Salary: £To be confirmed on application (our client has asked for this not to be advertised).
Location: Bristol 2 days per week
Contracting Authority: Government Client
Contract Length: to 31/03/2027
Clearance: SC
Person Specification
The role requires a proven RBAC and access governance lead who has led or assured RBAC design and implementation at enterprise scale. The postholder must operate with authority from day one, structure complex access control issues, challenge supplier designs, make evidence-based recommendations and provide confident direction across business, technical, security, data, architecture, supplier and operational stakeholders.
Essential experience and skills:
• Proven experience leading or assuring RBAC design and implementation in large-scale, complex enterprise transformation, ideally involving Oracle Fusion or comparable ERP, HCM, finance, commercial, analytics or corporate services platforms.
• Demonstrable experience working across multiple functions, business areas, user groups, security boundaries and delivery workstreams, while controlling complexity, role proliferation and local variation.
• Strong understanding of RBAC principles, access governance, least privilege, segregation of duties, auditability and role lifecycle controls.
• Understanding of how access control supports business processes, operational responsibilities, data protection and internal control requirements.
• Ability to translate process, data and operational requirements into clear access control expectations.
• Strong assurance capability, including reviewing supplier designs, challenging assumptions, identifying gaps and supporting evidence-based governance decisions.
• Credibility to direct, challenge and assure delivery partner activity, recognising common RBAC risks, design pitfalls, control weaknesses and implementation issues before they affect build, test, cutover or live operation.
• Understanding of Secure by Design, identity and access management, privileged access management, audit logging, compliance and operational security considerations.
• Ability to manage dependencies across architecture, security, data, testing, service management, functional design and business change.
• Strong communication and influencing skills, including explaining access control risks and decisions to technical and non-technical audiences.
• Ability to operate autonomously, structure ambiguity and drive progress ahead of Delivery Partner mobilisation.
Our dedicated team would be pleased to discuss in more detail how we may be able to help