Job description
Role: Head of Access Management Control
Location: Abu Dhabi
Role Purpose:
To lead, govern, and continuously enhance the Access Management Control framework across the bank by driving robust Identity Access Management (IDAM) practices, strengthening Segregation of Duties (SoD), and embedding automation, enhancing controls, and governance standards. The role ensures effective stakeholder engagement, regulatory compliance, and optimization of access lifecycle processes across UAE and international operations.
To work with stakeholders in enhancing access management processes, controls and onboarding new applications in Identity Access Management tool (IDAM) and enhance the reviews process, SOD and implement Role Mining as per standard matrices.
To advise and support the business units in establishment and maintaining an adequate Role-Based Access profiles across their operating systems in ADIB UAE and International expansion, this will help demonstrate segregation of duties and authorized system activities according to job roles and responsibilities.
To supervisory review of user's definition and systems access process including setting-up new applications, applying the change requests of parameterization/configuration, creating new profiles or groups and maintain the existing profiles, groups, privileges/access rights and users.
Support and participate in new systems, enhanced processes, new initiatives, centralization of activities and handle assigned tasks by Head of BCM&ICD.
Key accountabilities of the role:
Governance & Control Framework
- Establish and continuously enhance the Access Management Governance Framework, aligned with regulatory expectations and internal policies (RCSA, audit, compliance).
- Ensure effective implementation of Segregation of Duties (SoD) and principle of least privilege across all systems.
- Lead periodic RCSA reviews, control testing, and assurance reporting for Access Management.
- Drive closure of audit findings, regulatory observations, and control gaps related to IAM.
- Define and enforce access lifecycle controls (joiner, mover, leaver, privileged access, periodic certification).
- Establish governance over third-party / managed service access controls, ensuring periodic validation and monitoring.
Automation & Digital Enablement
Drive and own automation roadmap for Access Management, including:
- IDAM platform enhancements
- Workflow digitization and straight-through processing
- Automated access certification and SoD checks
- Role mining and intelligent access profiling
- Lead development of dashboards and MIS reporting (KPIs/KRIs) to provide real-time control visibility.
- Collaborate with IT to embed preventive controls within systems (automated validations, system-enforced SoD).
Promote data-driven decision-making using analytics for access anomalies, trends, and risk indicators.
Information Security & ITD Collaborations
- Work closely with GISD and ITD to:
- Define and enhance enterprise-wide IAM strategy and standards
- Onboard new applications into IDAM in a controlled and timely manner
- Define and maintain SoD rulebooks and access risk matrices
- Implement role mining frameworks and optimization strategies
- Ensure alignment with GISD on:
- Information Security policies impacting access management
- Privileged Access Management (PAM) controls
- Identity governance best practices
- Act as the primary interface between Operations, GISD, and ITD for IAM-related initiatives.
Support GISD in implementing security-driven enhancements and ensuring compliance with bank-wide security standards.
Access Management Operations
- Oversee end-to-end User Access Management (UAM) operations, including:
- Access provisioning, modification, and revocation
- Review and approval of access requests and changes
- Maintenance of profiles, roles, and security groups
- Supervise onboarding of new applications, including:
- Defining UAM baseline requirements
- Performing system testing and control validation pre-implementation
- Plan and execute periodic access reviews and certifications.
Team Management & Capability Building
Lead and manage the UAM / IJAM team performance, including:
Goal setting, performance reviews, and coaching
Capacity planning and workload allocation
Build a strong control culture within the team, ensuring adherence to policies and procedures.
Develop team capabilities through:
Training programs (IAM, SoD, tools, regulatory expectations)
Knowledge sharing and continuous learning initiatives
Drive succession planning and Emiratization support, where applicable.
Ensure consistent quality, timeliness, and compliance across all deliverables.
Continuous Improvement & Transformation
Identify and eliminate manual inefficiencies and redundant controls.
Lead process re-engineering initiatives to improve turnaround time and control effectiveness.
Benchmark against industry best practices and implement enhancements accordingly.
Support centralization and standardization initiatives across geographies.
Specialist Skills / Technical Knowledge Required for this role:
Strong expertise in Identity & Access Management (IAM / IDAM) frameworks, including user lifecycle management (Joiner–Mover–Leaver), role-based access control (RBAC), and identity governance
Proven experience in Access Management Governance frameworks, including RCSA, control testing, audit engagement, and regulatory compliance
Hands-on experience with IDAM tools and platforms (e.g., ServiceNow, IAM suites, workflow tools), including application onboarding, access certification, and role mining.
