Why this role exists:
This role exists to scale, secure, and automate our user access management infrastructure, ensuring zero-trust integrity at high velocity. You’ll help us protect our core IT ecosystem by managing the end-to-end employee access lifecycle, establishing standardized access profiles, leveraging modern automation and AI-driven tools, and meeting strict operational SLAs and security standards.
What you’ll drive:
Strategy & outcomes
Lead and optimize end-to-end Employee Lifecycle access workflows (Onboarding / Dismissal / Change Position): ensure seamless access provisioning during onboarding, timely revocation upon offboarding, and structured access reviews during internal transfers or role changes.
Own and govern the process of designing, standardizing, and maintaining corporate Access Profiles across departments to align with least-privilege principles.
Measure and track operational SLAs, proactively eliminating bottlenecks in the access request pipeline to maintain high customer satisfaction (CSAT).
Optimize operational processes by driving access lifecycle automation and minimizing manual intervention.
Discovery & decisions
Design, validate, and maintain role models (roles, sub-roles, permission sets, and Access Profiles) across corporate systems, continuously identifying and mitigating access anomalies.
Initiate and define requirements for automated testing of role-model functionality and access controls across systems.
Partner with Talent Department, IT, and engineering teams to onboard new corporate systems into the centralized Access Flow platform and align access profiles with organizational changes.
Delivery & execution
Leverage AI agents and LLM-powered automation tools to optimize repetitive operational tasks, accelerate ticket analysis/triaging, and streamline documentation workflows.
Process complex, escalated access tickets swiftly and securely, serving as a trusted gatekeeper for critical permissions.
Analyze complex access rights data, identify permission inconsistencies, and resolve access drift across platforms.
Build and maintain comprehensive internal documentation for SOPs, access profile matrices, role definitions, and access governance frameworks.
What makes you a GR8 fit:
Must-have:
2+ years of hands-on experience in Information Security, IAM, or IT Operations / Systems Administration / L3 Support with a strong focus on access management.
Proven experience managing Onboarding / Dismissal / Change Position workflows: automated/manual provisioning during onboarding, revoking access upon offboarding, and role adjustments upon job changes.
Practical experience creating, standardizing, and auditing Access Profiles and Role-Based Access Control (RBAC) models across corporate tools and systems.
Strong technical understanding of enterprise identity and access tools (e.g., Okta, CyberArk, Active Directory, PAM, SSO, and federation protocols).
Understanding and practical experience with AI tools / AI agents (e.g., prompt engineering, AI copilots, or agentic workflows) to automate routine operational tasks, reporting, or data processing.
Solid understanding of core access control principles: RBAC, ABAC, Principle of Least Privilege, and Zero Trust.
SLA- and quality-driven mindset with experience managing high-volume operational requests without compromising security standards.
Strong analytical skills with the ability to navigate and validate complex permission structures across diverse systems.
Clear communication skills—ability to explain technical security policies and requirements to non-technical stakeholders.
Fluency in Ukrainian or Russian; Intermediate+ level of English.
Nice-to-have:
Working knowledge of security compliance frameworks and audit requirements (PCI DSS, ISO 27001) in the context of access management and user access reviews.
Hands-on experience integrating AI agents or custom LLM workflows into internal IT/IAM automation pipelines (e.g., via API


