This job is with Fitch Group, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. Position Title: Associate Director, Identity Governance and Administration in our Manchester office. Fitch Group is currently seeking a Senior Identity and Governance Administration (IGA) Engineer based out of our Manchester office. As a leading, global financial information services provider, Fitch Group delivers vital credit and risk insights, robust data, and dynamic tools to champion more efficient, transparent financial markets. With over 100 years of experience and colleagues in over 30 countries, Fitch Group’s culture of credibility, independence, and transparency is embedded throughout its structure, which includes Fitch Ratings, one of the world’s top three credit ratings agencies, and Fitch Solutions, a leading provider of insights, data and analytics. With dual headquarters in London and New York, Fitch Group is owned by Hearst. Fitch is seeking a Senior IGA Engineer to drive the design, implementation, and ongoing evolution of our Identity and Governance Administration programme. This is a hands-on technical role that bridges engineering and governance: the successful candidate will build and maintain integrations between our IGA platform (SailPoint Identity Security Cloud) and the wider technology estate, design and implement lifecycle and access request workflows, and contribute to platform development using Python and modern tooling. Beyond the code, this person will be a credible technical voice in governance forums, audit engagements, and stakeholder conversations, able to articulate identity concepts clearly and translate business requirements into working solutions. How You’ll Make an Impact: Design, develop, and maintain integrations between SailPoint Identity Security Cloud and internal and external systems (HR platforms, cloud providers, SaaS applications, on-premises directories), using connectors, REST APIs, and custom rules/scripts. Build and maintain privileged-access integrations with Delinea Secret Server / Delinea Platform, including vault configuration, secret lifecycle, and external-secrets distribution. Author Python scripts and automation to extend IGA platform capabilities: provisioning logic, aggregation customisation, transformation rules, reporting pipelines, and operational tooling. Design and implement joiner–mover–leaver (JML) workflows, access request workflows, and access certification campaigns within SailPoint, aligning them to business policy and control requirements. Manage the full development lifecycle of IGA artefacts — version-controlled in Git, containerised where appropriate using Docker, and deployed through structured change processes. Operate and administer the IGA programme: account onboarding, entitlement management, role engineering (RBAC), separation of duties, least-privilege enforcement, and attestation cycles. Maintain and develop the IGA operations portal and team-facing tooling; Vue.js front-end experience is a practical advantage when extending or customising web-based components. Monitor platform health, integration performance, and connector status; raise and track issues with vendors or internal teams through timely resolution. Evidence of IGA governance controls for audit engagements (e.g., SOX, Dodd Frank, SOC 2, internal audit), preparing walkthroughs, evidence packs, and remediation tracking. Maintain technical documentation, runbooks, SOPs, and architecture diagrams; keep them current as integrations and workflows evolve. Manage non-human identities: service accounts, API credentials, certificates, and secrets — including lifecycle governance, vaulting, and distributed secrets via external-secrets patterns (e.g., AWS Secrets Manager, Azure Key Vault). Apply AI-assisted tooling and analytics to improve anomaly detection, provisioning accuracy, and audit evidence of quality, while maintaining governance and data-protection standards. Collaborate with engineering, operations, compliance, and security teams to onboard applications and services into the IGA platform, providing clear technical guidance throughout. You May be a Good Fit if: 5+ years of hands-on experience in an IGA or IAM engineering role, with demonstrable platform implementation and integration work — not solely operational support. Direct experience with SailPoint Identity Security Cloud (IdentityNow) including connector configuration, rule development, workflow design, and access certification — or equivalent depth on a comparable IGA platform. Experience with Delinea Secret Server / Delinea Platform for privileged access management, including vault setup, secret lifecycle, and integration with broader IGA workflows. Proficient in Python for scripting and automation in an enterprise context; comfortable writing maintainable, reviewable code and working within a Git-based development workflow. Practical experience with Docker for containerising tooling and services; understanding of how containers fit into a modern integration and deployment pipeline. Strong integration experience: designing and implementing API-based (REST/SOAP) connections between IGA platforms and external systems such as HR systems, cloud identity providers, ITSM platforms, and directory services. Solid understanding of IGA and governance concepts: JML lifecycle, RBAC, least privilege, separation of duties, access certification, privileged session management, and break-glass procedures. Familiarity with directory services and cloud identity platforms (e.g., Entra ID / Azure AD, Active Directory, Amazon AWS) and common enterprise environments (Linux, Windows Server). Experience supporting audit or regulatory engagements (SOX, Dodd Frank, SOC2), including evidence preparation, control walkthroughs, and remediation tracking. Strong written and verbal communication skills; able to present technical concepts clearly to both engineering peers and non-technical stakeholders and auditors. Experience with collaboration and documentation tools such as Microsoft 365 (SharePoint Online, Teams) and the Atlassian suite (Confluence, Jira). What Would Make You Stand Out: Experience with Vue.js or a comparable JavaScript front-end framework, particularly in the context of extending or building identity-related web interfaces or portals. Exposure to secrets-management patterns using external secrets operators or cloud-native vaults (AWS Secrets Manager, Azure Key Vault, Oracle Wallet). Relevant certifications in identity or security domains (e.g., SailPoint Certified IdentityNow Engineer, CISSP, CISM, CISA, Security+) are beneficial but not mandatory. Familiarity with infrastructure-as-code or CI/CD tooling in the context of deploying identity integrations and automation. Experience contributing to identity programme strategy, not just execution: connector roadmaps, lifecycle policy design, or IGA platform selection. Experience using AI tools to improve engineering productivity, accelerate analysis, reduce repetitive work, and strengthen the quality and consistency of technical deliverables. Hands-on experience with AI coding assistants for code generation, refactoring, debugging, test creation, documentation, and code review, with appropriate human oversight and security controls. Why Choose Fitch: Hybrid Work Environment: 3 days a week in office required based on your line of business and location A Culture of Learning
Associate Director, Identity Governance and Administration employer: Fitch Group
Fitch Group is an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration within its London-based Media Strategy & Communications team. Employees benefit from a hybrid work environment, competitive compensation, and ample opportunities for professional growth, making it an ideal place for those looking to make a meaningful impact in the financial services sector.