
Identity and Access Management Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Malaysia.
• Oversee the processes for joiners, movers, and leavers in accordance with HR systems, back-office systems, and IAM policies.
• Provision, alter, and revoke user, service, and privileged accounts across directories and integrated applications.
• Ensure accurate maintenance of identity attributes in line with corporate IAM and HR policies.
• Manage accounts, roles, and permissions across enterprise systems, cloud environments, and product back-office platforms.
• Implement and uphold least privilege, RBAC, and just-in-time access policies.
• Conduct reviews and audits of user access to ensure internal and regulatory compliance.
• Coordinate onboarding and offboarding activities with HR and IT teams.
• Integrate IAM systems with HRIS, directory services, and cloud identity providers.
• Handle IP whitelisting for product providers, payment gateways, and critical business systems.
• Maintain documentation and governance of IP access policies.
• Collaborate with network and application teams to troubleshoot and validate connectivity issues.
• Manage PIM/PAM solutions to safeguard privileged credentials and oversee administrative access.
• Enforce session recording, password rotation, and MFA for privileged accounts.
• Execute privileged account reviews and address access-related issues.
• Monitor access and data movement utilizing DLP and CASB tools.
• Investigate and respond to alerts regarding unauthorized data access or transfers.
• Define and enforce policies for data classification and protection.
• Assist with IAM integrations for SaaS platforms, Microsoft 365, Intune, collaboration tools, and third-party applications.
• Troubleshoot issues related to authentication, SSO, MFA, and access.
• Engage in IAM projects, including onboarding new back-office systems, enhancements, and tenant improvements.
• Maintain IAM processes, standards, documentation, and access matrices.
• Ensure IAM configurations adhere to security policies, audit requirements, and hardening standards.
• Identify and address access violations, orphaned accounts, and policy deviations.
• Support internal and external audits with evidence of access and compliance reports.
• Propel improvements and automation within IAM processes.
• Bachelor’s degree in Information Security, Computer Science, or a related field (or equivalent practical experience).
• Strong familiarity with Active Directory, Azure AD, Okta, or comparable IAM platforms.
• Experience with PIM/PAM solutions such as CyberArk, BeyondTrust, or Azure PIM.
• Knowledge of DLP and CASB technologies, like Proofpoint.
• Understanding of SAML, OAuth, OIDC, and MFA protocols.
• Background in managing IP whitelisting and firewall access controls within cloud and hybrid environments.
• 5 to 7 years of practical experience in Identity and Access Management or related security fields.
• Proficiency in Microsoft Entra ID (Azure AD), Conditional Access, and identity protection features.
• Knowledge of directory services, including Active Directory and LDAP.
• Familiarity with identity governance and administration practices.
• Ability to assess access risks and implement suitable controls.
• Strong analytical and troubleshooting abilities.
• Understanding of Zero Trust architecture and best security practices.
• High attention to detail and a strong sense of accountability.
• Excellent communication and documentation skills.
• Ability to manage sensitive and confidential access information.
• Detail-oriented and process-driven mindset.
• Collaborative approach across technical and business teams.
• High integrity and commitment to confidentiality and compliance standards.
• Experience in integrating IAM with CSPs such as AWS, Azure, or AliCloud, or tools like GitHub.
• Working knowledge of Python, PowerShell, or Bash for automating access management tasks.
• Familiarity with ISO 27001, PCI DSS, and GDPR standards.
• Preferred industry certifications include CISSP, CISM, Microsoft Certified: Identity and Access Administrator, or CyberArk Defender.
• Attractive salary package with performance-based bonuses.
• Flexible working arrangements, including remote and hybrid models.
• Comprehensive health insurance coverage.
• Wellness initiatives and resources for physical and mental well-being.
• Opportunities for training and continuous learning.
• Mentorship programs available.
• Clearly defined career development pathways.
• Supportive, inclusive, and growth-oriented work environment.
• Team-building activities and social events.
• Competitive compensation with performance-based incentives.
• Medical insurance included.
• Flexible and hybrid working models designed to support work-life balance.
Hightouch
Turner & Townsend
Intuitive
Turner & Townsend
Get handpicked remote jobs straight to your inbox weekly.