Identity and Access Management Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in Malaysia.

📋 Description

• Oversee the processes for joiners, movers, and leavers in accordance with HR systems, back-office systems, and IAM policies.

• Provision, alter, and revoke user, service, and privileged accounts across directories and integrated applications.

• Ensure accurate maintenance of identity attributes in line with corporate IAM and HR policies.

• Manage accounts, roles, and permissions across enterprise systems, cloud environments, and product back-office platforms.

• Implement and uphold least privilege, RBAC, and just-in-time access policies.

• Conduct reviews and audits of user access to ensure internal and regulatory compliance.

• Coordinate onboarding and offboarding activities with HR and IT teams.

• Integrate IAM systems with HRIS, directory services, and cloud identity providers.

• Handle IP whitelisting for product providers, payment gateways, and critical business systems.

• Maintain documentation and governance of IP access policies.

• Collaborate with network and application teams to troubleshoot and validate connectivity issues.

• Manage PIM/PAM solutions to safeguard privileged credentials and oversee administrative access.

• Enforce session recording, password rotation, and MFA for privileged accounts.

• Execute privileged account reviews and address access-related issues.

• Monitor access and data movement utilizing DLP and CASB tools.

• Investigate and respond to alerts regarding unauthorized data access or transfers.

• Define and enforce policies for data classification and protection.

• Assist with IAM integrations for SaaS platforms, Microsoft 365, Intune, collaboration tools, and third-party applications.

• Troubleshoot issues related to authentication, SSO, MFA, and access.

• Engage in IAM projects, including onboarding new back-office systems, enhancements, and tenant improvements.

• Maintain IAM processes, standards, documentation, and access matrices.

• Ensure IAM configurations adhere to security policies, audit requirements, and hardening standards.

• Identify and address access violations, orphaned accounts, and policy deviations.

• Support internal and external audits with evidence of access and compliance reports.

• Propel improvements and automation within IAM processes.


⛳️ Requirements

• Bachelor’s degree in Information Security, Computer Science, or a related field (or equivalent practical experience).

• Strong familiarity with Active Directory, Azure AD, Okta, or comparable IAM platforms.

• Experience with PIM/PAM solutions such as CyberArk, BeyondTrust, or Azure PIM.

• Knowledge of DLP and CASB technologies, like Proofpoint.

• Understanding of SAML, OAuth, OIDC, and MFA protocols.

• Background in managing IP whitelisting and firewall access controls within cloud and hybrid environments.

• 5 to 7 years of practical experience in Identity and Access Management or related security fields.

• Proficiency in Microsoft Entra ID (Azure AD), Conditional Access, and identity protection features.

• Knowledge of directory services, including Active Directory and LDAP.

• Familiarity with identity governance and administration practices.

• Ability to assess access risks and implement suitable controls.

• Strong analytical and troubleshooting abilities.

• Understanding of Zero Trust architecture and best security practices.

• High attention to detail and a strong sense of accountability.

• Excellent communication and documentation skills.

• Ability to manage sensitive and confidential access information.

• Detail-oriented and process-driven mindset.

• Collaborative approach across technical and business teams.

• High integrity and commitment to confidentiality and compliance standards.

• Experience in integrating IAM with CSPs such as AWS, Azure, or AliCloud, or tools like GitHub.

• Working knowledge of Python, PowerShell, or Bash for automating access management tasks.

• Familiarity with ISO 27001, PCI DSS, and GDPR standards.

• Preferred industry certifications include CISSP, CISM, Microsoft Certified: Identity and Access Administrator, or CyberArk Defender.


🏝️ Benefits

• Attractive salary package with performance-based bonuses.

• Flexible working arrangements, including remote and hybrid models.

• Comprehensive health insurance coverage.

• Wellness initiatives and resources for physical and mental well-being.

• Opportunities for training and continuous learning.

• Mentorship programs available.

• Clearly defined career development pathways.

• Supportive, inclusive, and growth-oriented work environment.

• Team-building activities and social events.

• Competitive compensation with performance-based incentives.

• Medical insurance included.

• Flexible and hybrid working models designed to support work-life balance.

People also viewed

Hightouch18 hours ago

Forward Deployed Engineer

US flagUnited States OnlyFull-timeEngineer$150k – $225k/year
ApplyView job
Turner & Townsend19 hours ago

Project Administrative Office Engineer

US flagUnited States OnlyFull-timeEngineer
ApplyView job
Intuitive19 hours ago

Staff Software Build Engineer

DE flagGermany OnlyFull-timeEngineer
ApplyView job
Turner & Townsend19 hours ago

Project Administrative Office Engineer

US flagUnited States OnlyFull-timeEngineer$75k – $100k/year
ApplyView job
Abacus Group19 hours ago

Escalation Engineer, Enterprise Service Desk

US flagUnited States OnlyFull-timeEngineer
ApplyView job
GXO Logistics, Inc.19 hours ago

Industrial Engineer – 1st Shift

US flagUnited States OnlyFull-timeEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers