Back to search
Sygnum Bank Linkedin · Posted 2d ago

Identity & Access Lead

Switzerland

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

About Sygnum

Sygnum is a global digital asset banking group, founded on Swiss and Singapore heritage. We empower professional and institutional investors, banks, corporates and DLT foundations to invest in digital assets with complete trust. Our team enables this through our institutional-grade security, expert personal service and portfolio of regulated digital asset banking, asset management, tokenization and B2B services.


In Switzerland, Sygnum holds a banking licence and has CMS and Major Payment Institution Licences in Singapore. The group is also regulated in the established global financial hubs of Abu Dhabi and Luxembourg.


We believe that the future has heritage. Our crypto-native team of banking, investment and digital asset technology professionals are building a trusted gateway between the traditional and digital asset economies that we call Future Finance. To learn more about how Sygnum’s mission and values are shaping this digital asset ecosystem, please visit sygnum.com and follow us on LinkedIn and X.


Our Values

A key pillar of our success are the Sygnum values that define and unite us a team. We proudly call them our SYGN values. Sygnum has one of the most diverse teams in the industry. Diversity plays a central role in keeping our work culture open, our teams productive and energised, and our solutions at the forefront of the industry. In the spirit of our SYGN value to “grow and win together”, we fully embrace an equal opportunity mindset in the way we onboard, develop and promote our team members.


About the role

At a regulated digital asset bank, identity is the control plane. Who can access what, and under what conditions, is the difference between a good day and a regulatory incident. We are looking for an Identity & Access Lead to own that control plane end to end: the strategy, the governance, and the engineering that makes it real. You will be the person Risk, the Board and the regulator turn to when identity is questioned.

This is a senior role with a broad mandate, and it works differently across the two estates. You own the workforce identity platform outright (Microsoft Entra ID, delivered as code with Terraform, governed to FINMA standards), with dedicated engineering resource to deliver it. Client identity is built by our engineering teams and delivery partners, and there you own the strategy, the standards and the partner relationships rather than the code. Across both you set the roadmap and carry personal accountability for identity risk and audit-readiness.

You will not be managing from a distance. You set direction, defend it, and then stay close enough to the work to challenge an architecture decision or review a Terraform pull request. If you want a layer of managers between you and the technology, this is not your role. If you want a mandate, real autonomy over how identity is engineered, and the authority to make identity decisions stick, it is.

A core part of the mandate is using AI as a force multiplier. We expect AI-assisted engineering and agentic automation to multiply what this function delivers, and we expect our identity architecture to be ready for a world where AI agents are first-class identities. We are already applying AI tooling in-house and want identity to go further with it.


What You Will Own

Identity Strategy and Direction

  • Define and own the group identity strategy and multi-year roadmap across workforce and client identity, aligned to business, security and regulatory objectives
  • Act as product owner for identity: own the backlog and roadmap, prioritise, manage platform lifecycle, and balance run versus change across both estates
  • Own the identity budget, vendor and outsource partner relationships, contracts and licensing, and act as the escalation point for identity services
  • Track the market and the Microsoft Entra roadmap, and decide which capabilities we adopt, when, and why


Accountability, Governance and Regulatory

  • Be the accountable owner for identity risk and controls: access reviews, segregation of duties, entitlement attestation, policy recertification and least-privilege enforcement
  • Own identity audit-readiness end to end, covering evidence, policy documentation and reporting, and front FINMA, external and internal audit on identity matters
  • Own and report identity KPIs and KRIs to leadership and represent identity in architecture, risk and change governance forums
  • Own the Joiner-Mover-Leaver, privileged access (PIM/JIT) and Conditional Access programmes, setting the target state and holding delivery to it
  • Partner with HR, Risk & Compliance, Legal and Security to make sure identity controls reflect real business and regulatory need, not just good intentions


