{"id":1258815,"url":"https://alion.io/job/mediacorp-assistant-lead-workforce-identity-security","title":"Assistant Lead, Workforce & Identity Security","company":{"id":232604,"name":"Mediacorp","domain":"mediacorp.sg","url":"https://alion.io/company/mediacorp-2","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"RecruiterPal","truth_index":{"grade":"C","score":57,"open_postings":155,"ghost_share":0.723,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-01T05:45:00Z"}},"role":"HR","role_family":"HR","seniority":"lead","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Singapore"],"countries":["SG"],"hiring_countries":["SG"],"hiring_countries_total":1,"salary":null,"salary_estimate":null,"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"Agile","optional":false},{"name":"Azure","optional":false},{"name":"CyberArk","optional":false},{"name":"IAM","optional":false},{"name":"Incident Management","optional":false},{"name":"ISO 27001","optional":false},{"name":"LDAP","optional":false},{"name":"Least Privilege","optional":false},{"name":"Linux","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"NIST CSF","optional":false},{"name":"Okta","optional":false},{"name":"Ping Identity","optional":false},{"name":"Rest API","optional":false},{"name":"SIEM","optional":false},{"name":"Unix","optional":false},{"name":"Windows","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-01-20T00:00:00Z","employer_posted_date":"2026-01-20","last_verified_at":"2026-09-29T10:48:21Z","board_verified":false,"closed_at":null,"days_open":254,"trust":{"level":"ghost","repost_count":0,"flags":["stale","company_stale"],"days_open":254},"description":"Purpose of the role\nYou are the person who ensures the right workforce has the right access to the right resources.\nYou own our Identity & Access Management (IAM), Privileged Access Management (PAM) and workforce security capabilities. You will drive an identity-first, Zero Trust model across on-prem, cloud and SaaS environments, and lead major IAM/PAM uplift projects that are central to our cyber-resilience and CSA Cyber Trust Mark ambitions.\nThis role reports to the Lead, Cyber Defence & Resilience and is a critical counterpart to our Cyber Fusion, Exposure & Vulnerability Management and Digital Trust teams.\nScope of the role\nIn this role, you will be responsible for the strategy, architecture, implementation and ongoing effectiveness of identity and workforce security across:\nIdentities & Accounts - Employees, contractors, vendors, service accounts and application identities across multiple directories and HR systems\nAccess Control - Role-based access (RBAC), attribute-based access (ABAC), segregation of duties (SoD), and entitlements for business and privileged users\nIAM Platforms - Enterprise IAM solutions (e.g. SailPoint, Saviynt, Oracle IAM, Azure AD / Entra ID, Okta or similar) covering identity lifecycle, SSO and federation\nPAM Platforms - CyberArk or equivalent vaulting and session-monitoring solutions for privileged and sensitive accounts\nProcesses & Governance - Joiner-mover-leaver (JML), recertification, access reviews, break-glass processes and exception handling\nZero Trust & Workforce Security - MFA, adaptive authentication, conditional access, device and contextual signals that underpin an identity-centric security model\nYou will work closely with:\n HR, IT Operations, Application Owners, Cloud Engineering and Enterprise Architecture\nCyber Fusion / SOC (for identity-related monitoring & response) and Exposure & Vulnerability Management\nInternal Audit, Risk & Compliance and external regulators in demonstrating effective access governance\nResponsibilities\nStrategy & Target Operating Model\nDefine and maintain the Workforce & Identity Security strategy and roadmap, aligned with Cyber Defence & Resilience, Zero Trust and CSA Cyber Trust Mark requirements\nDesign the target operating model for IAM & PAM: roles and responsibilities, RACI, processes, tooling and integration patterns\nTranslate business and regulatory requirements into clear identity control objectives and practical implementation plans\n Architecture, Design & Technology Ownership\nOwn the end-to-end IAM & PAM architecture, including directories, identity stores, SSO, federation, MFA, just-in-time provisioning and password-less / adaptive authentication\nSet architectural standards for integration of applications and systems into IAM/PAM platforms (e.g. connectors, APIs, SCIM, SAML/OIDC/OAuth, RADIUS)\nLead design and deployment of role and attribute models (RBAC/ABAC) that support least privilege while remaining maintainable and understandable\nEnsure IAM/PAM designs support hybrid and multi-cloud environments, remote work, and third-party access scenarios\n Delivery of IAM/PAM & Zero Trust Programmes\nLead multi-year IAM/PAM and identity-first security uplift programmes, including re-platforming or major expansion of IAM and PAM solutions\nManage full lifecycle of these programmes: requirements, design, build, test, migration, stabilisation and handover to BAU, using Agile or hybrid methodologies\nCoordinate cross-functional squads (security engineers, IAM developers, infra/AD teams, application owners, HR and business stakeholders) to deliver on time and within budget\nDrive application onboarding at scale, including bulk integrations of business systems and cloud apps to SSO, MFA and PAM platforms\n Governance, Operations & Continuous Improvement\nOwn and continuously improve JML, access request/approval, recertification and SoD processes, ensuring efficiency and strong control\nOversee access governance