Submit
Identity and Access Management (IAM) Operations Analyst
Job description
Operate client’s Identity and Access Management governance program, with primary focus on running User Access Reviews and access certification campaigns across our SailPoint Identity Security Cloud (ISC), Okta, Microsoft Entra ID, and our broader SaaS estate, ensuring access-governance outcomes consistently meet audit and regulatory expectations.
- Running and monitoring User Access Review and certification campaigns in SailPoint Identity Security Cloud (ISC) end-to-end - scoping, launch, reviewer assignment, reminders, escalation, and closure - with support from the IAM Manager and IAM Engineering.
- Driving reviewers to SLA, escalating to line managers and skip-level managers when campaigns stall, and scrutinizing low-quality or default "rubber-stamp" approvals so that review decisions are meaningful.
- Investigating and remediating policy violations surfaced by access governance, including the "active individuals without an assigned manager" policy and segregation-of-duties (SoD) conflicts.
- Tracking each campaign's revocations and access changes through to confirmed closure in the target systems, and evidencing outcomes in the Remediation Report.
- Monitoring account provisioning and de-provisioning across SailPoint and Okta, and resolving exceptions, joiner-mover-leaver gaps, and synchronization errors.
- Working with system and application owners to correctly map non-human, service-account, and machine-identity ownership in SailPoint.
- Providing ad hoc IAM support to DevOps on Teleport, who own ongoing maintenance of Teleport resources and policies.
- Partnering with other technical stakeholders to roll out and operationalize Teleport within their teams.
- Onboarding new services and servers into Teleport, enabling secure access for both human users and machine identities.
- Monitoring the integration health between SailPoint and connected source systems, and escalating connector, aggregation, and data-quality issues to senior team members where needed.
- Acting as second-level support to the L1 ticket queue for IAM troubleshooting.
- Generating standard and ad-hoc access-governance reports and metrics for IAM leadership, Security leadership, and external auditors.
- Packaging evidence for compliance-automation platforms (e.g., Drata) and external reviews (e.g., EY service-account reviews), and validating that controls are operating as designed.
- Documenting and maintaining IAM Standard Operating Procedures, reviewer guides, operational playbooks, and end-user FAQs.
- Supporting audit readiness by collecting evidence, validating control operation, and documenting access-governance activities across the IAM estate (SailPoint ISC, Okta, Microsoft Entra ID, and other SaaS applications).
- Researching improvements to access-review processes, policies, and automation, and translating them into practical, repeatable operational practices.
- Providing technical input to the IAM Manager on access-governance risks, control gaps, exceptions, and process-improvement opportunities.
- Running access reviews and certification campaigns over AI and generative-AI tools (e.g., Microsoft 365 Copilot, approved LLM platforms) and the entitlements, connectors, and data sources they can reach.
- Governing identities, entitlements, and least-privilege access for AI agents, copilots, and agentic/autonomous workloads - including their service accounts, API scopes, and tool-calling permissions - in SailPoint and Okta.
Requirements
- At least 2–4 years of experience in IT, IT support, system administration, security operations, or IAM operations, ideally including hands-on access governance.
- Bachelor's degree in information technology, computer science, information security, or a related field - or equivalent practical experience.
- Good understanding of identity and access management concepts, including authentication, authorisation, provisioning, MFA, RBAC, least privilege, and single sign-on (SSO).
- Hands-on experience with at least one IGA platform - SailPoint Identity Security Cloud (ISC) strongly preferred; Saviynt, One Identity, or Oracle IGA also relevant - and with Okta administration (users, groups, applications, and lifecycle policies).
- Experience running access reviews and certification campaigns, interpreting segregation-of-duties (SoD) policy output, and driving remediation with managers and application owners.
- Good understanding of cloud and infrastructure-access environments, APIs, authentication, and authorisation, with familiarity across Microsoft Entra ID, Active Directory, AWS IAM, Teleport (or an equivalent infrastructure-access platform such as HashiCorp Boundary, AWS SSM Session Manager, or CyberArk), and tools such as Postman.
- Good knowledge of common security and compliance frameworks such as ISO 27001, SOC 2, and SOX, including regional financial-services regulations (e.g., MAS, HKMA), and experience packaging evidence for compliance-automation platforms such as Drata.
- Ability to read and understand technical documentation, integration and connector designs, and identity data flows across connected systems.
- Exposure to scripting (PowerShell, Python, or Bash) for light reporting and automation.
- Relevant industry certifications are a plus - for example SailPoint, Okta Certified Professional/Administrator, CompTIA Security+, or an AWS security/IAM credential.
- Awareness of AI and generative-AI security risks relevant to identity - excessive agent permissions, over-scoped API/OAuth grants, insecure plugins/connectors, and data exposure through AI tools.
- Exposure to governing access for AI platforms, copilots, or agentic/non-human identities (reviewing entitlements, API scopes, and tool-calling permissions).
- Interest in using AI-assisted automation responsibly within IAM operations - for reporting, anomaly detection, or access-review insights.
- Strong stakeholder-management and analytical skills, with attention to detail and the ability to investigate and communicate access-related risks clearly.
- Able to work after hours from time to time as needed.
Want to apply?
Position
Name*
Email*
Phone number*
Country*
City*
Linkedin
Faça upload do seu CV*
(max. 4MB)
Upload your photo or video
(max. 4MB)