AI-Enabled Delivery and Non-Human Identity

  • Set the direction for AI as a force multiplier in identity: AI-assisted engineering, agentic automation of routine IAM operations (access requests, JML exceptions, evidence collection), and AI-supported governance (access review intelligence, entitlement drift and anomaly detection)
  • Own the guardrails for safe AI use in a regulated environment: human-in-the-loop controls, auditability of AI-assisted changes, and alignment with risk and compliance
  • Own the strategy for non-human and agentic identity, covering service accounts, workload identities and AI agents across their lifecycle, least-privilege scoping and credential management
  • Measure and report the productivity and quality impact of AI adoption, honestly


Team and Delivery

  • Lead, coach and grow the identity function; set technical standards and hold the bar on quality, security and auditability
  • Own delivery of the workforce identity platform (PIM, Conditional Access, entitlement management, endpoint integration) as code, with CI/CD and full auditability, and steer the engineering rather than absorb it
  • Own the identity strategy, security standards and requirements for the client-facing platform, and hold the engineering teams and delivery partners who build it to them, across authentication and federation flows (SAML, OAuth2, OIDC) and registration and recovery journeys
  • Make sure identity signals feed our SOC and that identity incident response is designed, rehearsed and effective


What Success Looks Like

  • An identity strategy and roadmap that leadership, Risk and the regulator all recognise as credible
  • Clear ownership of the workforce identity platform, and of the strategy, standards and partner relationships behind client identity
  • Automation and evidence generation driven across access reviews, JML and privileged access
  • Agentic automation extended in identity operations, with the guardrails and audit trail to defend it
  • A clear standard owned for non-human and AI agent identity as that demand grows


Our ideal candidate

You are an identity leader who grew out of hands-on IAM engineering into strategy and ownership, and never lost the ability to do the work. The role works two ways at once: you own workforce identity directly, and you own the strategy, standards and partners behind client identity without owning the engineers who build it. The second is the harder half, and it is what we will interview hardest on. In a role with this span you cannot only delegate. You can defend an identity roadmap to a regulator, a CIO and an engineer on the same day, and you are comfortable being the person accountable when identity is questioned. You lead through clarity and ownership rather than hierarchy, and you are at home in a regulated environment where audit-readiness is simply part of the job.


Essential

  • 8+ years in IT, including 5+ years in IAM, with time as the accountable owner of an identity platform, programme or roadmap
  • Track record defining and executing an identity strategy or target operating model in a regulated environment
  • Strong hands-on knowledge of Microsoft Entra ID (Conditional Access, PIM, entitlement management), enough to review a design, challenge it, and contribute to it directly
  • Working experience of infrastructure-as-code delivery (Terraform, CI/CD) applied to identity
  • Experience owning identity strategy and standards for a client-facing or customer identity platform built by others, including the delivery partners involved, with enough protocol depth (SAML, OAuth2, OpenID Connect) to challenge their design
  • Deep command of IAM principles: RBAC/ABAC, least privilege, zero trust, privileged access and identity governance (access reviews, SoD, attestation)
  • Demonstrated use of AI tooling to increase engineering or operational output, with a considered view of its risks and limits
  • Experience owning vendor relationships, budgets and service management (incident, change, escalation)
  • Solid grounding in the regulatory landscape (FINMA, ISO 27001, NIST) and experience fronting internal or regulatory audit
  • Excellent stakeholder communication in English; German an advantage
  • Degree in Computer Science, Information Security or a related field, or equivalent practical experience


Desirable

  • Product ownership experience: backlog management, roadmap prioritisation, agile delivery
  • CIAM product ownership: treating client identity as a product with a roadmap rather than a service to keep running
  • Experience with non-human or machine identity governance, or securing AI agent access
  • Familiarity with agentic frameworks and integrating AI into ITSM and engineering workflows (for example MCP or copilot tooling)
  • People leadership or mentoring experience, with the appetite to grow a function
  • Certifications: CISSP, CISM, Microsoft Identity certifications, or product ownership (CSPO or similar)
  • Financial services, digital assets or crypto experience


If you are passionate about the potential of blockchain to shape Future Finance and your profile is a good fit for this position, please send us your CV today!

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search