StellenbeschreibungppSygnum is a global digital asset banking group, founded on Swiss and Singapore heritage. We empower professional and institutional investors, banks, corporates and DLT foundations to invest in digital assets with complete trust. Our team enables this through our institutional-grade security, expert personal service and portfolio of regulated digital asset banking, asset management, tokenization and B2B services. /p pIn Switzerland, Sygnum holds a banking licence and has CMS and Major Payment Institution Licences in Singapore. The group is also regulated in the established global financial hubs of Abu Dhabi and Luxembourg. /p pWe believe that the future has heritage. Our crypto-native team of banking, investment and digital asset technology professionals are building a trusted gateway between the traditional and digital asset economies that we call Future Finance. To learn more about how Sygnum’s mission and values are shaping this digital asset ecosystem, please visit sygnum.com and follow us on LinkedIn and X. /p h3Our Values /h3 pA key pillar of our success are the Sygnum values that define and unite us a team. We proudly call them our SYGN values. Sygnum has one of the most diverse teams in the industry. Diversity plays a central role in keeping our work culture open, our teams productive and energised, and our solutions at the forefront of the industry. In the spirit of our SYGN value to “grow and win together”, we fully embrace an equal opportunity mindset in the way we onboard, develop and promote our team members. /p h3About the role /h3 pAt a regulated digital asset bank, identity is the control plane. Who can access what, and under what conditions, is the difference between a good day and a regulatory incident. We are looking for an Identity Access Lead to own that control plane end to end: the strategy, the governance, and the engineering that makes it real. You will be the person Risk, the Board and the regulator turn to when identity is questioned. /p pThis is a senior role with a broad mandate, and it works differently across the two estates. You own the workforce identity platform outright (Microsoft Entra ID, delivered as code with Terraform, governed to FINMA standards), with dedicated engineering resource to deliver it. Client identity is built by our engineering teams and delivery partners, and there you own the strategy, the standards and the partner relationships rather than the code. Across both you set the roadmap and carry personal accountability for identity risk and audit-readiness. /p pYou will not be managing from a distance. You set direction, defend it, and then stay close enough to the work to challenge an architecture decision or review a Terraform pull request. If you want a layer of managers between you and the technology, this is not your role. If you want a mandate, real autonomy over how identity is engineered, and the authority to make identity decisions stick, it is. /p pA core part of the mandate is using AI as a force multiplier. We expect AI-assisted engineering and agentic automation to multiply what this function delivers, and we expect our identity architecture to be ready for a world where AI agents are first-class identities. We are already applying AI tooling in-house and want identity to go further with it. /p h3What You Will Own /h3 pIdentity Strategy and Direction /p ul liDefine and own the group identity strategy and multi-year roadmap across workforce and client identity, aligned to business, security and regulatory objectives /li liAct as product owner for identity: own the backlog and roadmap, prioritise, manage platform lifecycle, and balance run versus change across both estates /li liOwn the identity budget, vendor and outsource partner relationships, contracts and licensing, and act as the escalation point for identity services /li liTrack the market and the Microsoft Entra roadmap, and decide which capabilities we adopt, when, and why /li /ul h3Accountability, Governance and Regulatory /h3 ul liBe the accountable owner for identity risk and controls: access reviews, segregation of duties, entitlement attestation, policy recertification and least-privilege enforcement /li liOwn identity audit-readiness end to end, covering evidence, policy documentation and reporting, and front FINMA, external and internal audit on identity matters /li liOwn and report identity KPIs and KRIs to leadership and represent identity in architecture, risk and change governance forums /li liOwn the Joiner-Mover-Leaver, privileged access (PIM/JIT) and Conditional Access programmes, setting the target state and holding delivery to it /li liPartner with HR, Risk Compliance, Legal and Security to make sure identity controls reflect real business and regulatory need, not just good intentions /li /ul h3AI-Enabled Delivery and Non-Human Identity /h3 ul liSet the direction for AI as a force multiplier in identity: AI-assisted engineering, agentic automation of routine IAM operations (access requests, JML exceptions, evidence collection), and AI-supported governance (access review intelligence, entitlement drift and anomaly detection) /li liOwn the guardrails for safe AI use in a regulated environment: human-in-the-loop controls, auditability of AI-assisted changes, and alignment with risk and compliance /li liOwn the strategy for non-human and agentic identity, covering service accounts, workload identities and AI agents across their lifecycle, least-privilege scoping and credential management /li liMeasure and report the productivity and quality impact of AI adoption, honestly /li /ul h3Team and Delivery /h3 ul liLead, coach and grow the identity function; set technical standards and hold the bar on quality, security and auditability /li liOwn delivery of the workforce identity platform (PIM, Conditional Access, entitlement management, endpoint integration) as code, with CI/CD and full auditability, and steer the engineering rather than absorb it /li liOwn the identity strategy, security standards and requirements for the client-facing platform, and hold the engineering teams and delivery partners who build it to them, across authentication and federation flows (SAML, OAuth2, OIDC) and registration and recovery journeys /li liMake sure identity signals feed our SOC and that identity incident response is designed, rehearsed and effective /li /ul h3What Success Looks Like /h3 ul liAn identity strategy and roadmap that leadership, Risk and the regulator all recognise as credible /li liClear ownership of the workforce identity platform, and of the strategy, standards and partner relationships behind client identity /li liAutomation and evidence generation driven across access reviews, JML and privileged access /li liAgentic automation extended in identity operations, with the guardrails and audit trail to defend it /li liA clear standard owned for non-human and AI agent identity as that demand grows /li /ul pYou are an identity leader who grew out of hands-on IAM engineering into strategy and ownership, and never lost the ability to do the work. The role works two ways at once: you own workforce identity directly, and you own the strategy, standards and partners behind client identity without owning the engineers who build it. The second is the harder half, and it is what we will interview hardest on. In a role with this span you cannot only delegate. You can defend an identity roadmap to a regulator, a CIO and an engineer on the same day, and you are comfortable being the person accountable when identity is questioned. You lead through clarity and ownership rather than hierarchy, and you are at home in a regulated environment where audit-readiness is simply part of the job. /p ul li8+ years in IT, including 5+ years in IAM, with time as the accountable owner of an identity platform, programme or roadmap /li liTrack record defining and executing an identity strategy or target operating model in a regulated environment /li liStrong hands-on knowledge of Microsoft Entra ID (Conditional Access, PIM, entitlement management), enough to review a design, challenge it, and contribute to it directly /li liWorking experience of infrastructure-as-code delivery (Terraform, CI/CD) applied to identity /li liExperience owning identity strategy and standards for a client-facing or customer identity platform built by others, including the delivery partners involved, with enough protocol depth (SAML, OAuth2, OpenID Connect) to challenge their design /li liDeep command of IAM principles: RBAC/ABAC, least privilege, zero trust, privileged access and identity governance (access reviews, SoD, attestation) /li liDemonstrated use of AI tooling to increase engineering or operational output, with a considered view of its risks and limits /li liExperience owning vendor relationships, budgets and service management (incident, change, escalation) /li liSolid grounding in the regulatory landscape (FINMA, ISO 27001, NIST) and experience fronting internal or regulatory audit /li liExcellent stakeholder communication in English; German an advantage /li liDegree in Computer Science, Information Security or a related field, or equivalent practical experience /li liCIAM product ownership: treating client identity as a product with a roadmap rather than a service to keep running /li liExperience with non-human or machine identity governance, or securing AI agent access /li liFamiliarity with agentic frameworks and integrating AI into ITSM and engineering workflows (for example MCP or copilot tooling) /li liPeople leadership or mentoring experience, with the appetite to grow a function /li liCertifications: CISSP, CISM, Microsoft Identity certifications, or product ownership (CSPO or similar) /li liFinancial services, digital assets or crypto experience /li /ul pIf you are passionate about the potential of blockchain to shape Future Finance and your profile is a good fit for this position, please send us your CV today! /p /p #J-18808-Ljbffr