- Contract
- Anywhere
Freelance IAM Architect – Utilities Sector
Location: Brussels Region, Belgium (3 days onsite, remainder remote)
Start Date: ASAP
Contract Type: Freelance
Project Type: Long-term assignment (12 months+)
About the Client
Our client is a leading Utilities organisation based in the Brussels region, operating within a highly regulated and security-critical environment. The company manages complex, large-scale IT and OT infrastructures that support essential public services.
Given the critical nature of its operations, security, resilience, compliance, and automation are strategic priorities. Identity & Access Management (IAM) plays a central role in protecting core systems, ensuring regulatory compliance, and enabling secure digital transformation.
Role Overview
We are seeking an experienced Freelance IAM Architect to lead a strategic IAM transformation program.
The mission is structured in three key phases:
GAP Analysis – Assess the current IAM and Privileged Access Management (PAM) landscape.
Strategy Definition – Design a future-proof IAM target operating model aligned with regulatory and business requirements.
Automation & Implementation Roadmap – Define and guide the implementation of a highly automated IAM ecosystem, strongly integrated with HR systems and business processes.
This role does not require deep hands-on technical engineering, but demands strong architectural vision, functional IAM expertise, governance knowledge, and experience with privileged IAM, target modelling, and HR-driven lifecycle management.
You will act as a strategic advisor, bridging Security, Infrastructure, HR, and Business stakeholders.
Key Responsibilities
1️⃣ GAP Analysis
Assess the current IAM, PAM, and access governance maturity level.
Review identity lifecycle processes (Joiner–Mover–Leaver).
Evaluate integration between IAM and HR systems (source of truth).
Identify risks related to privileged access, segregation of duties (SoD), and compliance gaps.
Analyze current tooling, automation level, and manual interventions.
Deliver a structured GAP analysis report with risk prioritization.
2️⃣ IAM Strategy & Target Operating Model
Define the IAM vision aligned with business, security, and regulatory requirements (e.g., NIS2 context).
Design the Target IAM Architecture, including:
Identity lifecycle management
Role-Based Access Control (RBAC) modelling
Privileged Access Management (PAM)
Access governance & certification
HR system integration as authoritative source
Develop a target operating model covering governance, ownership, and processes.
Define privileged IAM strategy (tiering model, least privilege, session monitoring).
Create a multi-year IAM roadmap with clear priorities and milestones.
3️⃣ Automation & Process Industrialisation
Design a fully automated IAM process driven by HR events.
Define end-to-end automation for:
Joiner / Mover / Leaver workflows
Role assignment based on target modelling
Automated provisioning & deprovisioning
Privileged account lifecycle management
Reduce manual approvals and operational overhead through policy-driven automation.
Ensure auditability, traceability, and compliance by design.
Provide guidance to implementation teams and validate architectural alignment.
Required Experience & Skills
8+ years of experience in Identity & Access Management.
Strong expertise in:
IAM architecture & governance
Privileged Access Management (PAM)
Target modelling & RBAC design
HR-driven identity lifecycle integration
Experience performing IAM maturity or GAP assessments.
Ability to translate business requirements into IAM operating models.
Experience in regulated or critical infrastructure environments (Utilities, Energy, Financial Services, Manufacturing, etc.).
Strong stakeholder management and advisory capabilities.
Ability to work autonomously in a freelance setup.
Fluent in Dutch (spoken and written).
English is a strong plus.
Profile
Strategic thinker with strong analytical capabilities.
Governance-driven rather than purely technical.
Able to challenge existing structures and drive transformation.
Structured, pragmatic, and delivery-focused.
Strong communication skills towards C-level, Security, HR, and IT stakeholders.
Contract Details
Location: Brussels Region, Belgium
Onsite/Remote: 3 days onsite per week
Duration: 12 months+
Contract Type: Freelance
