Principal IAM Engineer
FUJIFILM Life Sciences Biotechnologies Denmark ApS · Hillerod, Denmark
About The Role
Join a team where access done right protects patients. FUJIFILM Biotechnologies powers life-changing biologics for partners around the globe. Every one of those medicines runs on validated, regulated systems — and on knowing exactly who has access to them, and why. As our Principal IAM Engineer, you will own the identity governance capability end to end in a GxP environment. Your work will directly safeguard regulated operations, enable secure productivity for our global workforce, and ensure our access controls and evidence stand up to audit and inspection — making a measurable contribution to the success and trust of our organization.
The Opportunity
Within Global Digital Workplace and IS&O, you will own what the IGA platform does, what gets built next, and how it performs. This role blends product leadership with hands-on platform expertise across Omada Identity and SailPoint. You will define functional design, direct specialist partners, and ensure changes land without disrupting access or compliance.
You’ll work closely with Quality, Cybersecurity, HR, application owners, and colleagues across global sites. In this environment, getting access right is a patient safety and regulatory matter — not just an IT one.
What You’ll Do
Product Ownership & Backlog
· Own the IGA product backlog: gather requirements from business, Quality, and Cybersecurity stakeholders, prioritize against capacity, and set the release plan.
· Translate access policy and control requirements into functional designs, user stories, and acceptance criteria.
· Make the trade-off calls when certification campaigns, onboarding demand, and deployment work compete for the same weeks — and communicate them clearly.
· Own functional testing and UAT, and represent IGA in change control and release governance.
· Report progress, risks, and capacity constraints to IS&O leadership in terms stakeholders can act on.
Platform Configuration & Service Ownership
· Perform hands-on configuration and maintenance of the IGA platform: policies, workflows, rules, forms, request catalogue, and reporting.
· Maintain joiner, mover, and leaver configuration for employee, contractor, partner, and service identities.
· Own the role model, entitlement catalogue, birthright access, and approval flows.
· Own identity data quality against authoritative sources, including correlation and attribute standards.
· Act as senior functional escalation for provisioning failures, campaign issues, and access-related incidents.
Access Certification & GxP Evidence
· Run the access certification and recertification cycle: campaign design, scoping, scheduling, execution, and closure of revocations.
· Apply RBAC, segregation of duties, and least privilege in the access model and review scope.
· Own audit evidence and act as the IAM point of contact for internal audits, external audits, and regulatory inspections.
· Ensure IGA processes align with applicable GxP expectations, GAMP 5, EU Annex 11, 21 CFR Part 11, and internal policy.
Platform Delivery Leadership
· Lead the functional design and delivery of IGA platform work — deployments, upgrades, migrations, and major integrations — aligned to global standards.
· Own the design and migration of access models, lifecycle processes, and certification approaches across platform change.
· Define connector, integration, and data requirements with delivery partners and platform engineering, and validate what they deliver through functional testing.
· Ensure delivery meets validation and change control requirements by design.
· Plan and sequence application onboarding so change lands without disrupting access for the business.
Delivery Partner Leadership
· Direct a team of specialist delivery resources day to day: allocate work, set expectations, review quality, and unblock delivery.
· Bring partners up to speed on our environment, standards, and regulatory obligations so their output meets requirements first time.
· Hold delivery partners to scope and quality standards.
Why This Role Matters
· You will enable a secure, reliable identity lifecycle at global scale, ensuring the right people have the right access at the right time.
· Your governance and evidence underpin audit readiness, regulatory confidence, and business continuity in a GxP context.
· Your leadership in platform change will keep our global workforce productive while protecting validated systems and sensitive data.
· Your work directly supports our mission to deliver high-quality biologics safely and efficiently for patients worldwide.
Minimum Education Requirements
· Bachelor’s degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related field, or equivalent professional experience.
· Relevant IAM or IGA platform certification strongly preferred.
Minimum Experience Requirements
· 10+ years of IT experience, including 6+ years focused on identity governance and administration.
· Hands-on, production-grade configuration experience on a major IGA platform — Omada Identity, SailPoint (IdentityIQ or Identity Security Cloud), or equivalent. Experience with either Omada or SailPoint is a strong advantage.
· Demonstrated experience leading IGA platform work as the functional owner — an implementation, migration, major upgrade, or equivalent — not only participating in one.
· Experience directing specialist or system integrator teams and being accountable for the quality of what they deliver.
· Proven product ownership skills: backlog management, requirements definition, prioritization against real capacity, and stakeholder negotiation.
· Proven experience owning joiner-mover-leaver processes, role models, and access request flows in a global enterprise.
· Demonstrated experience running access certification campaigns end to end, including revocation follow-through.
· Experience in a regulated life sciences, pharmaceutical, biotechnology, or comparable GxP environment, including audit and validation support.
· Working knowledge of Microsoft Entra ID and Active Directory as they relate to provisioning and access governance.
What Success Looks Like
· Identity lifecycle runs reliably and automatically across our global sites.
· Certification campaigns complete on schedule, with clear evidence available on demand.
· A well-governed, maintainable role and entitlement model that scales with the business.
· Platform work — deployments, upgrades, migrations — delivered to scope, quality, and validation requirements.
· Access controls and evidence that stand up confidently to GxP audit and inspection.
If you want both depth and scope — to be hands-on in IGA while shaping the product that secures a global, regulated enterprise — we’d love to hear from you.
This is a global position that will support all our FUJIFILM Biotechnologies sites. Benefits and compensation will be governed by the location that you are based from and considered your home site.
As part of any recruitment process, FUJIFILM Biotechnologies collects and processes personal data relating to job applicants. The organisation is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations and may share this as part of the global recruitment process with hiring managers in Europe and the United States.
To all agencies: Please, no phone calls or emails to any employee of FUJIFILM about this requisition. All resumes submitted by search firms/employment agencies to any employee at FUJIFILM via-email, the internet or in any form and/or method will be deemed the sole property of FUJIFILM, unless such search firms/employment agencies were engaged by FUJIFILM for this requisition and a valid agreement with FUJIFILM is in place. In the event a candidate who was submitted outside of the FUJIFILM agency engagement process is hired, no fee or payment of any kind will be paid.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing