Job Summary
Standard Chartered’ s diverse footprint across 63 of the fastest growing markets in Asia, Africa and the Middle East create unique opportunities for passionate, motivated, and highly skilled people who want to make a difference. We are changing the way people think about banking. We are changing the way we do business – becoming the digital bank with a human touch. This is your opportunity to be part of a growth story in an industry that is reimagining how customers are getting better, faster experiences and convenience through digital technology.
Our Information & Cyber Security (ICS) team sits within the Transformation, Technology & Operations (TTO) function and is responsible for all mission-critical and enterprise-wide areas of cybersecurity, including identity and access management, global threat intelligence, data protection, malware protection, and application and infrastructure security. These are challenges that impact our clients globally.
Our ICS Portfolio team develops the platforms, drives the processes and builds partnerships on behalf of ICS. We thrive on providing solutions to complex issues, devoting time and energy to designing and delivering new and innovative solutions, and all in an environment that demands being risk-aware, not risk-averse. ICS chooses progress over perfection and aims to always participate with a constructive purpose. The team makes an impact wherever they are based, be it in our offices around the world, our Global Business Solution centres in China, India, Malaysia and Poland, or even from our home.
If tackling complex challenges excites you, then join our ICS Identity & Access Management team where you will get to collaborate and work on solutions across business and functions to drive the transformation and deliver better experiences to our customers. We constantly strive to reduce time-to-market and streamline our processes. We follow agile methodology and work to embed an improvement habit across the bank.
Now you have an opportunity to make a meaningful impact with a diverse and passionate team of creators, innovators, and achievers. With us, you’ll learn, be inspired, and make an impact every day. The success of our work hinges on how we use the unique diversity of our people to realise the effects we seek to achieve: Always on. Always safe. Always Simple.
Key Responsibilities
The Authorisation Security Team within the Identity and Access Management domain operates as an integrated model consisting of independent yet interconnected capabilities that together form a closed-loop control system. IAM Emerging Identity Security is responsible for ensuring the Bank is prepared for new identity types, trust models and access risks before they become systemic control issues.
The Lead, IAM Emerging Identity Security role sits within ICS Identity & Access Management and is responsible for identifying emerging identity and authorisation risks arising from AI, Agentic AI, non-human identities, autonomous systems, digital assets and evolving technology patterns. The role converts those risks into practical control patterns, standards, guardrails, capability requirements and investment priorities for the IAM Authorisation domain. It is a future-looking risk and capability role, not an AI product owner, technology delivery manager, research function or duplicate governance layer.
• Own the emerging identity security strategy and roadmap for IAM Authorisation.
• Assess identity and access risk arising from AI, Agentic AI, machine actors, autonomous systems, digital assets and future trust models.
• Translate emerging technology risk into practical Authorisation control patterns, standards and guardrails.
• Define reusable control expectations for emerging identity use cases before fragmented local solutions become embedded.
• Maintain visibility of emerging identity security debt, capability gaps and future control requirements.
• Convert horizon scanning, risk signals and technology change into IAM requirements, investment priorities and engineering outcomes.
• Provide input into Authorisation strategy, design and investment planning.
• Challenge unclear ownership, unmanaged access risk and one-off control responses where they may create systemic exposure.
Strategy
• Establish the forward-looking identity security strategy for emerging identity types and trust models.
• Ensure IAM capability roadmaps reflect future identity and access requirements across AI, Agentic AI, NHI, autonomous systems and digital assets.
• Develop reusable Authorisation control patterns that can be applied across emerging technology domains.
• Shape Authorisation design and investment planning by converting ambiguity into clear capability requirements.
• Partner with Enterprise Security Architecture, Technology, Risk and Cyber stakeholders to ensure emerging identity risks are understood early and translated into executable outcomes.
• Prevent fragmented, one-off control responses by promoting common standards, patterns and guardrails.
Business
• Act as a trusted advisor to IAM, Technology, Risk, Cyber and Architecture stakeholders on emerging identity and access risk.
• Help business and technology teams understand identity implications of new technology patterns before they scale.
• Provide clear, practical guidance on control expectations for AI, Agentic AI, NHI, autonomous systems and digital asset access patterns.
• Support prioritisation decisions where future identity risk, control debt and capability uplift compete for capacity.
• Translate emerging risks into business-relevant implications, practical Authorisation outcomes and senior stakeholder messaging.
• Engage with third-party vendors and industry sources where needed to inform capability direction, without becoming a vendor delivery manager.
Processes
• Establish mechanisms for horizon scanning across technology, threat, regulatory and industry developments relevant to identity and access.
• Define practical processes for assessing emerging identity risk and converting findings into Authorisation requirements.
• Maintain visibility of emerging identity security debt, unresolved ownership questions and capability gaps.
• Ensure standards, guardrails and control patterns remain proportionate, reusable and aligned to IAM Authorisation outcomes.
