Identity & Access Management
Quiet, methodical, well-paid. Massive sustained demand at every Nigerian bank.
What the day actually looks like.
ServiceNow queue with 14 tickets. New hire in Lagos needs Okta + Microsoft 365 + Salesforce; you run the joiner workflow in Okta or Microsoft Entra ID, assign group memberships, confirm MFA enrolment. Three leaver tickets — deprovision, revoke sessions, transfer OneDrive. Mid-morning: time-bound elevated access via CyberArk PAM. Afternoon: SAML SSO scoping with an app owner. Quarterly access review/recertification in SailPoint. Light PowerShell or Okta Workflows scripting may sneak in but is optional at the analyst level.
Where the work lives.
What you actually need.
- Identity protocols (SAML, OAuth 2.0, OIDC, SCIM, LDAP, Kerberos)
- Microsoft Entra ID
- Okta admin console
- One IGA tool (SailPoint or Saviynt)
- One PAM tool (CyberArk or BeyondTrust)
- ServiceNow / Jira ticketingtransferable
- Light PowerShell
- Methodical patiencetransferable
Frame-perfect editing → audit-perfect access reviews.
- Strong written documentationtransferable
- Customer-service mindsettransferable
- Discretion
The shape of the journey.
- 1IAM Analyst (L1 ops)0–2 yr
- 2IAM Engineer2–5 yr
- 3Senior IAM Engineer4–8 yr
- 4IAM Architect7–12 yr
- 5IAM Manager / Head of Identity10–18 yr
Note. Times reflect typical paths for someone with strong communication and 10–15 hrs/week of focused study.
What it pays.
Ranges are directional. Currency: USD · annual. Last updated: 2025.
The cert sequence that won't bankrupt you.
Microsoft SC-300
MicrosoftSingle highest-ROI cert for Nigerian banks (mostly Microsoft shops).
Microsoft SC-900
MicrosoftCheapest meaningful starter cert.
Okta Certified Professional
OktaFor Okta-shop fintechs.
CyberArk Defender
CyberArkPAM specialisation.
SailPoint Certified IdentityIQ
SailPointConsultancy track at Accenture/Capgemini/TCS.
Security+
CompTIAOptional vocabulary baseline.
Working from Lagos, Abuja, or anywhere.
Highly remote globally. Nigerian bank roles are typically hybrid 2–3 days office. Microsoft Entra is the dominant stack at tier-1 banks.
The good, the gritty, and who this suits.
- +Massive sustained demand.
- +Introvert-friendly (heads-down ticket queues).
- +Pays well at Nigerian banks.
- +Microsoft Learn home lab is free.
- −Repetitive ticket queues at L1.
- −On-call rotations during incidents.
- −Vendor lock-in risk (Okta vs Entra vs SailPoint).
If you find satisfaction in 'everything in its right place', IAM will reward you.
Three to five hours that beat any cert.
Beginner's Guide to Entra ID
Why watch. John Savill is the canonical Microsoft Entra/Azure trainer on YouTube.
Authentication Fundamentals: Web Single Sign-On
Why watch. Stuart Kwan walks through SSO from first principles.
Get Started with Microsoft Entra External ID
Why watch. Customer-identity (CIAM) intro — increasingly relevant for fintechs.
Do this by Friday.
This week: spin up a free Microsoft Entra ID developer tenant + free Okta dev tenant. By Sunday, post a screenshot to LinkedIn of an SSO integration you wired up. Tag #SC300.