UK remote
Identity and Access Management Lead
About this role
Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology- and data-driven group implementing a scientific approach to investing. Combining data, research, technology, and trading expertise has shaped our collaborative mindset, which enables us to solve the most complex challenges. QRT’s culture of innovation continuously drives our ambition to deliver high-quality returns for our investors.
You will join QRT as the Identity and Access Management Lead, owning the firm’s global identity and access security capability. This is a hands-on leadership role in which you will set the strategy, lead programmes, and remain close to the technology to ensure solutions are secure, automated, and practical for QRT’s engineering environment. Your Future Role within QRT Lead QRT’s IAM and IGA strategy, architecture, roadmap, and delivery.
Develop identity lifecycle management, application onboarding, entitlement governance, and access certification. Redesign Active Directory groups, legacy permissions, and access models, establishing clear ownership of applications, roles, entitlements, and access decisions. Develop pragmatic role- and attribute-based access models and improve the automation and accuracy of joiner, mover, and leaver processes. Own the global PAM programme, including the continued development and adoption of PrivX.
Redesign privileged access to production, infrastructure, cloud, and trading-critical environments. Reduce standing privileges through controlled, time-bound, and auditable access, with effective controls for administrative accounts, emergency access, and privilege escalation. Own the enterprise secrets-management programme and HashiCorp Vault platform. Define how credentials, certificates, API keys, and other secrets are created, stored, rotated, and revoked.
Reduce embedded, shared, and long-lived credentials, while establishing governance for service accounts, workloads, applications, and AI-agent identities. Lead authentication and authorisation programmes across the workforce, infrastructure, cloud, and internally developed applications. Develop strategies and reusable patterns for SSO, MFA, passwordless authentication, phishing-resistant credentials, applications, APIs, platforms, and production systems.