- Own the JML process framework. Define standards, controls, escalation paths, and exception handling while the Service Desk executes routine provisioning against those standards.
- Conduct periodic user access reviews with business stakeholders, ensuring access entitlements remain appropriate, justified, and compliant.
- Identify and remediate access control gaps, segregation of duties conflicts, and governance weaknesses across supported platforms.
- Maintain clear, audit-ready documentation and evidence to support internal and external compliance reviews.
- Act as the primary point of escalation for non-standard or high-risk access decisions referred from the Service Desk.
Automation & Tooling
- Develop and maintain automation (e.g. PowerShell, Graph API, JQL) to reduce manual effort in access provisioning, reporting, and compliance tasks including tooling consumed by the Service Desk.
- Build and maintain access lifecycle automation where practical, reducing reliance on manual ticket-driven workflows.
- Identify and propose tooling improvements that improve accuracy, auditability, and operational efficiency.
- Maintain version-controlled scripts and automation assets to ensure reliability and supportability.
Reporting & Compliance Assurance
- Produce and maintain access, compliance, and platform health reports for governance, audit, and management oversight.
- Support phishing simulations, compliance campaigns, and audit readiness activities.
- Provide evidence and analysis to support internal audit, external review, or regulatory inspection.
- Monitor for anomalous access patterns or entitlement drift and elevate or remediate accordingly.
- Design and maintain Service Catalogue items and process documentation for access-related services including operating guides consumed by the Service Desk for transactional execution.
- Produce and maintain runbooks, access control standards, and training materials.
- Ensure all documentation is current, clearly written, and operationally fit for purpose.
Collaboration & Stakeholder Engagement
- Work closely with the Service Desk to ensure transactional JML processes are well-governed, consistently executed, and escalated appropriately.
- Engage with business stakeholders on access reviews, compliance activities, and platform changes.
- Collaborate with Security, Risk, and Corporate Support Engineering teams on access governance and platform security.
Experience and Skills
Technical
- Solid hands-on experience with Microsoft 365, Entra ID / Azure AD, Google Workspace, and Atlassian in an enterprise environment.
- A good understanding of RBAC, access governance, entitlement management, and Conditional Access.
- Demonstrable scripting and automation capability (e.g. PowerShell, Microsoft Graph API, JQL).
- Experience designing or owning JML process frameworks in a regulated or audit-sensitive environment, not just executing them.
- Familiarity with enterprise password management, MFA, and privileged access controls.
- Experience with Halo ITSM or equivalent ITSM platforms is desirable.
Operational & Governance
- Strong audit, compliance, and evidence-gathering mindset who is able to build and demonstrate a defensible control environment.
- Ability to identify access risk and proactively address control weaknesses.
- Experience supporting or preparing for internal or external audits.
- Comfortable working alongside a separate Service Desk function responsible for transactional delivery.
Ways of Working
- Process-driven and analytically minded. Comfortable defining how work is done, not just doing it.
- Strong documentation discipline and structured approach to knowledge management.
- Able to balance security and control requirements with operational pragmatism.
- Self-directed and capable of managing workload with light supervision.
#J-18808-Ljbffr