Head of Identity Security (all humans)
fulltime_permanent manager 85000-90000 EUR/yearJob Overview
Make a difference in the financial life of millions of people: At Erste Digital you are co-creating the digital future, in which better financial health is possible. #believeinyourself
We are part of Erste Group β the largest banking group in Central and Eastern Europe with more than 2,500 branches and over 45,000 employees. Our more than 2,000 IT experts and enthusiasts are the bank's Digital Muscle.
Help shape the next generation of Cyber & Information Security at Erste Digital
We are evolving our security organization around clear missions, accountable services and stronger collaboration across domains. As Head of Department, you will shape the capability together with your teams and peers rather than inherit a fixed organizational blueprint. You will be accountable for outcomes, people leadership, service maturity and cross-Group value.
Your Mission
Build and evolve trusted, reusable identity and access capabilities that allow people, applications and machines to authenticate, receive appropriate access and consume services securely across Erste Digital and the Group.
What you will shape and be accountable for
Evolve Identity Security from individual IAM solutions into a coherent, reusable identity platform and service ecosystem.
Set direction across identity lifecycle, entitlement and role management, access governance, authentication, authorization, federation and identity data.
Create identity services that are easy to consume by application and platform teams through standardized APIs, connectors, patterns and self-service capabilities.
Establish scalable approaches for roles, entitlements and authorization that reduce application-specific access logic and enable consistent policy enforcement.
Improve automation, data quality and transparency across identity lifecycle and access-certification processes.
Prepare the identity capability for non-human identities, workloads, automation and AI-enabled services without creating parallel or fragmented control models.
Guide the transition from fragmented or solution-specific capabilities towards a coherent service-oriented target architecture while maintaining dependable day-to-day operations.
Group first - Built to scale beyond one entity
Think Group First: design identity capabilities for Group consumption wherever a shared service is realistic and creates value.
Where central consumption is not feasible, provide reusable reference architectures, APIs, standards, blueprints and implementation patterns so entities can apply the same principles consistently.
Align with Group Security, Holding and relevant entities before creating local-only solutions where common patterns or shared capabilities are possible.
Treat interoperability and portability as design requirements: a strong solution should not only work locally, but help simplify identity across the Group.
What success looks like
Identity and entitlement data is trustworthy enough to support automated, context-aware access decisions.
Authentication, authorization and federation are provided through consistent capabilities with strong security and low user friction.
Role and entitlement models are understandable, scalable and increasingly reusable instead of being recreated application by application.
Developers and application teams can consume identity services through clear patterns, APIs and connectors instead of building their own security mechanisms.
Orphaned, excessive and outdated access rights are reduced through reliable lifecycle and review processes.
Other Group entities can consume the capability directly or reuse its patterns, standards and blueprints.
Who benefits from your work
Employees, developers, solution managers, application owners, IAM owners, platform teams, HR/IT processes, auditors, Holding functions and Group entities benefit from simpler access, stronger authentication and authorization, more reliable identity information and reusable identity services.
Make Your Resume Now