A&
IDAM Security Advisor
Auto & General AustraliaBrief Description
The position
We're seeking an experienced and highly analytical IDAM Security Advisor to join our expanding team. This is a critical advisory role, reporting directly to the Head of Tech Security, where you will be instrumental in shaping our Identity and Access Management (IAM) future. You'll work closely with our team of IAM specialists, providing guidance and expertise to design, build, and implement our IAM strategy, policies, and standards, ensuring best-in-class coverage and adherence to best practices.
This role is for someone who thrives on influencing outcomes and driving strategic direction in a fast-paced environment.
Your Role Key Responsibilities
The position
We're seeking an experienced and highly analytical IDAM Security Advisor to join our expanding team. This is a critical advisory role, reporting directly to the Head of Tech Security, where you will be instrumental in shaping our Identity and Access Management (IAM) future. You'll work closely with our team of IAM specialists, providing guidance and expertise to design, build, and implement our IAM strategy, policies, and standards, ensuring best-in-class coverage and adherence to best practices.
This role is for someone who thrives on influencing outcomes and driving strategic direction in a fast-paced environment.
Your Role Key Responsibilities
- Strategic Leadership & Advisory: Provide expert advisory services on IDAM, including human, non-human, and machine identities, aligning with security, policy compliance, regulatory obligations, and zero-trust principles. Lead the strategic design and governance of our IDAM capabilities.
- IDAM Strategy & Architecture: Develop and maintain the enterprise IDAM strategy, roadmap, and target architecture. Define and drive our zero-trust architecture posture, leveraging identity as the primary control plane.
- Policy & Standards Development: Design, implement, and govern comprehensive IAM frameworks, policies, and standards covering identity lifecycle management, governance, administration (IGA), and Privileged Access Management (PAM).
- Authentication & Access Management: Lead the design and uplift of enterprise authentication capabilities, including Multi-Factor Authentication (MFA), passwordless, and adaptive/risk-based authentication. Define and enforce consistent access management policies.
- Privileged Access Management (PAM): Define and govern privileged access policies across on-premises, cloud (AWS, Azure, GCP), and third-party remote access environments, with a strong focus on Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, and Separation of Duties (SoD) models.
- Risk, Compliance & Assurance: Identify, assess, and mitigate IDAM-related security risks. Ensure controls comply with legislative and regulatory obligations (e.g., APRA CPS 234/230, ISO 27001).
- Stakeholder Engagement: Act as a Subject Matter Expert (SME), translating complex IDAM concepts and findings into business-relevant language for technical and non-technical audiences, including executive leadership. You will need strong skills to prepare and present business cases.
- Incident Response: Provide IDAM expertise during security incidents (e.g., account compromise, privilege escalation), supporting investigation, containment, and remediation efforts.
- Minimum 7 years of hands-on experience in Identity and Access Management roles, with significant expertise in Privileged Access Management (PAM).
- Proven experience (5+ years) with enterprise identity platforms, specifically OKTA and Entra ID (formerly Azure AD), including governance, configuration review, and security validation.
- Demonstrated experience implementing Zero Standing Privilege, Zero Standard Access, and Separation of Duties (SoD).
- Solid enterprise-level experience within complex environments.
- Strong understanding of PAM concepts: credential vaulting, session recording, password rotation, break-glass workflows, and security control validation.
- In-depth knowledge of authentication and authorisation concepts, including adaptive authentication, risk-based access controls, phishing-resistant MFA (FIDO2/WebAuthn), and policy enforcement.
- Familiarity with protocols/standards such as OAuth 2.0, OpenID Connect (OIDC), SCIM, and LDAP.
- Experience with cloud identity platforms (AWS IAM, Azure AD, GCP IAM).
- Exceptional analytical and problem-solving abilities with a meticulous eye for detail.
- Superior written and verbal communication skills, with a proven ability to craft compelling business cases and convey complex technical information clearly to diverse audiences.
- Strong stakeholder management and influencing skills, capable of driving consensus and progress without direct authority.
- Self-motivated, proactive, and a collaborative team player who thrives in a fast-paced, evolving environment.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent industry experience.
- Industry-recognised certifications such as CISSP, CISM, CISA, or CompTIA Security+.
- Previous experience within the Finance or Insurance industry, particularly in an APRA-regulated environment.
- Experience in security assurance, governance, risk, or audit functions.
- Join a highly collaborative and supportive security team where you'll be challenged and empowered to make a significant impact.
- We foster a culture of continuous learning and professional growth, all while ensuring we maintain a healthy work-life balance with our hybrid working model.
- Close to a variety of public transport and easy parking options, the Toowong office has excellent end of trip facilities (including secure bike storage and showers), outdoor spaces and plenty of modern collaborative areas to work and connect with colleagues.
- Conveniently based at Toowong Village tower with views of the mountains and the Brisbane River, our location is only 4 km from the city and provides access to retail, restaurants and other amenities.
- Be rewarded - we recognise high performance and reward our people for their hard work through bonuses and other perks.
- Work flexibility - with options to work from home two days per week.
- Options for leave - life happens, so we’ve got volunteer days, an additional paid ‘ME’ day, paid parental leave and the opportunity to purchase additional leave to cover all of the big stuff.
- Grow with us - we’ve got learning and professional development opportunities to suit everyone.
- Give back - our A&G Difference program gives you the power to change our community for the better through volunteering, fundraising and donation opportunities for causes that you’re passionate about.
- Take care of yourself - your wellbeing is important to us and our healthy mind and body hub, mental-health support and fitness discounts will help you be your best self.
- Celebrate the wins - we love sharing our successes and celebrating together - join us and you’ve got a ticket to our many on-site events throughout the year, family fun days and annual celebrations.
- Save money - as well as discounts on insurance products, we’ve teamed up with some incredible retailers, hospitality providers and others to bring you discounts on your purchases, no matter where you are in Australia.
- Auto & General (A&G) is the fastest-growing major Motor and Home insurer in Australia, providing insurance products and solutions to safeguard a brighter future for our customers and community.
- Our range of general insurance products including Car, Motorcycle, Home, Contents Pet and Travel products are delivered through our multi-award-winning brand Budget Direct and partnerships with leading brands - ING, Qantas, and Coles Insurance.
- We’re excited about the future and we’re always on the lookout for talented, passionate individuals who can help us achieve our goal of being Australia’s best insurer! If this sounds like you, apply today.
- Auto & General values individual differences and believes in fostering an inclusive culture that creates a great place to work for all.
- A note from Auto & General to recruitment agencies: We politely ask that you avoid making any approaches or sending any unsolicited resumes to our Recruitment Team or Hiring Leaders across our business. Auto & General is not responsible for any fees related to unsolicited resumes.