Identity Security Privileged Access Architect

FNZ is a global wealth management platform provider.

Distributed
About FNZ

FNZ describes itself as 'wealth's growth platform', providing a global, end-to-end wealth management platform that integrates modern technology, business operations, and investment operations within a regulated financial institution connected to a universe of investment products. The company serves banks, wealth managers, insurance companies, and asset managers, with over US$2.5 trillion in assets on platform and nearly 30 million end investors served through its clients. Its offerings span wealth management platforms, advisor tools and productivity solutions, asset management distribution, and trade and post-trade securities services, along with a data platform combining an Operational Data Store, Analytical Data Warehouse, and Aggregated Data Warehouse to power analytics, machine learning, and generative AI insights. FNZ has notable clients including Santander, Colonial First State (CFS), Vanguard, Aviva, and Swedbank, and in 2025 announced a global five-year strategic partnership with Microsoft to integrate Azure AI Foundry, Microsoft Fabric, GitHub Copilot, and Microsoft 365 Copilot across its platform and operations. FNZ is backed by major institutional shareholders including Caisse de dépôt et placement du Québec (CDPQ), CPP Investments, Generation Investment Management, and Motive Partners.

View jobs by FNZ

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will design, automate and implement identity and privileged access management solutions. You will improve CyberArk services, mature privileged access controls, support governance, implement just-in-time and least-privilege processes, manage service accounts and user groups, monitor sessions, maintain security documentation, and collaborate with stakeholders on identity solutions.

Requirements

  • Strong experience with IAM lifecycle management
  • Strong knowledge of Entra ID Active Directory cloud identity and CyberArk
  • Strong secrets management knowledge for SSH keys passwords and certificates
  • Expert-level experience developing and managing formal security documents
  • Ability to manage stakeholders through security maturity improvements
  • Ability to communicate information security and risk concepts
  • CyberArk Guardian-level knowledge
  • Coding skills to support engineers and the Identity Security function
  • Knowledge of Microsoft Azure privileged account strategy and ownership

Responsibilities

  • Improve the CyberArk privileged access tool
  • Drive maturity of privileged access controls services and processes
  • Support security control governance and oversight
  • Support global technology strategy delivery
  • Maintain security policies and standards
  • Implement just-in-time and least-privilege processes
  • Support global CyberArk instances
  • Develop management patterns for non-human and service accounts
  • Identify AI risks in privileged access
  • Monitor user sessions
  • Support groups and users for key platforms and services
  • Deliver consistent global identity security services