Requirements

Qualifications

  • 8+ years in identity and access management, including 2+ years leading IAM governance, strategy, or a senior technical IAM function. 

  • Demonstrable track record designing and operating access governance - access reviews/certification, RBAC models, and entitlement rationalisation at enterprise scale. 

  • Hands-on experience with Segregation of Duties and access governance over business applications such as Workday, NetSuite, or Salesforce. 

  • Operational expertise in Microsoft Entra ID and Okta - Conditional Access, federation, SCIM, OIDC/SAML. 

  • Experience with privileged access tooling (Entra PIM, Okta privileged access, JIT admin) and a record of reducing standing admin and orphaned accounts. 

  • Experience with non-human identity governance - service accounts, OAuth apps, secrets management. 

  • Compliance and audit fluency: ISO 27001, SOC 2, or SOX - able to design controls and produce audit-ready evidence. 

  • Ability to communicate governance and technical decisions clearly to senior business stakeholders, Finance, and Internal Audit. Fluent English. 

Benefits

Additional Information

We are the pioneers and trailblazers of a global IT Market Category (DEX) that is shaping the future of how the world works, giving our customers’ IT Teams total digital visibility across their enterprise. Our innovative solutions integrate real-time analytics, automation, and employee feedback across all endpoints. This enables our IT teams to solve complex technical challenges, create ever more productive workplaces, and deliver happy, satisfied employees in the digital workplace.

With over 1000 employees across 5 continents, Nexthink operates as One Team, connecting, collaborating and innovating to continuously grow. We call our employees ‘Nexthinkers’ and our commitment to diversity, inclusion, and equity is second to none. We currently have over 75 nationalities working with us, from all cultures and backgrounds, speaking many different languages.

If you are looking for a change and like a nice atmosphere, lots of challenges, and having fun while working, this is a great opportunity for you! Check what we offer: 

  • 💼 Permanent Contract and a competitive compensation package. 
  • 📍 Amazing centrally located offices near the Bernabeu Stadium. 
  • 🩺 Private Health Insurance (Sanitas) and daily meal vouchers of 11 EUR . 
  • 🏡 Hybrid work model balancing office and remote work. 
  •  🏖️ Flexible Hours and unlimited vacation (employees have unlimited paid time off on top of the 23 days of holidays we offer) plus 3 company-paid volunteer days. 
  • 🤸 Up to 25 EUR per month for a gym subscription. 
  • 🛴 Flexible compensation plan for childcare & public transportation.  
  • 🧑‍🏫 Reimbursement of up to 50% of the cost of English & Spanish classes. 
  • 🍉 Fresh fruit, cookies, and soft drinks in the office. 
  • 🍕 Regular company and team events like Pizza talks, Team Building activities, Christmas parties, hosting Meetups at the office and more! 
  • 📣  Bonuses for referring successful hires after three months of continuous employment. 

We set our pay ranges using objective criteria: the scope and level of the role, the skills it takes to do it well, and the relevant market data. Ranges are reviewed every year to remain competitive and fair. We're transparent about this because we think you deserve to know what you're working towards from day one.  In accordance with the EU Pay Transparency Directive (2023/970), we publish salary ranges on every Nexthink role. We won't ask what you currently earn or your previous salary. What matters to us is what this role is worth and whether it works for you. Nexthinkers come from all kinds of backgrounds, and that's what makes us stronger. We welcome applications from everyone.

Original Advert

Company Description

Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any application or network, before employees notice the issue. As the first solution to allow IT to progress from reactive problem solving to proactive optimization, Nexthink enables its more than 1,500 customers to provide better digital experiences to more than 25+ million employees. Dual headquartered in Lausanne, Switzerland and Boston, Massachusetts, Nexthink has 9 offices worldwide. #LI-Hybrid

Job Description

We are looking for an IAM and Access Control Lead to drive the identity strategy and operational excellence of Nexthink's corporate identity perimeter. This role leads a small team of senior engineers responsible for the platforms, policies and engineering standards that govern how every employee, contractor, service account and non-human identity gains, uses, and loses access across Nexthink's corporate environment.

You will partner with the CISO function on policy and standards, and with IT on operational delivery, owning the engineering execution end to end.

Key Responsibilities

IAM Governance & Strategy

  • Define and own the IAM governance model - principles, standards, decision rights, and operating cadence -as the durable internal foundation for the program.

  • Develop and maintain the multi-year IAM roadmap, sequencing capability build against business risk and investor expectations.

  • Establish the application prioritization and SaaS onboarding strategy: which systems are governed first, to what standard, and on what timeline.

  • Define role-based access control (RBAC) governance standards and the target access model across the corporate estate.

  • Scope, commission, and steer external specialist engagements (e.g. role mining, access-model optimization), retaining internal ownership of outcomes and standards.

Access Reviews & Certification

  • Design and operate the enterprise access review and certification framework - periodic, risk-based, and fully evidenced.

  • Run recurring access certifications across in-scope applications with documented, audit-ready evidence trails.

  • Establish and operate quarterly privileged access reviews; drive standing admin toward zero for all in-scope environments.

Business Application Access & Segregation of Duties

  • Establish access governance over core business applications - Workday, NetSuite, and Salesforce - in partnership with the application owners.

  • Lead Segregation of Duties (SoD) analysis: define the conflict ruleset, identify and remediate SoD conflicts, and operate ongoing monitoring.

  • Support SOX, ISO 27001, and SOC 2 audit readiness with documented controls, evidence, and remediation tracking; serve as IAM's primary interface to Internal Audit.

  • Lead NetSuite role design and Salesforce permission rationalization to align entitlements with least privilege and clean role definitions.

Identity Platform Operations

  • Own the engineering standards and roadmap for Microsoft Entra ID and Okta.

  • Define and enforce SSO standards across the SaaS estate, including SAML/OIDC integrations and SCIM provisioning.

  • Drive passwordless and non-phishable MFA adoption across all employee and privileged access scenarios.

Privileged Access & Just-In-Time Admin

  • Design and operationalise Just-In-Time admin access (Intune, Entra PIM, Okta privileged access).

  • Act as the technical escalation point for IAM incidents and high-severity access requests.

Non-Human Identity (NHI) Governance

  • Build and operate the inventory of service accounts, API keys, OAuth applications, and machine identities.

  • Define ownership, rotation, and deprovisioning standards for every NHI; eliminate orphaned and over-privileged service accounts across SaaS, GitHub, and cloud IAM.

Primary Metrics

  • Access certification completion rate and cycle timeliness

  • SoD conflicts identified vs. remediated (and open-conflict ageing)

  • SaaS estate onboarding coverage against the governance roadmap

  • SSO coverage across the SaaS estate; MFA exception rate

  • Privileged access SLA and standing-admin count

  • Orphaned account count; NHI owner coverage

DevOps Architect - Remote

Las Rozas - Madrid / A Coruña / Asturias / Barcelona / Cádiz / Canarias / España / Huelva / Madrid / Málaga / Murcia / Palma de Mallorca / Sevilla / Valencia / Zaragoza
New
Need a visa? No sponsorship mentioned here. Browse visa jobs