Identity Management Consultant

Company: Eames Consulting
Apply for the Identity Management Consultant
Location: London
Job Description:

IAM Security Consultant (FS / Insurance) – Outside IR35

If you think you are the right match for the following opportunity, apply after reading the complete description.

Location: London (2 days onsite)

Start: ASAP

The Role

We’re looking for an experienced IAM / User Access Management Security Consultant to join a high-profile change and transformation programme within the insurance / financial services sector.

IAM/UAM is a key regulatory risk area. Around 1,200 internal users currently have access, but controls, structure, and governance are weak. Regulators have flagged this as a material risk, and this role is critical to fixing it.

You’ll be part of a 12-person transformation project team, helping to design, implement, and embed robust IAM controls across the organisation.

What You’ll Be Doing

  • Assessing and remediating IAM / UAM control weaknesses across a large internal user base
  • Mapping current access models and defining target-state IAM frameworks
  • Designing and implementing security and access controls aligned to regulatory expectations
  • Producing clear IAM reporting, audit artefacts, and control documentation
  • Supporting privacy, segregation of duties, and least-privilege principles
  • Working closely with security, risk, compliance, and technology stakeholders
  • Contributing hands-on to a change & transformation programme, not just advisory

Essential Experience (Non-Negotiable)

  • Strong IAM / UAM delivery experience (hands-on project work, not just theory)
  • Financial Services or Insurance sector experience – MUST have
  • Proven background with IAM tooling (e.g. SailPoint, xwzovoh Saviynt, CyberArk, Okta, etc.)
  • Experience operating in regulated environments with audit/regulatory scrutiny
  • Track record of mapping access, defining controls, and improving governance
  • Comfortable working onsite in London 2 days per week

Nice to Have

  • Experience remediating regulator-identified security risks
  • Exposure to large-scale internal user populations (1,000+ users)
  • Strong stakeholder communication and documentation skills

Posted: March 31st, 2026