risk appetite allows.
SNR IT Security Operations Manager at Coventry Building Society (2017-01 – 2019-01)
Steered a highly-qualified team of 14 analysts and JML activity while serving as IAM Subject Matter Expert. Influenced society's perception of "Privileged Account Management" and "User Access Management" RBAC. Contributed to spearheading all phases of projects at an SME level from inception to completion while ensuring compliance with best practices (ISO 27001/2, NIST, and CIS).
Managed security operations ranging from SOC, Siem, DLP, vulnerability scanning, and cloud security. Developed and deployed a security incident management process focusing on identifying and mitigating security threats or incidents in real-time.
Senior Security Specialist at RBS (2015-01 – 2017-01)
Delivered thought leadership to a team of four analysts, RACF, and Infoman. Led user management process, including user entitlement reviews on RACF and Core Web. Enabled the bank to move from "upto 10 day" SLAs on user creation to "24 hr" SLAs through Joiner, Mover, and Leaver Simplification program. Automated manual reviews to identify vulnerabilities.
RACF Security Contractor at Co-Op Bank (2014-01 – 2015-01)
Executed and managed end-to-end separation project operations to build a secure environment within UAT for development staff to test code. Secure endevor installation and Lpars for seamless testing, Digicert creation, as well as writing Carla for reporting and administration. Maintained data integrity by securing LPARs. Held accountability for daily administration and Carla programming for the current RACF staff, including RBAC and zSecure tool package.
RACF Security Contractor at Santander\Computacentre (2009-01 – 2014-01)
Managed several IBM mainframes, including users, groups, datasets & resources (DB2 & CICS) by leveraging RACF and zSecure toolsets. Utilized Carla to research and formulate adhoc reports. Administered UNIX users within the bank's proprietary system.
Security Analyst | Reconciliation Clerk | MIRAS Clerk at Alliance & Leicester PLC