Life @ AP+
We are one connected team in pursuit of one inspiring purpose – to unite people and technology to power better experiences. Each of us has a part to play in making that happen. You’ll be encouraged to bring your big ideas forward and make a difference through your work. Taking steps forward in your career whilst still having room for fun, friendships, and flexibility in your daily life.
We’re driven by our core values: lead with heart, learn for tomorrow and live our legacy. A purpose like ours takes the inspired impact of an incredible team. Ready to change the game? We’re ready to help you do it.
The Purpose
As our Identity and Access Management Lead, you’ll help protect AP+ by making sure the right people have the right access to the right systems and data, at the right time. You’ll play a key role in establishing and continuously improving our Identity and Access Management (IAM) capability, helping reduce security risk while enabling our people and technology to operate securely and efficiently.
You’ll shape the frameworks, policies, standards and controls that underpin IAM across AP+, with a particular focus on identity lifecycle management, privileged access, authentication, authorisation and least-privilege access. You’ll work across technology, security and the broader business to embed secure access practices into platforms and services, while ensuring our controls remain aligned with organisational risk, compliance obligations and evolving security threats.
This role combines strategic thinking with practical delivery. You’ll oversee IAM control effectiveness, identify and remediate access risks and exceptions, support audits and risk assessments, and use data and reporting to provide clear insight into the effectiveness of our access controls. You’ll also help optimise and integrate IAM tooling, Identity Governance & Administration (IGA) and Privileged Access Management (PAM) solutions.
With identity sitting at the heart of modern security, you’ll help shape a scalable IAM capability that supports AP+ as it evolves, while providing specialist advice to technology and business teams on secure access patterns and how to protect critical systems and information.
Key Responsibilities the Role Owns
- Define and maintain enterprise IAM policies, standards, controls and the target-state IAM roadmap.
- Oversee identity lifecycle processes, including joiner, mover and leaver management, access provisioning and de-provisioning.
- Manage Privileged Access Management (PAM) governance, controls and continuous improvement.
- Ensure authentication, authorisation and access control designs align with security risk and compliance requirements.
- Partner with security engineering, operations and architecture teams to embed IAM controls into platforms and services.
- Monitor and report on IAM control effectiveness, access exceptions and compliance obligations, driving remediation where required.
- Lead IAM-related risk assessments, audits and evidence management for internal and external stakeholders.
- Drive the configuration, optimisation and integration of IAM tooling, including Identity Governance & Administration (IGA) and Privileged Access Management (PAM) solutions.
- Support the investigation and response to access-related security incidents and suspected credential misuse.
- Provide specialist advice to technology and business teams on secure access patterns, identity governance and least privilege.
You’ll likely be a strong fit for this role if
You’re an experienced IAM or PAM professional who enjoys solving complex security challenges and building practical controls that protect an organisation without getting in the way of good business outcomes. You’ll bring demonstrated experience leading IAM capabilities in a complex enterprise environment, with strong knowledge of identity governance, privileged access management, and least-privilege principles.
You’ll be comfortable working across security, technology and business teams, providing specialist advice and influencing how identity and access controls are designed and implemented. Experience supporting audits, risk assessments and control uplift initiatives will be important, along with an understanding of security risk management and relevant standards and regulatory obligations. Relevant certifications across platforms will be valuable, but strong practical experience will be equally important.
What happens next
At AP+, we believe in the power of passion, pride and purpose. Our team is driven by a shared mission to make a difference in the world of payments, and we're proud to work together towards this common goal.
If you’re an Identity and Access Management professional who enjoys solving complex security challenges, strengthening controls and helping organisations operate securely, we’d love to hear from you.
If you’re ready to be a game changer, please submit your application. The Talent Acquisition team will endeavor to review your application and notify you of the outcome within the next two weeks.
We want to remove all barriers to inclusion, so if you need advice or support with your application, we’re here to help. Please reach out to [email protected]. We also encourage you to let us know your pronouns at any point during the recruitment process.
AP+ are not partnering with Recruitment agencies for this role.
Skills Required
- Demonstrated experience leading IAM capabilities in a complex enterprise environment
- Strong knowledge of identity governance and administration
- Strong knowledge of privileged access management
- Strong understanding of least-privilege principles
- Experience working across security, technology, and business teams
- Experience supporting audits, risk assessments, and control uplift initiatives
- Understanding of security risk management
- Understanding of relevant security standards and regulatory obligations
- Relevant platform certifications
What We Do
Introducing Australian Payments Plus Australian Payments Plus (AP+) brings together Australia’s three domestic payment providers, BPAY Group, eftpos and NPP Australia, into one integrated entity. Bringing these businesses together enables AP+ to create a more competitive and coordinated Australian payments organisation that is strategically placed to respond to the impacts of regulatory and technological change today, and into the future. Operating in the public interest, AP+ is a member-owned organisation, with a diverse range of members including Australia’s domestic banks, international banks operating in Australia, some of the country’s largest merchants, payment service providers and payment processors, together with a range of challenger and disruptor brands focused on specific markets and products.
.png)








