696,339open jobs
40,697companies
104,863added this week
Browse all
Location
In office
Seniority
Staff · 10+ years exp
Overview
Company
Impact
Profile match
StoneX Group Inc. is a global financial services enterprise that provides institutional-grade execution, clearing, and market infrastructure across diverse asset classes. The company connects commercial entities, institutional clients, and retail traders to global capital markets through specialized capabilities in commodities, foreign exchange, securities, and derivatives. Supported by a global regulatory footprint and advanced proprietary technology, it delivers market intelligence, risk management advisory, and cross-border payment solutions worldwide.

Overview

Connecting clients to markets - and talent to opportunity. With 5,400+ employees and over 80,000 institutional, commercial, and payments clients, we operate from more than 80 offices spread across six continents. As a Fortune 100, Nasdaq-listed provider, we connect clients to the global markets - focusing on innovation, human connection, and providing world-class products and services to all types of investors.Whether you want to forge a career connecting our retail clients to potential trading opportunities, or ingrain yourself in the world of institutional investing, StoneX Group is made up of four business segments that offer endless potential for progression and growth.

Business Segment Overview

Corporate: Engage in a deep variety of business-critical activities that keep our company running efficiently. From strategic marketing and financial management to human resources and operational oversight, you’ll have the opportunity to optimize processes and implement game-changing policies.

Position Purpose: As Identity Access Management Operations and Engineering Manager for IT Risk and Security, you will lead an IAM Operations and Identity Engineering function within StoneX, owning both the day-to-day identity service the firm depends on and the engineering of the platforms that deliver it. The estate runs core identity platforms such as Microsoft Entra ID with Active Directory, and Okta. Around them sit enterprise PKI, privileged access management, modern authentication and identity governance tooling, alongside legacy platforms now being retired. The ideal candidate will have experience working in a regulated financial environment and is a highly skilled, experienced and motivated leader willing to drive and grow our identity function across a globally distributed team.

Responsibilities

Primary duties will include:

  • Own the identity service catalogue end to end - joiner, mover and leaver processing, access request, entitlement and group administration, privileged account issuance, certificate services and application onboarding and the service levels each commitment carries.
  • Set the engineering and operations roadmap and act as technical design authority across both core identity platforms; Entra ID with hybrid directory services and Okta as well as identity governance and administration, privileged access management, PKI and certificate lifecycle, federation and single sign-on, and modern authentication.
  • Run the operational disciplines behind the service: incident and problem management for identity outages, change control, capacity and availability planning, and a documented escalation and on-call model that holds across time zones.
  • Design, implement and maintain IAM policies, procedures and standards to ensure the confidentiality, integrity and availability of sensitive data and resources.
  • Manage and lead a team (1-3) of identity engineers and analysts and building coverage so that every platform has more than one engineer, in more than one region, who can safely operate it.
  • Drive standing privilege down across the estate: run the access certification and recertification cycle, enforce segregation of duties and least privilege, eliminate orphaned and dormant accounts, and bring service, workload and other non-human identities under the same lifecycle discipline as people.
  • Act as identity manager you will be working with the team and supporting internal audit, external audit and client or scheme assessments including SWIFT CSP, inc. producing evidence on request, owning remediation actions and closing findings to agreed dates.
  • Automate the routine work out of the service: provisioning and deprovisioning driven from authoritative HR sources, policy and role-based entitlement in place of ticket-by-ticket approval and reporting instrumented so identity risk is visible without a manual data pull.
  • Own identity data quality and metrics, account ownership, lifecycle state, entitlement mapping and application registration as the foundation every downstream control, report and detection depends on.
  • Lead directory and tenant consolidation and legacy platform decommissioning, including the absorption of acquired identity estates onto the strategic Entra ID and Okta platforms, working directly with the application teams that depend on those platforms rather than routing every migration through the identity team.
  • Collaborate with cross-functional teams - security architecture, security operations, enterprise IT, HR, compliance and the business to assess IAM requirements and develop solutions that meet business needs.
  • Manage external partners and vendors against their commitments, and contribute to forecasting and planning for identity licensing, tooling and headcount.
  • Maintain IAM process documentation, including end-user guidance, runbooks and team processes and procedures, to a standard that allows work to move between regions without loss.

Qualifications

To land this role you will need:

  • This individual must be capable of working with internal and customer-facing teams to facilitate process improvement and customer support resulting in an enhanced security posture, reduction in risk and improvement in end-user experience. Excellent communication, strong organizational skills and attention to detail are essential.
  • 10+ years of overall professional experience, including at least 6 years in identity and access management and 3+ years leading and directly managing an IAM team, with accountability for both a production service and an engineering backlog; experience in financial services a plus.
  • Proven experience designing, implementing and managing complex IAM processes and solutions within large organizations.
  • Deep, current, hands-on knowledge of both core platforms. Microsoft Entra ID and Active Directory in a hybrid estate - tenant and forest design, synchronisation, conditional access, privileged role management and entitlement models. Okta - policy architecture, authentication journeys, application integration, lifecycle management and federation at scale.
  • Production delivery experience across at least three of: identity governance and administration tooling, privileged access management such as CyberArk, PKI and certificate lifecycle management, federation and single sign-on, and multi-factor or passwordless authentication.
  • Knowledge and implementation of key security concepts such as RBAC, zero trust, identity lifecycle automation, least privilege and identity governance, together with command of the underlying protocols SAML 2.0, OIDC, OAuth 2.0, SCIM, Kerberos and LDAP.
  • Automation and scripting ability sufficient to lead engineers credibly e.g. PowerShell, Microsoft Graph and the Okta management APIs with practical use of source control, pipelines and configuration-as-code applied to identity change.
  • Demonstrated operational management discipline: service level definition and reporting, incident, problem and change management, and oversight of vendors or managed service providers.
  • Direct experience owning identity controls through audit - preparing evidence, defending design decisions to auditors or regulators, and closing findings.
  • Understanding of a broad range of general information security domains, including networking, cybersecurity, governance and risk, and cloud.
  • Strong leadership skills with a track record of successfully leading distributed and cross-functional teams across time zones, including offshore or GCC-based staff.
  • Excellent communication and interpersonal skills to effectively collaborate with technical and non-technical stakeholders.

What makes you stand out:

  • You have an operations mindset and an engineer's instinct; you see an inefficient process and immediately think of how to automate it away rather than staff it.
  • You thrive in a fast-paced, collaborative environment and are comfortable juggling a live service and a delivery roadmap at the same time.
  • You are equally comfortable in both platforms and can reason about where a capability belongs - Entra ID or Okta - rather than defaulting to the one you know best.
  • You build people as deliberately as you build platforms, and you measure your team by the cover and capability it has, not by the hours it works.
  • You have experience in a Zero Trust program, or with securing non-human identities including service accounts, workload identities and emerging agentic and AI workloads.

Education / Certification Requirements:

  • Bachelor's or master's degree in computer science, information security or a related field (or equivalent experience).
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred.
  • Okta Certified Professional or Okta Certified Administrator preferred.
  • CISSP, CISM, CyberArk Defender or Sentry, or an equivalent identity governance credential preferred; ITIL foundation or equivalent service management training is a plus.

Working environment:

  • 4 days' work from office
  • Working hours aligned to India business hours, with overlap into CET / BST.
  • Team distributed across UK, US and Latam locations; participation in an escalation and on-call rotation should be expected.
  • Travel requirements, for leadership meetings and conferences.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
696,339 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$157k – $328k per year (Estimated) • Equity • In office • 10+ years exp • Master's Degree • Menlo Park
Python
AI/ML
Function Calling
AI Agents
LLM
LLM Guardrails
Tool Use
Machine Learning
Cybersecurity
Least Privilege
Apply
In office • 5+ years exp • Master's Degree
Python
AI/ML
AI Agents
Analytics
Microsoft Excel
Management
Agile
Apply
$32k – $39k per year • In office • Bachelor's Degree
Python
PowerShell
Bash
DevOps
Terraform
GCP
Azure DevOps
GitHub Actions
VMWare
CloudFormation
Prometheus
Azure
CI/CD
Windows Server
AWS
Docker
Kubernetes
Grafana
Bicep
Azure AKS
Windows
DNS
VPN
Cybersecurity
Microsoft Entra ID
Active Directory
Analytics
Informatica
Apply
$45k – $56k per year • Remote/Hybrid • Bachelor's Degree • Milan
JavaScript
TypeScript
AI/ML
Model Context Protocol
AI Agents
Frontend
GraphQL
Tailwind CSS
Next.js
React.js
DevOps
Rest API
Analytics
Informatica
Apply
$41k – $51k per year • In office • Bachelor's Degree
Python
PowerShell
DevOps
Terraform
Azure DevOps
GitHub Actions
CloudFormation
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Bicep
Amazon EKS
Azure AKS
AWS Lambda
Amazon EC2
Amazon S3
IAM
Amazon CloudWatch
AWS Step Functions
API Gateway
Cybersecurity
Microsoft Entra ID
Analytics
Informatica
Apply
In office • Internship
Apply
ITOC Team Lead 2 hours ago
In office • 7+ years exp • Bachelor's Degree
DevOps
VMWare
Datadog
SLI/SLO/SLA
Linux
Windows
BGP
Management
ServiceNow
ITIL
Service Desk
Apply
In office
DevOps
Linux
Windows
Apply
In office • 3+ years exp
PHP
PHP
WordPress
Drupal
AI/ML
Claude
ChatGPT
LLM
Management
Confluence
Jira
Marketing
HubSpot
Ahrefs
YouTube
Apply
Senior Staff Engineer 2 hours ago
In office • 8+ years exp
JavaScript
Java
SQL
Databases
RabbitMQ
Apache Kafka
Frontend
React.js
DevOps
Azure DevOps
Azure
CI/CD
Git
Management
Agile
Apply
See all jobs
This is one of many
696,339 more open roles from verified company boards, updated every day.