• Feed emerging identity requirements into engineering, architecture and investment planning processes.
• Maintain evidence of risk assessments, design rationale, accepted trade-offs and agreed remediation actions where required.
People and Talent
• Operate as a strategic security thinker and capability builder, not as a technology follower.
• Influence senior stakeholders and engineering teams through evidence, clarity and practical control reasoning.
• Coach teams on how emerging technology changes identity, privilege, trust and access risk.
• Build common understanding of reusable emerging identity control patterns across IAM and adjacent technology teams.
• Challenge assumptions constructively where new technology creates unclear ownership, unmanaged access risk or weak control accountability.
• Support capability development by identifying skills, knowledge and maturity gaps relevant to future identity security.
Risk Management
• Identify emerging identity and authorisation risks before they become systemic control issues.
• Assess risk from immature or evolving technology patterns where standards, ownership or industry practices remain unclear.
• Ensure AI, Agentic AI, NHI, autonomous system and digital asset access patterns have clear control expectations.
• Escalate material emerging identity risk, control gaps and ownership ambiguity through appropriate IAM, ICS and risk pathways.
• Challenge local optimisation where it creates enterprise-level Authorisation, privilege or access risk.
• Ensure evidence-based judgement is applied to risk assessments, control pattern design and capability prioritisation.
• Maintain traceable evidence of key decisions, residual risks, accepted debt and remediation commitments.
Governance
• Embed emerging identity security standards and guardrails into existing IAM, ICS, Architecture and delivery governance pathways.
• Avoid creating duplicate governance layers; use existing forums and decision paths wherever possible.
• Ensure control patterns and standards are traceable, defensible and aligned to Authorisation strategy.
• Provide evidence-based input into risk, audit, architecture and investment discussions.
• Ensure horizon scanning outputs are converted into operationally useful requirements, not research artefacts without ownership or outcome.
• Act as a role model for integrity, ethical behaviour and responsible security judgement.
Regulatory and Business Conduct
• Display exemplary conduct and live by the Group’s Values and Code of Conduct.
• Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
• Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters.
• Head of IAM Authorisation Security
• IAM Authorisation capability leads across Policy Engineering, Lifecycle, Privileged Access, Intelligence and related capabilities
• ICS Identity & Access Management Leadership Team
• Enterprise Security Architecture and Technology Architecture stakeholders
• Cyber Security Operations and Technology teams involved in AI, Agentic AI, NHI, autonomous systems and digital asset use cases
• Risk, Audit, Compliance and control stakeholders requiring confidence that identity controls are evolving with technology change
• Engineering, platform and delivery teams responsible for implementing Authorisation control patterns and requirements
• Third-party vendors and industry partners where relevant to emerging identity security capability assessment
• Embed Here for good and the Group’s brand and values within ICS Identity & Access Management. Perform other responsibilities assigned under Group, Country, Business or Functional policies and procedures.
• Strategic Security Thinker - anticipates emerging identity and access risks before they become systemic issues.
• Practical Translator - converts ambiguous technology change into executable control requirements, standards and patterns.
• Future-Looking Risk Owner - applies evidence-based judgement in regulated, audit-sensitive environments.
• Trusted Advisor - engages credibly across IAM, Technology, Cyber, Risk, Audit and Architecture stakeholders.
• Delivery-Oriented - relentless focus on achieving OKRs and outcomes.
• Strong Challenger - constructively challenges unclear ownership, weak control patterns and unmanaged access risk.
Our Ideal Candidate
• 15 +years of total experience as a cyber security professional with 8+years demonstrated experience defining and governing enterprise authorisation policy in regulated environments.Proven experience stabilising and transforming fragmented identity environments at scale, without disrupting business operations
• Strong understanding of IAM, Authorisation, PAM, IGA, cloud identity, non-human identities and emerging identity control models.
• Familiarity with AI, Agentic AI, machine actors, autonomous systems and digital assets from an identity, privilege and access risk perspective.
• Ability to assess identity risks from immature or emerging technology patterns where standards and ownership are still evolving.
• Ability to translate ambiguity into executable Authorisation control requirements, engineering outcomes and investment priorities.
• Experience operating across senior Technology, Cyber, Risk, Audit, Architecture and engineering stakeholders in a regulated, audit-sensitive environment.
Role Specific Technical Competencies
• Identity & Access Management
• Authorisation & Access Control Models
• Security Architecture
• Technology Risk Management
• Emerging Technology Security
• Stakeholder Influence & Strategic Consulting
About Standard Chartered
We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.
Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.
Together we:
- Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
- Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
- Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term
What we offer
In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.
- Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
- Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
- Flexible working options based around home and office locations, with flexible working patterns.
- Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
- A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
- Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.
Recruitment Assessments
Some of our roles use assessments to help us understand how suitable you are for the role you've applied to. If you are invited to take an assessment, this is great news. It means your application has progressed to an important stage of our recruitment process.
Visit our careers website www.sc.com/careers