Application Security / Authorization Management Consultant (IAM and PAM)
Working conditions
Experience: 5+ years
Contract type : B2B Contract
Start Date: Early June 2025
Contract Duration: Until approximately December 31, 2025, with potential for extension
Engagement: Full-time
Work Arrangement: Primarily remote; occasional presence in Berlin may be required
🔧 Role Overview
We are in search of a seasoned consultant to spearhead the implementation of DORA guidelines and address compliance-related challenges within our client’s infrastructure. The ideal candidate will possess deep expertise in Identity and Access Management (IAM) and Privileged Access Management (PAM), coupled with a strong background in application security.
🛠️ Key Responsibilities
Assist in formulating a strategic vision for authorization management processes and tools
Contribute to the overhaul of release, testing, and IT change management procedures, ensuring seamless integration with existing IT interfaces
Lead project management initiatives to drive implementation efforts
Analyze and refine authorization frameworks to enhance security posture
Develop comprehensive Segregation of Duties (SoD) matrices for both business and IT environments
Design and implement a structured joiner-mover-leaver process tailored for external personnel
Draft specifications and establish processes for effective Privileged Access Management
Revise and enhance protocols for penetration testing in alignment with DORA requirements
Plan, coordinate, and assess penetration tests, including the development of associated risk analyses
Formulate guidelines and procedures to bolster cloud security and promote secure software development practices
🎯 Desired Expertise
Extensive experience in IAM and PAM domains
Proven track record in application security, with familiarity in MaRisk and DORA regulations
Demonstrated ability in conceptual design and project management
Knowledge of authorization management within cooperative banking systems
Familiarity with the bit tool from bit Informatik GmbH is advantageous
Proficiency in Active Directory is a plus
Self-driven with a proactive approach to project advancement
Strong determination and motivation to achieve project goals