Advanced stakeholder management and communication skills, with ability to engage Business, ITD, GISD, Risk, Audit, and Compliance functions effectively
Demonstrated leadership and team management capability, including performance management, coaching, and capability development
Strong process improvement and re-engineering skills, with the ability to identify inefficiencies and drive standardization and control optimization.
Previous experience required (if any):
12–15 years of progressive experience in Access Management, Identity & Access Management (IAM), and IT Controls, preferably within banking or financial services.
Proven experience in leading enterprise-wide Access Management or IAM functions, including governance, control design, and operational oversight.
وصف الوظيفة
الدور: رئيس إدارة التحكم في الوصول
المكان: أبوظبي
هدف الدور:
قيادة الحوكمة والتحسين المستمر لإطار عمل إدارة الوصول عبر البنك من خلال تطبيق ممارسات قوية لإدارة الهوية والوصول (IDAM)، وتعزيز فصل الواجبات (SoD)، وتضمين الأتمتة وتحسين الضوابط ومعايير الحوكمة. يضمن الدور مشاركة أصحاب المصالح بشكل فعال، والامتثال التنظيمي، وتحسين عمليات دورة الوصول عبر عمليات الإمارات العربية المتحدة والتوسع الدولي.
العمل مع أصحاب المصلحة لتعزيز عمليات إدارة الوصول والضوابط وتوفير التطبيقات الجديدة في أداة إدارة الهوية والوصول (IDAM) وتحسين عملية المراجعة، وفصل الواجبات وتنفيذ تنقيب الأدوار وفقاً للمصفوفات القياسية.
تقديم المشورة والدعم للوحدات التجارية في إنشاء والحفاظ على ملفات وصول قائمة على الدور عبر أنظمة تشغيلهم في الإمارات العربية المتحدة وعمليات التوسع الدولية، مما يساعد في إظهار فصل الواجبات وأنشطة النظام المصرح بها وفقاً للأدوار والمسؤوليات الوظيفية.
للمراجعة الإشرافية لتعريف المستخدم وعملية وصول الأنظمة بما في ذلك إعداد التطبيقات الجديدة، تطبيق طلبات التغيير للتهيئة/التخصيص، إنشاء ملفات أو مجموعات جديدة والحفاظ على الملفات والمجموعات والامتيازات/حقوق الوصول والمستخدمين الموجودة.
تقديم الدعم والمشاركة في الأنظمة الجديدة، والعمليات المحسّنة، والمبادرات الجديدة، وتوحيد الأنشطة والتعامل مع المهام المعينة من قبل رئيس BCM&ICD.
المسؤوليات الأساسية للدور:
الإطار الحوكمي والضبط
- إنشاء وتحسين مستمر لإطار حوكمة إدارة الوصول، متوافق مع التوقعات التنظيمية والسياسات الداخلية (RCSA، التدقيق، الامتثال).
- ضمان التطبيق الفعال لفصل الواجبات ومبدأ الحد الأدنى للوصول عبر جميع الأنظمة.
- قيادة مراجعات RCSA الدورية، واختبار الضوابط، وتقرير الضمان لإدارة الوصول.
- دفع إغلاق نتائج التدقيق والملاحظات التنظيمية والفجوات الضبطية المتعلقة بـ IAM.
- تحديد وتنفيذ ضوابط دورة الوصول (الانضمام، النقل، الانسحاب، الوصول المميز، الشهادات الدورية).
- إرساء حوكمة على ضوابط وصول الطرف الثالث/المزودين، وضمان التحقق والمراقبة الدورية.
الأتمتة والتمكين الرقمي
قيادة وتملك خريطة طريق الأتمتة لإدارة الوصول، بما في ذلك:
- تحسينات منصة IDAM
- ارتحال سير العمل والتحول الرقمي للمعالجة المباشرة
- شهادات الوصول الآلية وفحص SoD
- تنقيب الأدوار وملف تعريف الوصول الذكي
- قيادة تطوير لوحات البيانات والتقارير MIS (KPIs/KRIs) لتوفير رؤية تحكمية في الوقت الفعلي.
- التعاون مع تكنولوجيا المعلومات لدمج ضوابط وقائية ضمن الأنظمة (التحقق الآلي، SoD يطبق من النظام).
