Key Accountabilities and Responsibilities
- Overall responsibility for the development and maintenance of EPM policies and procedures, encompassing all human and non-human privileged users.
- Delivery of the EPM service via our chosen software and service partners.
- Continuously improve the including alignment with IAM specific processes, to ensure the least privileged access is provided for the minimum time possible.
- Continuously improve EPM Endpoint rules and processes to enable the business to operate successfully with least privilege on Endpoints.
- Provide accurate data analytics to ensure visibility of key metrics and use of this data (combined with audit procedures) to ensure least privilege of users, just in time escalated privileges and no toxic privileged access.
- Identify EPM related risks and proactively work to ensure that these risks are identified, assessed and mitigated across the business.
- Engagement and communication with stakeholders across JLR to ensure awareness of EPM policies and procedures.
- Act as a point of escalation for any EPM alerts or issues which has been raised by other departments, or potentially from monitoring systems.
- Keep abreast of trends in information security and be able to propose proactive mitigation as appropriate
- Provide consultancy on EPM Best Practices to different stakeholders / teams
- Key Interactions
- IAM SME & Product Owner (part of the IAM Team)
- CISO and the wider Information & Cyber Security Leadership Team.
- Head of Enterprise, Data & Infrastructure & ED&I Leadership Team
- Head of IT Corporate Audit
Knowledge, Skills and Experience Essential :
Significant prior experience as a subject matter expert within Identity and Access Management, in particular deep technical knowledge of identity management and privilege escalation within a Microsoft Environment (Windows Operating Systems & Active Directory), Linux based operating systems (desktop & server), Core infrastructure (network, databases).Significant knowledge of Privileged Access Management governance principles and best practices and experience in managing information security risk relating to identitySignificant knowledge of Endpoint Privilege Management governance principles and best practices and experience in managing information security risk relating to privilege escalation on end points.Experience of working and influencing cross-functionally and managing external agenciesGood working knowledge of industry IT compliance standards, particularly in design and implementationExperience of relationship management of senior stakeholdersStrong IT skills, able to analyze data for reporting purposes and follow work instructionRelevant degree or equivalent experience preferredDesirable :Knowledge of privileged account management within a DevOps environment, including API Management platforms, containerization and cloud platforms (Google / Azure / AWS).Knowledge and experience in Information Security Auditing TechniquesKnowledge and experience in Managing Information Security for operational technology (e.g. PLCs, embedded systems in plant machinery)Knowledge and experience in Managing Information Security within a manufacturing organizationEssential :
An individual with a customer first mindset who is easy to do business with and makes people feel special, driven to deliver experiences that are personalized, transparent and dependable.An individual who is results driven, demonstrates, tenacity, drive and perseverance, with the ability to deliver in a complex, highly demanding environment.An individual with the ability to combine a short term, pragmatic focus with longer term planningAn individual who is resilient, energetic and enthusiastic, able to deliver results under pressure, whilst responding constructively to challenging new ideas and inputsAn individual who is able to challenge existing thinking in a positive way whilst building credibility and trust through experience and personal styleA good communicator who can communicate complex ideasAn effective team player, actively leads, develops and supports team membersSkills Required
Epm