Jobs and Careers
VO

Senior Identity & Access GRC Engineer

Vodafone
Romaniafull_timeVerifiedPosted 6 Mar 2026

About the role

Join Us

At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.

Senior Identity & Access Governance Engineer is responsible for the design, implementation and continuous improvement of Identity and Access Management (IAM) controls across the organization to mitigate cyber risk and ensure compliance with local/international regulatory requirements. The role sits within the GRC function and acts as the technical authority for identity governance, ensuring the translation of policies into enforceable and auditable technical controls across on-premises, cloud and hybrid environments. This is a senior, hands-on role with governance responsibilities and cross-functional influence, who will design the operating model, define governance frameworks, implement risk-based controls and set the IAM maturity level at the enterprise level.

What you’ll do

Main Responsibilities:
Identity Control Governance and Design
• Define IAM governance framework, standards and control structure
• Design IAM operational model
• Translate IAM policies and standards into applicable technical controls
• Design and maintain enterprise-wide RBAC models aligned with business roles and risk levels
• Define and enforce Segregation of Functions (SoD) controls
• Establish Key Risk Indicators (KRIs) and control effectiveness metrics
• Maintain IAM documentation and record repository
• Create an IAM maturity roadmap
• Ensure alignment with Zero Trust principles
Identity Lifecycle Management (JML)
• Design and optimize Joiner Mover Leaver processes
• Ensure automatic provisioning and revocation of access in critical systems
• Reduce accounts orphaned, inactive, and overprivileged
• Integrate IAM with authoritative sources (HR and identity sources)
• Define SLAs for deprovisioning and monitor compliance
• Establish access recertification governance
Privileged access governance
• Define governance framework for Privileged Access Management (PAM)
• Reduce permanent administrative privileges
• Implement Just in Time (JIT) and least privilege / Just Enough Access (JEA) principles
• Ensure privileged session monitoring and logging controls
• Coordinate with CSOC for identity-based detection cases
Authentication and access control
• Ensure MFA enforcement for critical systems and high-risk users
• Validate SSO and federation configurations
• Define authentication assurance levels based on risk
• Align identity controls with Zero Trust principles
Support for compliance and audit
• Ensure alignment IAM with:
o NIS2
o ISO 27001
o GDPR
o Internal Security Policies
• Support for internal and external audits
• Provide IAM records and remediation plans
• Track and remediate IAM non-conformities
Oversee and modernize the IAM platform
• Assess the health of IAM/IdM platforms and lifecycle risks (EOL/EOS)
• Identify coverage gaps in applications and cloud environments
• Propose a modernization and improvement roadmap
• Lead the integration of new systems in the IAM area
Cross-functional collaboration
• Close collaboration with:
o IT Operations
o Network Operations
o HR
o Application Owners
o Cloud & DevOps Teams
o CSOC
o Business teams
• Act as SME in the identity area during security incidents
• Ensure the inclusion of identity risks in the enterprise risk register

Who you are

Experience
• 5–8+ years of experience in IAM or Identity Governance
• Experience in building or transforming IAM capabilities
• Hands-on experience with enterprise IAM platforms (SailPoint, Saviynt, OneIdentity, Okta, Microsoft Entra ID)
• Experience with PAM solutions (CyberArk, BeyondTrust)
• Strong knowledge of:
o RBAC / ABAC
o Segregation of Functions (SoD)
o SAML, OAuth2, OIDC
o LDAP / Active Directory
o MFA and conditional access policies
• Experience in regulated environments (telecom, financial, utilities – preferred)
• Experience in supporting audit and compliance programs

Technical Skills
• Enterprise IAM architecture and design
• JML frameworks
• Governance models for privileged access
• Authentication and federation architecture (SSO, MFA, conditional access)

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Vodafone

View company profile →