IAM Governance Analyst
Agensi Pekerjaan Penta Consultancy Sdn. Bhd · Kuala Lumpur, Malaysia ·
- Category
- Security
- Experience
- 5+ years
An IAM Governance Analyst in Kuala Lumpur who builds and maintains identity and access management governance frameworks — policies, access certification, RBAC, PAM, and JML processes — while monitoring IAM risks, tracking KRIs/KPIs, and supporting internal and external audits. Requires 5+ years in IAM, IT risk, or cybersecurity governance.
Job Responsibilities:
- Develop, maintain, and oversee IAM governance frameworks, policies, standards, and procedures to ensure alignment with security and compliance requirements.
- Establish and maintain IAM governance processes, including access provisioning, access certification, privileged access governance, and exception management workflows.
- Support governance oversight of Joiner, Mover, Leaver (JML), Role-Based Access Control (RBAC), access reviews, and Privileged Access Management (PAM) processes.
- Monitor IAM risks, control gaps, and compliance issues while coordinating remediation activities with relevant stakeholders.
- Define and track IAM Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) through governance dashboards and reporting.
- Maintain IAM documentation, governance records, and evidence to support audit and regulatory requirements.
- Collaborate with business, security, risk, and technology teams to improve IAM controls and governance effectiveness.
- Support internal and external audits by preparing compliance evidence and assisting with issue remediation and closure.
Job Requirements:
- Minimum 5 years of experience in Identity and Access Management (IAM), IT Risk, Cybersecurity Governance, or Technology Controls.
- Strong understanding of IAM governance principles, including RBAC, PAM, Access Certification, JML processes, and access control frameworks.
- Experience in developing and maintaining IAM policies, standards, procedures, and governance documentation.
- Experience in IAM risk assessment, control monitoring, compliance reporting, and audit support.
- Experience working in financial services or highly regulated environments is preferred.
- Relevant certifications such as CISM, CRISC, CISSP, or equivalent security/governance certifications are advantageous.