Senior Manager, Identity & Access Management (TECH Risk & Security)
AIA Malaysia · Federal Territory of Kuala Lumpur, Malaysia
Apply & track with Apply EdgeWhat You Will Expect:The position is responsible for developing and delivering the Identity & Access Management (IAM) strategy, roadmap and operating model under the direction of the Head of Information Security, ensuring that workforce, privileged, third-party and machine identities receive appropriate access throughout their lifecycle. The role manages the governance, engineering and operations of IAM capabilities, reduces identity-related risk, enables secure digital transformation, and ensures compliance with regulatory, Group and internal security requirements. The role also provides leadership across identity governance, access management, privileged access management, authentication, directory services and access assurance, while developing a capable IAM team and strong partnerships across Technology, Risk, Audit and the Business.What You Will Do:IAM Strategy, Governance & Operating Model Establish and maintain the enterprise IAM strategy, target-state architecture, roadmap, policies, standards and control framework aligned with business priorities and security risk appetite.Establish clear IAM service ownership, decision rights, control accountabilities, performance measures and governance forums across Technology and Business stakeholders.Provide executive-level reporting on identity risks, control effectiveness, service health, transformation progress and material issues.Maintain an authoritative inventory of IAM services, identity stores, privileged access technologies, authentication methods and critical dependencies.Identity Governance & Administration Oversee joiner, mover and leaver controls for employees, contractors, third parties, service accounts and other non-human identities.Drive role-based and attribute-based access models, access request and approval workflows, segregation-of-duties controls, birthright access and timely deprovisioning.Lead periodic access reviews, privileged access recertification and remediation of excessive, dormant, orphaned or inappropriate access.Improve identity data quality and integration with authoritative sources, including Human Resources, vendor management and application ownership records.Access Management, Authentication & Directory Services Lead secure authentication and access services, including single sign-on, federation, multi-factor authentication, conditional access and passwordless capabilities.Oversee enterprise directory and identity platform security, resilience, configuration governance, monitoring, backup and recovery readiness.Ensure authentication and session controls are proportionate to user, device, transaction, application and data risk.Guide application teams in integrating modern authentication and authorization standards into new and existing solutions.Privileged Access Management Manage the privileged access management programme covering administrative, emergency, application, database, infrastructure, cloud and service accounts.Ensure privileged credentials are vaulted, rotated, monitored and used through controlled mechanisms, with appropriate approval and session recording where required.Reduce standing privilege through least privilege, time-bound access and just-in-time or just-enough administration approaches.Ensure Tier-0 and other critical identity infrastructure receive enhanced protection, monitoring, change control and access restrictions.IAM Engineering, Operations & Service Management Manage the implementation, integration, maintenance and continuous improvement aligned with Group strategy on the centralized IAM platforms and supporting services.Ensure IAM services meet agreed availability, capacity, performance, resilience and recovery requirements.Drive automation, standardization and self-service to improve control consistency, user experience and operational efficiency.Risk, Compliance, Audit & Assurance Ensure IAM controls comply with applicable regulatory requirements, Group standards, internal policies and approved security architecture principles.Provide complete and timely evidence for audits, regulatory reviews, control testing and risk assessments; own remediation plans through sustainable closure.Identify, assess and treat IAM risks, control gaps, exceptions and technical debt, escalating material exposures appropriately.Define IAM control metrics and key risk indicators, including access provisioning timeliness, leaver removal, recertification completion, privileged account coverage and authentication strength.Security Incident & Threat Response Coordinate IAM response activities during cyber incidents involving compromised credentials, privilege misuse, account takeover or identity infrastructure.Ensure rapid containment actions are available, including account suspension, session revocation, credential rotation and emergency access restrictions.Leadership & Stakeholder Management Manage and develop the IAM team with clear objectives, succession planning, skills development and performance accountability.Partner with application, infrastructure, cloud, security, architecture, HR, procurement, risk, compliance and audit teams to embed IAM requirements throughout technology and employee lifecycles.Work with senior stakeholders and application owners to remediate access risks and adopt enterprise IAM services.Promote a strong control culture and communicate identity security requirements in practical business terms.What You Will Need:Qualifications & CertificationsBachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering or a related discipline.Minimum 6 years of relevant experience in, identity security, technology risk or infrastructure security, including at least 3 years in an IAM management or team leadership capacity.Demonstrated experience managing IAM transformation initiatives and operational services in a complex or regulated organization; financial services or insurance experience is preferred.Relevant professional certifications such as CISSP, CISM, CRISC, CCSP, Microsoft Identity and Access Administrator, vendor-specific IAM/PAM certifications, or equivalent are advantageous.IT service management, cloud security, architecture or project / programme management qualifications are beneficial.Technical & Domain KnowledgeDeep knowledge of identity governance and administration, access management, privileged access management, directory services and identity lifecycle controls.Strong understanding of Microsoft Active Directory, Microsoft Entra ID, hybrid identity, federation, single sign-on, multi-factor authentication, conditional access and passwordless authentication.Experience with enterprise IGA and PAM platforms, identity integration patterns, workflow automation, connectors, APIs and identity data reconciliation.Knowledge of authentication and authorization standards and protocols, including SAML, OAuth 2.0, OpenID Connect, LDAP, Kerberos, SCIM and public key infrastructure.Understanding of cloud IAM across major cloud platforms, workload identities, secrets management, service principals, certificates, API keys and machine identity governance.Strong command of least privilege, zero trust, segregation of duties, role engineering, access certification and privileged session controls.Ability to design and govern IAM controls for legacy applications, modern applications, cloud services, databases, infrastructure platforms and third-party access.Knowledge of cyber threat scenarios involving credential theft, account takeover, privilege escalation, lateral movement and identity infrastructure compromise.Experience with regulatory compliance, audit engagement, risk assessment, control testing, evidence management and remediation governance.Working knowledge of secure architecture, security operations, vulnerability management, incident response, resilience and disaster recovery as they relate to IAM.Ability to define service levels, operational metrics, control metrics and executive reporting for IAM services and risks.Personal AttributesHigh integrity, sound judgement and a strong sense of accountability for security and customer trust.Strong strategic and operational thinkers who can translate risk and business priorities into an achievable IAM roadmap.Decisive and calm under pressure, with the ability to lead through security incidents and service disruptions.Collaborative and pragmatic, balancing control requirements, user experience, operational feasibility and business outcomes.Curious, improvement-oriented and willing to challenge ineffective processes or accepted practices.Resilient and organized, with the ability to manage competing priorities, dependencies and senior stakeholder expectations.Clear communicator who can explain complex identity risks and technical decisions to non-technical stakeholders.Key CompetenciesIAM strategy, roadmap and delivery management.Identity security, architecture and control design.Team management, coaching and capability development.Risk-based decision-making and regulatory awareness.Operational excellence, service resilience and continuous improvement.Management communication, negotiation and stakeholder influence.Vendor, commercial and third-party service management.Data-driven governance, metrics and management reporting.Incident coordination and cross-functional problem solving.