تعزيز اتخاذ القرار القائم على البيانات باستخدام التحليلات لاكتشاف الشذوذ في الوصول والاتجاهات ومؤشرات المخاطر.
الأمن المعلوماتي وتعاون ITD
- العمل بشكل وثيق مع GISD وITD لـ:
- تحديد وتعزيز استراتيجية IAM ومعايير على مستوى المؤسسة
- إدراج تطبيقات جديدة في IDAM بشكل مضبوط وفي الوقت المناسب
- تحديد وصيانة كتب القواعد لـ SoD ومصفوفات مخاطر الوصول
- تطبيق أطر تنقيب الأدوار واستراتيجيات التحسين
- التأكد من التوافق مع GISD بشأن:
- سياسات الأمن المعلوماتي التي تؤثر على إدارة الوصول
- ضوابط إدارة الوصول المميز (PAM)
- أفضل ممارسات حوكمة الهوية
- التصرف كواجهة أساسية بين العمليات وGISD وITD لمبادرات IAM.
دعم GISD في تنفيذ التحسينات المعززة الأمنية والتأكد من الامتثال لمعايير الأمن المصرفي الشامل.
تشغيل إدارة الوصول
- الإشراف على عمليات إدارة وصول المستخدمين من البداية للنهاية، بما في ذلك:
- توفير الوصول، والتعديل، وإلغاء الوصول
- مراجعة واعتماد طلبات الوصول والتغييرات
- الصيانة للملفات والدور ومجموعات الأمان
- الإشراف على إدراج تطبيقات جديدة، بما في ذلك:
- تحديد متطلبات UAM الأساسية
- إجراء اختبارات النظام والتحقق من الضوابط قبل التنفيذ
- تخطيط وتنفيذ مراجعات وصول وشهادات دورية.
إدارة الفريق وبناء القدرات
قيادة وإدارة أداء فريق UAM / IJAM بما في ذلك:
بناء ثقافة تحكم قوية داخل الفريق، مع الالتزام بالسياسات والإجراءات.
تطوير قدرات الفريق من خلال:
قيادة تخطيط التعاقب ودعم الإمارات العربية المتحدة، حيثما كان ذلك مناسباً.
ضمان اتساق الجودة والالتزام والوقت في جميع الأعمال التسليم.
التحسين المستمر والتحول
تحديد وإزالة أوجه الكسل اليدوية والضوابط الزائدة.
قيادة مبادرات إعادة هندسة العمليات لتحسين فترة الاستجابة وفعالية الضبط.
المقارنة مع أفضل الممارسات الصناعية وتنفيذ التحسينات وفقاً لذلك.
دعم مبادرات المركزية والتوحيد عبر المناطق الجغرافية.
المهارات المتخصصة / المعرفة الفنية المطلوبة لهذا الدور:
خبرة قوية في إطار عمل إدارة الهوية والوصول (IAM / IDAM)، بما في ذلك إدارة دورة حياة المستخدم (الانضمام-الانتقال-الانسحاب)، والتحكم في الوصول القائم على الدور (RBAC)، وإدارة الهوية
خبرة مثبتة في أطر حوكمة إدارة الوصول، بما في ذلك RCSA، واختبار الضوابط، وتدقيق الامتثال التنظيمي
خبرة عملية مع أدوات ومنصات IDAM (مثل ServiceNow، مجموعات IAM، أدوات سير العمل)، بما في ذلك إدراج التطبيقات، وشهادات الوصول، وتنقيب الأدوار.
مهارات متقدمة في إدارة أصحاب المصلحة والاتصالات، مع القدرة على التواصل بشكل فعال مع الأعمال، ITD، GISD، المخاطر، التدقيق والامتثال
قيادة وقدرات إدارة الفريق، بما في ذلك إدارة الأداء والتوجيه وتطوير القدرات
مهارات تحسين العمليات وإعادة الهندسة قوية، مع القدرة على تحديد الكفاءات غير الفعالة ودفع التوحيد والتحكم الأمثل.
الخبرة السابقة المطلوبة (إن وجدت):
12–15 سنة من الخبرة التطويرية في إدارة الوصول، الهوية والوصول (IAM)، والضوابط التقنية وتكنولوجيا المعلومات، ويفضل في البنوك أو الخدمات المالية.
خبرة مثبتة في قيادة وظائف إدارة الوصول على مستوى المؤسسة، بما في ذلك الحوكمة، تصميم الضوابط، والإشراف التشغيلي.
"