Identity & Access Management Administrator (80-100% FTE)
Lombard Odier Group · Luxembourg
Description du poste
About the role
Join Lombard Odier’s IT Operations team as an Identity & Access Management (IAM) Administrator. You will help secure and automate the identity lifecycle for over 3,000 employees as the firm moves toward Zero Trust, RBAC, and cloud‑hybrid models.
Key responsibilities
- Process and analyse access requests via ServiceNow, ensuring proper provisioning and de‑provisioning.
- Manage identities, accounts, and groups in Active Directory and Entra ID (Azure AD).
- Administer access rights for NTFS, file shares, and business applications; monitor Joiners/Movers/Leavers processes.
- Contribute to IAM automation through workflows, scripting and APIs.
- Support the evolution of access models (RBAC/ABAC) and integrate new applications (SSO, provisioning, federation).
- Participate in Zero Trust and identity‑first architecture transitions.
- Manage access assignment workflows, run recertification campaigns, and administer privileged access via PAM solutions.
- Handle sensitive access and secrets management (Vault) and support compliance audits (FINMA, ISO).
- Provide Level 2/3 IAM support and collaborate with Security, Infrastructure, Application, and Risk teams.
- Write and maintain technical procedures and IAM documentation.
Required profile
- Strong experience in Identity & Access Management.
- Excellent knowledge of on‑prem Active Directory and Entra ID / Azure AD.
- Good understanding of RBAC and ABAC concepts, SSO protocols (SAML, OAuth2, OIDC) and provisioning standards (SCIM).
- Experience with IAM/IGA tools such as SailPoint, One Identity, Saviynt or ServiceNow IAM.
- Familiarity with privileged access management solutions (e.g., CyberArk, BeyondTrust) and secret vault technologies.
- Exposure to compliance frameworks and audit requirements (FINMA, ISO).
Required skills
- Active Directory
- Entra ID / Azure AD
- RBAC / ABAC
- SAML, OAuth2, OIDC
- SCIM
- ServiceNow (ITSM)
- SailPoint, One Identity, Saviynt, ServiceNow IAM
- CyberArk, BeyondTrust (PAM)
- Vault (secrets management)
- Scripting / APIs
Questions fréquentes
Pourquoi signalez-vous cette offre ?
Postulez en 30 secondes
Entrez votre email pour postuler. Un compte sera cree automatiquement.
En continuant, vous acceptez nos conditions d'utilisation.
Deja un compte ? Connexion
Publie il y a 7 heures
Expire dans 1 mois
1 vues · 0 interesses
Boostez vos chances
Importez votre CV : nous vous proposons les offres qui matchent votre profil.
Analyse de votre CV en cours...
Lombard Odier Group
Luxembourg
Offres similaires
-
Data Annotator (French) – Remote, $15.3/hr
Crossing Hurdles Luxembourg -
Support applicatif IT – Gestion et amélioration des applications métiers
OPEN Luxembourg -
Data & AI Analyst – Performance & Operations
atHomeGroup Luxembourg -
Technical Application Specialist Senior
Altherias Luxembourg -
Ingénieur Système Windows & Cloud Azure
KEYTEO Luxembourg