Head of Identity & Access Management (IAM)
Summary
Builds a digital bank's entire identity layer from scratch: customer-facing CIAM (MFA, biometrics, passwordless) plus workforce IAM (SSO, directory services, PAM, RBAC) while satisfying CBE regulatory requirements. Leadership role requiring 10+ years in IT security with deep IAM/CIAM/PAM architecture experience in banking or fintech.
Envision Employment Solutions is currently looking for a Head of Identity & Access Management (IAM) for one of our partners, a leading Digital Bank!
THE ROLE
Every login, every customer authentication, every privileged access request runs through the architecture you design, from a blank page. You're building both sides of identity at once, the customer-facing experience that has to feel invisible and secure at the same time, and the workforce controls that keep the bank's critical infrastructure locked down. Get it right, and identity becomes the thing nobody thinks about because it just works, safely, every time.
WHAT YOU’LL DO
- Design and build the enterprise IAM and CIAM framework entirely from scratch, defining modern identity lifecycle workflows, authentication standards, and authorization models
- Partner with the Product team to architect secure, high-availability, low-friction consumer authentication experiences, including multi-factor authentication, biometric integration, and passwordless options, balancing rigorous bank security with a seamless digital banking experience
- Implement robust workforce identity controls, Single Sign-On (SSO), Enterprise Directory services, and automated Privileged Access Management (PAM) workflows to protect critical infrastructure and cloud environments
- Partner with cloud security and network engineering to enforce continuous identity verification, least-privilege access, and conditional access policies across cloud-native microservices
- Automate user provisioning, de-provisioning, and role-based access control (RBAC) to eliminate identity sprawl and streamline internal HR-to-IT workflows
- Establish regular access recertification campaigns, audit logging, and reporting mechanisms to satisfy internal reviews and CBE regulatory examinations
WHAT WE’RE LOOKING FOR
- 10+ years of cumulative IT and information security experience, including 4 to 5 years specializing in IAM, CIAM, and PAM architecture and leadership within banking, financial services, or advanced fintech environments
- Hands-on expertise with modern identity protocols (OIDC, OAuth 2.0, SAML), cloud identity providers (e.g., Azure AD/Entra ID, Okta, Ping Identity), and modern CIAM architectures
- Solid understanding of Central Bank of Egypt (CBE) cybersecurity circulars, authentication requirements, and data privacy guidelines
- Professional credentials such as CISSP, Certified Identity and Access Manager (CIAM), or vendor-specific expert certifications are strongly preferred
- A builder mindset, thriving in a fast-paced, from-scratch environment, able to balance extreme security rigor for financial data with rapid, agile product delivery
- Excellent cross-functional collaboration skills, bridging product engineering, security operations, and executive stakeholders
YOU’LL THRIVE HERE IF YOU
- You'd rather architect identity from first principles than patch together an inherited mess of directories and permissions
- You believe a login should feel effortless to the customer and be uncompromising underneath
- You treat least-privilege access as a default, not an exception you get to when there's time
- You can translate an identity architecture decision into something both a regulator and a product team understand
- You want to build the layer that every other system in the bank ultimately trusts
Skills
As published by workable · 21 questions · 13 written answers
Basics
First name, Last name, Email, Headline, Phone, Address, Photo, Education, Experience, Summary, Resume, Cover letter
Pick from a list (8)
- How did you hear about us?
- Are you currently based in Egypt? If not, are you willing to relocate to Egypt for this role?
- This is a full-time, on-site role (9 AM to 6 PM). Are you comfortable and available to work on-site during these hours?
- Do you have 10+ years of cumulative IT and information security experience, including 4 to 5 years specializing in IAM, CIAM, or PAM architecture and leadership?
- Has this experience been within banking, financial services, or an advanced fintech environment?
- Do you have hands-on experience with identity protocols such as OIDC, OAuth 2.0, or SAML?
- Do you have hands-on experience with cloud identity providers such as Azure AD/Entra ID, Okta, or Ping Identity?
- Do you hold a certification such as CISSP or a vendor-specific identity certification?
Written answers (13)
- If you were referred to this role by a recruiter, please provide their name.
- How would you rate your English proficiency (written and spoken)?
- Describe your experience designing an IAM or CIAM framework from scratch. What was the scope and what did you prioritize first?
- Walk us through a consumer authentication experience you've architected, such as MFA, biometrics, or passwordless login. How did you balance security with user experience?
- Tell us about your experience implementing Privileged Access Management (PAM) or Single Sign-On (SSO) for workforce identity. What was the environment and scale?
- Describe your experience enforcing Zero Trust principles or conditional access policies across cloud-native microservices.
- Walk us through how you've automated identity lifecycle processes (provisioning, de-provisioning, RBAC). What problem was it solving?
- Tell us about your experience with access recertification campaigns or audit logging for regulatory examinations. What did that process look like?
- Describe your working knowledge of CBE cybersecurity circulars or similar regulatory authentication requirements.
- Tell us about a time you had to bridge a gap between product engineering and security operations on an identity-related decision. How did you resolve it?
- What is your current monthly net salary?
- What are your expected monthly net salary requirements?
- When can you start? (Notice Period)