An IAM Controls & Compliance Specialist in Kuala Lumpur who designs, tests, and monitors identity and access management controls (JML, PAM, RBAC, SoD, access certification), tracks remediation, and supports internal and external audits. Requires 3+ years in IAM controls, IT risk, or IT audit; certifications like CISM or CISSP are a plus.
Design, implement, and maintain IAM control frameworks to ensure alignment with internal policies, regulatory requirements, and cybersecurity standards.
Perform IAM control assessments and validate the design and operating effectiveness of access management controls.
Execute control monitoring and testing activities across IAM processes, including Joiner, Mover, Leaver (JML), Privileged Access Management (PAM), and access certification.
Identify control gaps, track exceptions, and coordinate remediation activities with relevant stakeholders.
Assess compliance with Role-Based Access Control (RBAC), Segregation of Duties (SoD), least privilege principles, and identity lifecycle management requirements.
Prepare IAM control metrics, risk indicators, and assurance reports for management review.
Support internal and external audits by preparing control evidence, responding to audit requests, and tracking remediation actions.
Maintain control documentation, evidence repositories, and ensure implementation of corrective actions.
Job Requirements:
Minimum 3 years of experience in IAM Controls, IT Risk, IT Audit, Cybersecurity Compliance, or Technology Risk.
Strong understanding of IAM control frameworks, access governance, and security control testing methodologies.
Experience in assessing IAM controls related to JML processes, PAM, access certification, RBAC, and Segregation of Duties (SoD).
Familiarity with regulatory requirements, internal audit processes, and external audit support.
Strong analytical, documentation, and problem-solving skills with attention to detail.
Ability to work with cross-functional teams including security, risk, compliance, and technology stakeholders.
Experience in financial services or regulated industries is preferred.
Relevant certifications such as CRISC, CISM, ISO 27001 Lead Auditor, CISSP, or equivalent are advantageous.