jobs in 深圳市法本信息技术股份有限公司

深圳市法本信息技术股份有限公司 Hiring! Full Time IAM Governance, Controls - Operations Specialist in Federal Territory - Ricebowl

IAM Governance, Controls - Operations Specialist

深圳市法本信息技术股份有限公司

Undisclosed

KL City, Federal Territory

Share
Save

Working Location

  • Kuala Lumpur Federal Territory Malaysia

Job Description

Responsibilities

Role Summary

This combined role integrates core responsibilities of IAM Governance Analyst, IAM Controls & Compliance Specialist, and IAM Operations and Access Review Support Analyst. The incumbent owns end-to-end Identity & Access Management delivery covering daily IAM operational execution, access certification workflows, privileged access administration, IAM control design & validation, governance framework maintenance, IT risk oversight, audit compliance support, and IAM performance reporting, aligned with enterprise risk policies and local regulatory requirements in Malaysia’s highly regulated financial, telco and corporate sectors.


Key Responsibilities

1. IAM Daily Operations & Identity Lifecycle Management

  • Execute full Joiner, Mover, Leaver (JML) workflows following standardised procedures for employees, contractors and third-party vendors.
  • Deliver end-to-end user access provisioning, modification and deprovisioning across enterprise applications, Active Directory and LDAP environments.
  • Administer Privileged Access Management (PAM) activities including privileged access request approvals, credential reconciliation, periodic privileged account reviews, dormant/orphaned privileged account identification and remediation.
  • Support full access recertification campaigns; coordinate attestation activities with business and application owners, follow up on overdue reviews and track remediation of excessive access rights.
  • Monitor IAM operational SLAs, manage access exceptions, escalate critical operational blockers and maintain complete audit trails and operational activity records.
  • Generate access certification, user lifecycle and PAM operational reports as compliance evidence for internal and external audits.


2. IAM Controls Design, Testing & Validation

  • Build, maintain and validate enterprise IAM control standards and control libraries aligned with cybersecurity, data protection and Malaysian regulatory frameworks.
  • Establish and execute recurring IAM control monitoring programs and formal control effectiveness testing methodologies.
  • Evaluate the operational efficiency of JML, PAM, access certification, Segregation of Duties (SoD) and least-privilege access controls.
  • Track control deficiencies, risk exceptions and mitigation activities; validate that all corrective management actions are fully implemented and sustainable.
  • Maintain a central repository of control evidence to support audit examinations.


3. IAM Governance Framework & Risk Oversight

  • Own the design, rollout and ongoing maintenance of the organization’s formal IAM governance framework, including all IAM policies, standards, operating procedures and governance documentation.
  • Develop and update IAM RACI matrices, stakeholder mapping, and formal governance workflows covering access provisioning, recertification, privileged access governance and exception handling.
  • Conduct continuous oversight over JML, access review and privileged access processes to identify governance gaps, then coordinate cross-functional remediation workstreams.
  • Track, aggregate and escalate IAM-related risks, control issues and remediation progress to security and business leadership.
  • Build, deploy and maintain IAM KPI/KRI dashboards to measure governance effectiveness and define formal risk escalation thresholds.


4. Audit, Regulatory & Stakeholder Management

  • Serve as primary IAM point of contact for internal audit, external audit and regulatory compliance assessments.
  • Prepare structured audit submission packs, track action plans for audit findings and validate full closure of all non-conformities.
  • Engage cross-functional stakeholders, business unit leaders, IT teams and auditors; deliver clear written and verbal updates on IAM governance, risk and operational performance.
  • Develop standardised IAM process documentation, user guides and evidence management practices for consistent cross-team adoption.


Required Skills & Experience

  1. Minimum 5 years of cumulative professional experience covering IAM Operations, Identity Administration, IT Security Risk, Cybersecurity Governance or Technology Controls within regulated industries (financial services, telco, multinational corporate environments preferred).
  2. Deep working knowledge of core IAM fundamentals: RBAC, JML identity lifecycle, PAM, access recertification, SoD and least privilege access principles.
  3. Hands-on exposure to designing and maintaining IAM governance frameworks, formal security policies and control testing methodologies.
  4. Practical experience operating mainstream IGA and PAM tools: SailPoint, CyberArk, Okta, Entra ID, CAPAM, TPAM or equivalent enterprise identity platforms.
  5. Strong analytical thinking, meticulous attention to detail, advanced documentation skills and ability to manage multiple concurrent cross-functional workstreams.
  6. Excellent written and verbal communication, proven stakeholder engagement and cross-team coordination capabilities.


Preferred Qualifications & Industry Experience

  1. Professional security certifications: CISM, CRISC, ISO 27001 Lead Auditor, CEH, Security+ or ITIL Foundation.
  2. Prior work experience within Malaysia’s financial services, banking, telco or highly regulated multinational organizations.
  3. Working knowledge of Malaysian data protection regulations and local corporate audit compliance requirements.
  4. Hands-on experience building KPI/KRI dashboards for security governance and IAM operational performance tracking.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More