RBAC Lead - SC in Newport

RBAC Lead - SC in Newport

Newport Full-Time On-site
A

Job Description \n Job Title: Role-Based Access Control (RBAC) Lead - SC Location: Bristol/Hybrid (2 days/week on site) Contract Duration : 31/3/27 Daily Rate : Β£600/day (Umbrella) IR35 Status: Inside IR35 \n Security Clearance: SC \n The RBAC Lead will be responsible for: \n \n Establishing and maintaining the authority-side RBAC plan, roadmap, milestones, dependencies, risks, issues and decisions required to support design, build, testing, assurance, operational readiness and programme planning, with delivery manager support. \n Acting as the Authority lead for RBAC, representing the organisations interests in planning, design, assurance and governance discussions with delivery partners and internal stakeholders. \n Ensuring RBAC coverage across Oracle Fusion, FDI analytics, integrations, operational tooling, approved extensions and all other in-scope CSM applications or services. \n Setting, maintaining and assuring RBAC principles, design standards and decision criteria for role design, access allocation, exception handling and future operational governance. \n Assuring Delivery Partner RBAC design and build activity against agreed RBAC principles, CSM design principles, architecture standards, Secure by Design, data governance and operational requirements. \n Ensuring RBAC is designed around business roles, processes, organisational responsibilities and data access needs, not individual preferences or local workarounds. \n Ensuring the RBAC model supports segregation of duties, least privilege, auditability, access reviews and controlled role creation, amendment and retirement. \n Prioritising vendor-standard and seeded roles wherever appropriate, with adapted or custom roles used only where justified, approved and documented. \n Managing RBAC deviations from agreed principles, design standards or vendor-standard roles through CSM governance, ensuring decisions, approvals, risk acceptances and rationale are documented. \n Identifying, managing and escalating RBAC risks, issues, assumptions and dependencies, including segregation of duties, excessive or privileged access, data exposure, testing readiness and operational handover. \n Coordinating authority-side input from functional programmes responsible for Business RBAC, together with security, data, enterprise architecture, service management, testing, internal controls, business change and supplier teams. \n Defining Authority expectations for RBAC artefacts, including role catalogues, role mapping matrices, segregation of duties matrices, access control policies, test scenarios and governance documents. \n Reviewing Delivery Partner outputs and providing evidence-based feedback on gaps, risks, inconsistencies and areas requiring further development. \n Facilitating workshops with functional, technical and security stakeholders to clarify role requirements, access patterns and operational support needs. \n Aligning RBAC design across Finance, HR, Commercial, Service Management, FDI analytics, integrations and approved extensions to avoid role proliferation and inconsistent access patterns. \n Ensuring coherent RBAC design across all user groups, functions, business processes and in-scope system functionality, resolving inconsistencies, duplication, gaps and conflicting access patterns before they impact delivery or live operation. \n Overseeing and assuring Functional programme Business RBAC, while leading EATD responsibility for Technical RBAC, including clear separation between functional, data, privileged, technical administration, service support and integration or automated access. \n Working with testing teams to ensure scenario-based testing confirms users can perform required activities and cannot access functions or data outside their role. \n Supporting the future RBAC operating model, including role ownership, access approvals, joiner-mover-leaver processes, periodic access reviews and exception management. \n Providing concise updates, escalations and recommendations to CSM governance forums where decisions, trade-offs or risk acceptance are required. \n \n Essential experience and skills: \n \n Proven experience leading or assuring RBAC design and implementation in large-scale, complex enterprise transformation, ideally involving \n Oracle Fusion or comparable ERP, HCM, finance, commercial, analytics or corporate services platforms. \n Demonstrable experience working across multiple functions, business areas, user groups, security boundaries and delivery workstreams, while controlling complexity, role proliferation and local variation. \n Strong understanding of RBAC principles, access governance, least privilege, segregation of duties, auditability and role life cycle controls. \n Understanding of how access control supports business processes, operational responsibilities, data protection and internal control requirements. \n Ability to translate process, data and operational requirements into clear access control expectations.

RBAC Lead - SC in Newport employer: Aspect Resources

At our Abingdon facility, we pride ourselves on being an excellent employer that values technical expertise and fosters a collaborative work culture. With competitive daily rates and a commitment to employee growth through hands-on experience in control and instrumentation systems, we offer a unique opportunity for professionals to thrive in a supportive environment. Our dedication to inclusivity, as demonstrated by our Disability Confident and Armed Forces Covenant commitments, ensures that all employees feel valued and empowered to contribute meaningfully to our projects.

A

Contact Details:

Aspect Resources Recruitment Team