
IAM (Identity and Access Management) Operations Analyst
- Singapore
- Permanent
- Full-time
- IAM Strategy & Implementation: Design and implement a robust IAM framework aligned with security best practices and business needs.
- User Access Management: Oversee user provisioning, deprovisioning, and role-based access control across multiple systems and regions.
- Security & Compliance: Ensure adherence to regulatory requirements (e.g., GDPR, SOX) and internal security policies.
- Reporting and Documentation: Maintain thorough documentation of user access policies, and audit logs for internal and external reporting purposes.
- Role based Access control assessment (RBAC): Ensure role definitions are clear and users are only assigned the necessary rights to perform their role in the organization in order to minimize risk of excessive or inappropriate permissions.
- Stakeholder Engagement: Work closely with IT, security, and business leaders to align IAM initiatives with organizational goals.
- Incident Management: Lead investigations into access-related security incidents and recommend remediation measures.
- Training and awareness: Ensure staff understand user access policies, procedures and security awareness.
- Ensure high priority requests are handled efficiently and in compliance with the IAM guidelines and SLA's.
- Manage the IAM Team, carry out annual appraisals ensuring that all team members are meeting their performance targets and delivering high-quality support to clients.
- Close monitoring of the relevant Jira queues, managing and updating of Jira tickets within agreed SLA's.
- Ensure compliance with the company's regulatory requirements under the FCA.
- Adhere to the operational risk framework for your role ensuring that all regulatory or company determined parameters are complied with.
- Role model for demonstrating highest level standards of integrity and conduct and reflecting Company Values.
- At all times comply with the FCA's Code of Conduct.
- To ensure that you are fully aware of and adhere to internal policies that relate to you, your role or any other activities for which you have any level of responsibility
- To report any breaches of policy to Compliance and/ or your supervisor as required
- To escalate risk events immediately
- To provide input to risk management processes, as required.
- Technical Expertise: Understanding of IAM tools (e.g., Okta, SailPoint, CyberArk, Azure AD) and technologies such as SSO (Single Sign-On), MFA (Multi Factor Authentication), and role-based access control (RBAC).
- Security Knowledge: In-depth knowledge of security concepts like least privilege, identity governance, and privileged access management (PAM).
- Compliance Awareness: Familiarity with regulations such as GDPR, SOX, HIPAA, and industry standards like ISO 27001.
- Problem-Solving Skills: Ability to identify and address IAM-related security issues and access violations, along with implementing effective solutions.
- Communication Skills: Ability to work with cross-functional teams (IT, security, legal) and communicate complex IAM concepts to both technical and non-technical stakeholders.
- Analytical Skills: Ability to assess and review user access data, audit trails, and IAM configurations to ensure compliance and security.
- Experience working in a regulated environment and knowledge of the risk and compliance requirements associated with this.
- Strategic Vision: Ability to design and implement IAM strategies that align with business goals and security needs, both in the short and long term.
- Problem-Solving: Proficient at identifying complex IAM challenges and developing creative solutions to address them efficiently.
- Stakeholder Engagement: Strong communication skills to interact with senior leadership and other business units, ensuring IAM strategies are aligned with organizational goals and security needs.
- Reporting and Documentation: Ability to clearly present IAM performance, risks, and audit results to senior leadership and regulatory bodies.
- Conflict Resolution: Capable of resolving conflicts related to access management policies or resource allocation with diplomacy and professionalism.
- Auditing and Compliance: Skilled in conducting audits and ensuring IAM systems and practices comply with legal and regulatory requirements.
- Incident Response: Ability to quickly and effectively respond to access-related security incidents, including breaches, unauthorized access, or policy violations.
- Crisis Management: Strong decision-making ability in high-pressure situations, ensuring access management processes remain secure and operational during a crisis.
- Act with integrity
- Act with due skill, care and diligence
- Be open and cooperative with the FCA, the PRA and other regulators
- Pay due regard to the interests of customers and treat them fairly
- Observe proper standard of market conduct
- Act to deliver good outcomes for retail customers