Role: Role-Based Access Control (RBAC) Lead REF 106024
Contract Length: Until 31/03/2027
Location: Hybrid/Bristol - 2 days per week
IR35: Inside
Pay Rate to Intermediary: Market Rate
Security Clearance: SC requested
Spinwell is recruiting for a Role-Based Access Control (RBAC) Lead for an excellent opportunity within the public sector.
RESPONSIBILITIES OF THE ROLE-BASED ACCESS CONTROL (RBAC) LEAD
The RBAC Lead will be responsible for:
- Establishing and maintaining the authority-side RBAC plan, roadmap, milestones, dependencies, risks, issues and decisions required to support design, build, testing, assurance, operational readiness and programme planning, with delivery manager support.
- Acting as the Authority lead for RBAC, representing client interests in planning, design, assurance and governance discussions with delivery partners and internal stakeholders.
- Ensuring RBAC coverage across Oracle Fusion, FDI analytics, integrations, operational tooling, approved extensions and all other in-scope CSM applications or services.
- Setting, maintaining and assuring RBAC principles, design standards and decision criteria for role design, access allocation, exception handling and future operational governance.
- Assuring Delivery Partner RBAC design and build activity against agreed RBAC principles, CSM design principles, architecture standards, Secure by Design, data governance and operational requirements.
- Ensuring RBAC is designed around business roles, processes, organisational responsibilities and data access needs, not individual preferences or local workarounds.
- Ensuring the RBAC model supports segregation of duties, least privilege, auditability, access reviews and controlled role creation, amendment and retirement.
- Prioritising vendor-standard and seeded roles wherever appropriate, with adapted or custom roles used only where justified, approved and documented.
- Managing RBAC deviations from agreed principles, design standards or vendor-standard roles through CSM governance, ensuring decisions, approvals, risk acceptances and rationale are documented.
- Identifying, managing and escalating RBAC risks, issues, assumptions and dependencies, including segregation of duties, excessive or privileged access, data exposure, testing readiness and operational handover.
- Coordinating authority-side input from functional programmes responsible for Business RBAC, together with security, data, enterprise architecture, service management, testing, internal controls, business change and supplier teams.
- Defining Authority expectations for RBAC artefacts, including role catalogues, role mapping matrices, segregation of duties matrices, access control policies, test scenarios and governance documents.
- Reviewing Delivery Partner outputs and providing evidence-based feedback on gaps, risks, inconsistencies and areas requiring further development.
- Facilitating workshops with functional, technical and security stakeholders to clarify role requirements, access patterns and operational support needs.
- Aligning RBAC design across Finance, HR, Commercial, Service Management, FDI analytics, integrations and approved extensions to avoid role proliferation and inconsistent access patterns.
- Ensuring coherent RBAC design across all user groups, functions, business processes and in-scope system functionality, resolving inconsistencies, duplication, gaps and conflicting access patterns before they impact delivery or live operation.
- Overseeing and assuring Functional programme Business RBAC, while leading EATD responsibility for Technical RBAC, including clear separation between functional, data, privileged, technical administration, service support and integration or automated access.
- Working with testing teams to ensure scenario-based testing confirms users can perform required activities and cannot access functions or data outside their role.
- Supporting the future RBAC operating model, including role ownership, access approvals, joiner-mover-leaver processes, periodic access reviews and exception management.
- Providing concise updates, escalations and recommendations to CSM governance forums where decisions, trade-offs or risk acceptance are required.
SKILLS/EXPERIENCE OF THE ROLE-BASED ACCESS CONTROL (RBAC) LEAD
- Proven experience leading or assuring RBAC design and implementation in large-scale, complex enterprise transformation, ideally involving Oracle Fusion or comparable ERP, HCM, finance, commercial, analytics or corporate services platforms.
- Demonstrable experience working across multiple functions, business areas, user groups, security boundaries and delivery workstreams, while controlling complexity, role proliferation and local variation.
- Strong understanding of RBAC principles, access governance, least privilege, segregation of duties, auditability and role lifecycle controls.
- Understanding of how access control supports business processes, operational responsibilities, data protection and internal control requirements.
- Ability to translate process, data and operational requirements into clear access control expectations.
- Strong assurance capability, including reviewing supplier designs, challenging assumptions, identifying gaps and supporting evidence-based governance decisions.
- Credibility to direct, challenge and assure delivery partner activity, recognising common RBAC risks, design pitfalls, control weaknesses and implementation issues before they affect build, test, cutover or live operation.
- Understanding of Secure by Design, identity and access management, privileged access management, audit logging, compliance and operational security considerations.
- Ability to manage dependencies across architecture, security, data, testing, service management, functional design and business change.
- Strong communication and influencing skills, including explaining access control risks and decisions to technical and non-technical audiences.
- Ability to operate autonomously, structure ambiguity and drive progress ahead of Delivery Partner mobilisation.
If you are a Role-Based Access Control (RBAC) Lead, apply now or send your CV to Spinwell!
We welcome all applications regardless of background, in line with our commitment to diversity, equality and inclusion.
Applying to this or any other vacancy advertised by Spinwell Ltd constitutes an agreement for Spinwell Ltd to hold your details for 24 months for the purpose of assessing suitability for the advertised position and to make you aware of any other positions deemed suitable of which You will make you aware by means of either email, text or phone. In line with GDPR regulations you are able to request your details be removed from the company data at any time by emailing us
Disability Confident
As a member of the disability confident scheme, the client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group.
Armed Forces Covenant
The client is proud to support the Armed Forces Covenant and as such, we guarantee to interview all veterans or spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where we have a high volume of ex-military candidates / military spouses or partners, who meet all of the essential criteria, we will interview the best candidates from within that group.
If you qualify for the above, please notify us and quote the role you are applying for.
We will be in touch to discuss your suitability and arrange your Guaranteed Interview.
Should you require reasonable adjustments at any point during the recruitment process or if there is a more accessible way for us to communicate, please do let us know.