reporting and dashboards - who has access to what, where risk hotspots exist, and progress against remediation\nDefine and monitor KPIs/KRIs (e.g. orphan accounts, dormant privileged accounts, recertification completion, policy violations, number of manual exceptions)\nEnsure operating procedures, runbooks, and playbooks are in place for identity lifecycle, privileged account management and emergency access\nIncident Management & Assurance\nServe as the senior escalation point for identity-related incidents, including compromised credentials, abuse of privilege or IAM/PAM platform outages\nCoordinate with the SOC and other teams to detect and respond to credential theft, lateral movement and anomalous access behaviour\nProvide detailed evidence and explanations for internal and external audits, red-team exercises, and regulatory inspections focused on access governance\nRegularly validate that IAM/PAM controls meet or exceed expectations in NIST, ISO 27001 and Cyber Trust Mark control sets\n Leadership & Stakeholder Engagement\nAct as a trusted advisor to senior business and technology leaders on identity, workforce and privileged access risks, presenting trade-offs in business language\nDrive user-centric change management to improve security behaviours (e.g. MFA adoption, secure password practices, responsible use of privilege) without degrading productivity\nKey Challenges You'll Tackle\nHarmonising identity and access across legacy on-prem systems, modern cloud platforms and diverse third-party services\nAutomating and simplifying controls to reduce manual work, while maintaining strong governance and auditability\nBalancing business demands speed and convenience with robust enforcement of least privilege and SoD\nFoundational Competencies\nYou are expected to:\nDemonstrate strong strategic thinking, able to articulate an identity-first security vision and translate it into a pragmatic roadmap\nInfluence and negotiate at senior levels, resolving tensions between security, usability and delivery timelines\nLead complex programmes and cross-functional teams, using structured planning, risk management and communication\nCommunicate clearly with both technical and non-technical audiences, including EXCO, audit and regulators\nFunctional Competencies\nYou bring deep, hands-on experience in several of these areas:\nIdentity & Access Management (IAM)\nDesign and implementation of enterprise IAM platforms (e.g. Oracle IAM, SailPoint, Saviynt, Okta, Azure AD/Entra ID, Ping Identity or similar)\nIntegration of applications using SAML, OAuth2/OIDC, SCIM, REST APIs, flat files and HR connectors (e.g. Workday, SAP, Oracle HR)\nDirectory services and identity stores (Active Directory, LDAP, cloud directories), including schema design and group/role models\nImplementation of SSO, MFA, adaptive/conditional access and self-service identity features (e.g. self-service password reset, access requests)\nPrivileged Access Management (PAM)\nDeployment and operation of PAM platforms such as CyberArk or equivalent - vaults, connectors, credential rotation, session recording and just-in-time access\nOnboarding and management of privileged accounts across Windows, Unix/Linux, databases, network devices, applications and cloud platforms\nDesign of break-glass procedures, privileged account review processes and integration with SIEM/SOC tooling\nAccess Governance & Zero Trust\nDefining RBAC/ABAC models, SoD rules and recertification processes for large user populations\nImplementing Zero Trust / identity-centric security principles in hybrid environments (device posture, identity strength, network and app signals)\nUnderstanding of and ability to apply frameworks such as NIST CSF, ISO 27001, CSA Cyber Trust Mark, MAS TRM and PDPA to identity controls\nDegree in Information Systems, Computer Science, Cybersecurity, Engineering or related discipline; or equivalent industry experience\nRelevant certifications are advantageous, e.g. CISSP, CISM, CCSP, vendor IAM/PAM certifications (Okta, CyberArk, SailPoint/Saviynt, Azure AD/Entra)\nTypically, 10+ years in security, identity management or infrastructure engineering, including substantial hands-on IAM/PAM experience\nProven track record designing and implementing enterprise IAM and/or PAM solutions in complex, hybrid environments (preferably including cloud)\nExperience leading multi-project IAM programmes - such as SSO rollouts, IAM re-platforming, large-scale application onboarding or PAM migration - from design through to operations\nFamiliarity with Singapore's regulatory environment (MAS, CSA, PDPA) and experience contributing to audits, assessments or certifications (e.g. Cyber Trust Mark, ISO 27001) is highly valued","description_format":"text","description_chars":8631,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Singapore","iso":"SG","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Media & Entertainment","Broadcasting","Content Creation","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-25T19:47:09Z"}],"liveness":{"score":4,"band":"cold","label":"Long shot","p_open":1,"p_active":0.136,"p_room":0.28,"age_days":254,"expected_fill_days":30,"reasons":["conf:42","stale_co","ghost","win:tail","crowd:brand"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/mediacorp-assistant-lead-workforce-identity-security","json_url":"https://alion.io/job/mediacorp-assistant-lead-workforce-identity-security.json","meta":{"generated_at":"2026-10-01T11:11:13Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2651,"day_limit":5000,"remaining_today":2349,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}