Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Experienced
About the role
This senior role leads the enterprise identity function at a major Singapore telco, owning the strategy and roadmap that makes identity the company's central control plane. The position suits an experienced identity and access management leader who can drive a large directory migration, govern privileged and non-human identities, and work through vendors and matrixed teams.
What you'll do
Own the identity-led enterprise strategy and an 18-month roadmap, delivering approved scope, budget and milestones.
Own the canonical identity model, authoritative sources and attribute precedence across HR and legacy M&A systems.
Establish Google Workspace / Cloud Identity as the sole workforce authentication and SSO front door.
Retire AD as a workforce authority by inventorying dependencies, then migrating, federating, retiring or time-boxing exceptions.
Govern privileged, non-human and AI-agent identities so privileged or autonomous actions stay attributable to an accountable human.
Implement CISO-set identity policy, with BTS operating it while the CISO owns policy, risk acceptance and exceptions.
Report status, risks and decisions to the CIO, ISLT and ICC, and own the Identity OKR.
Translate the identity-led enterprise position paper into a phased architecture covering authoritative sources, canonical identity, Google front door, access enforcement, workload access and telemetry.
Define AD-to-Google coexistence, including event authority, JML and exit criteria for every AD dependency.
Select IGA/PAM tooling that supports the Google-first model without creating a second identity authority.
Set integration and onboarding standards for applications, AWS, endpoints, integration and AI platforms.
Lead matrixed architecture, security, engineering, project resources and partners, controlling scope, sequencing, RAID and budget.
Deliver migration waves with identity clean-up, role and group rationalisation, orphan-account testing and validated deprovisioning.
Automate JML from SuccessFactors and approved contractor and guest workflows, including sponsors, end dates and revalidation.
Reconcile acquired entities under the canonical model using match logic, confidence thresholds, adjudication and merge/unmerge controls.
Separate standard and privileged personas, enforcing named approvals, break-glass controls and quarterly access certification.
Maintain a non-human identity registry covering owner, purpose, environment, credentials, review and decommission trigger.
Enforce zero net-new unmanaged shared or generic accounts and reduce existing account debt to a published schedule.
Govern AI agents as non-human identities with approved purpose, data domains, actions and act-as or on-behalf-of modes, aligned to the IMDA Model AI Governance Framework for Agentic AI.
Feed GWS, AWS, endpoints and critical applications into the SIEM using common identity identifiers.
Provide audit evidence for identity controls, including CCoP and in
Requirements
12+ years in identity and access management, security architecture or enterprise platforms
Led at least one enterprise IAM programme end to end
Led a large directory migration or consolidation across several thousand identities
Hands-on identity lifecycle and JML automation, IGA, PAM, SSO and federation (SAML, OIDC, SCIM) and access certification
Experience governing non-human identities such as service accounts, workload identity, secrets and certificate-based patterns
Working knowledge of Zero Trust architecture and emerging identity controls for AI agents
Jio can write this application for you
Jio reads this job and your profile, then writes a short letter in your words. You read it, change anything, and send it yourself. Nothing is sent until you say so.