JOB SCOPE
- The IAM manager will be responsible to ensure that all Identity, Privilege and Access management operates efficiently, reliably and in compliance with required regulations, policies, and processes to support MBS’s business, security & integrity of the IT operations.
- Identify and employ IAM methodologies, developing standards & procedures and to champion program improvements.
- To align technologies and security to fit & function effectively. Maintain a simple, pragmatic and effective IAM program design that meets the needs of business & security requirements.
- Provide support to the Identity Access Management Operations team on all audits and compliance reporting (such as SOX, IT-ICC, Entry-Levy, etc.).
- Understanding of the current regulatory environment and related implications to identity management and security/audit compliance solutions.
- Responsible for evaluating access management systems to show continued improvements of provision processes and operations.
- Perform user provisioning/de-provisioning for Infra related System access.
- Develop and document IAM policies, procedures, standards, and guidelines.
- Lead , plan and coordinate the activities of team..
- Troubleshoot and resolve any incidents pertaining to system access tickets in a timely manner.
- Generate user access privilege reports and coordinate with user department heads for the quarterly/annually access review to ensure all critical systems are having up-to-date access privileges.
- Ensure that all access reviews and procedures performed are documented appropriately such that they can be reviewed and validated by internal and external auditors.
- Continuous delivery and enhancement of the infrastructure for identity and access management which include Microsoft Active Directory, Azure Active Directory (AAD) and Public Key Infrastructure (PKI).
- Lead as subject matter expert in the technologies for identity and access management, specifically on Microsoft Active Directory Services, Microsoft Infrastructure technologies and Azure AD.
- Support and drive all IAM related governance and audits initiatives.
- Review and enhance the infrastructure-wide identity services to support users and future business needs.
- Identify opportunities to automate and standardize infrastructure access controls and for the supported teams.
- Continuously finds means and ways to improve operations, streamline work processes and work cooperatively and jointly with various teams to provide quality service.
- Review and adoption of relevant industry best practices for IT infrastructure, specifically for the infrastructure for identity and access management.
- Ensure that project implementation and operations are aligned to corporate technology standards and policies.
JOB REQUIREMENTS
- Degree with 8 years of work experiences in IAM and compliance regulations related field, such as Sarbanes-Oxley (SOX), PCI-DSS etc.
- Excellent written and verbal communication and ability to influence and communicate effectively with non-technical audience and senior management
- Have more than 5 years of experience in successfully recommending IAM policies & processes and lead technical integration outcome of IAM products with infrastructure systems (Windows/Red Hat/SQL/Oracle etc).
- Managing and refining a Role Based Security framework, with schema designs and operational plans to enforce this, alongside managing and implementing sign-on solutions utilising federated technologies such as SAML2, OAuth2 and LDAP.
- Candidate must have an understanding of industry best practices for access administration (Provisioning, de-provisioning), access enforcements (authentication protocols) and access governance (certification, logging, monitoring etc.)
- Experience in Enterprise Identity Directory System (AD Directory Services, ADFS, Forest Trust, AD Rights Management Service, etc) and Azure AD (AAD Connect, Conditional Access Policy, Entitlement Management, etc)
- Experience with Privileged Identity Management solutions (such as SailPoint) and Password Management solutions (such as CyberArk) a plus.
- Hands on experience in Active Directory Security Administration as well as Privileged Account Management (PAM) solutions.
- Good knowledge of LDAP, SAML, databases, authentication, and authorization concepts.
- Possess working knowledge of relational databases (MS SQL, Oracle etc)
- Possess working knowledge of infrastructure security components such as firewall, unified threat management, log captures, SIEM etc
- Ability to learn and adapt quickly in a diverse environment.
- Sound knowledge in ITIL framework.