Identity and Access Management Specialist
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Identity and Access Management (IAM) Specialists to design, implement, administer and maintain identity and access management solutions within complex enterprise IT environments.
The successful candidates will be responsible for ensuring that access to organisational systems, applications, networks and sensitive information is securely managed in accordance with established security policies, regulatory requirements and industry best practices.
This role requires strong hands-on experience with identity lifecycle management, access provisioning, authentication technologies, privileged access controls and enterprise identity management platforms.
The ideal candidates will have proven experience implementing and supporting IAM solutions across on-premises, cloud and hybrid environments, with a strong understanding of identity governance, access security and cybersecurity risk management.
Key Responsibilities
Identity and Access Management
- Design, implement, configure and maintain enterprise identity and access management solutions.
- Administer user identities, access permissions, roles and security groups across enterprise systems.
- Manage the complete identity lifecycle, including user onboarding, transfers, role changes and termination.
- Implement and maintain automated user provisioning and deprovisioning processes.
- Configure and manage role-based access control (RBAC) and attribute-based access control (ABAC) mechanisms.
- Ensure access rights are assigned according to least-privilege and need-to-know principles.
- Maintain identity repositories, directory services and identity synchronisation processes.
- Investigate and resolve identity management and access-related incidents.
Authentication and Access Security
- Implement, configure and support single sign-on (SSO) solutions.
- Manage multi-factor authentication (MFA) and conditional access policies.
- Configure authentication and authorisation protocols, including SAML, OAuth 2.0 and OpenID Connect.
- Support federation services and secure identity integration between applications and platforms.
- Monitor and investigate suspicious authentication activities and unauthorised access attempts.
- Implement secure access controls for enterprise applications, cloud services and infrastructure.
- Support passwordless authentication and modern identity security initiatives.
Identity Governance and Compliance
- Implement and maintain identity governance and administration (IGA) processes.
- Conduct periodic user access reviews and access recertification exercises.
- Identify and remediate excessive, inappropriate or conflicting access permissions.
- Support segregation of duties (SoD) controls and privileged access reviews.
- Maintain accurate identity and access management records and audit trails.
- Ensure IAM controls comply with organisational policies and relevant security frameworks.
- Support internal and external audits by providing access control evidence and documentation.
- Assist with IAM risk assessments and remediation of identified security weaknesses.
Privileged Access and Enterprise Integration
- Support privileged access management processes and integration with dedicated PAM platforms.
- Assist with securing administrative accounts, service accounts and privileged identities.
- Integrate IAM solutions with Active Directory, Microsoft Entra ID, enterprise applications and cloud platforms.
- Collaborate with infrastructure, cybersecurity, application development and cloud teams.
- Support IAM automation through scripting, APIs and workflow integrations.
- Participate in identity security improvement projects and system upgrades.
- Maintain technical documentation, operational procedures and IAM architecture records.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Information Systems, Cybersecurity or a related discipline.
- Typically 3–5 years of relevant experience in identity and access management, identity security or enterprise access administration.
- Proven hands-on experience implementing, configuring or administering enterprise IAM solutions.
- Strong working knowledge of Microsoft Active Directory and Microsoft Entra ID (formerly Azure Active Directory).
- Practical experience with user provisioning, deprovisioning and identity lifecycle management.
- Experience implementing or supporting SSO, MFA and conditional access solutions.
- Strong understanding of authentication and authorisation protocols, including SAML, OAuth 2.0 and OpenID Connect.
- Experience managing role-based access controls, security groups and access permissions.
- Knowledge of identity governance, access certification and segregation of duties.
- Understanding of privileged access management principles and least-privilege security.
- Familiarity with identity management across on-premises, cloud and hybrid environments.
- Knowledge of information security frameworks such as ISO 27001 and NIST.
- Strong troubleshooting, analytical and technical documentation skills.
Technical Skills and Competencies
Identity and Access Management Platforms
Experience with one or more of the following enterprise platforms:
- Microsoft Entra ID
- Microsoft Active Directory
- Microsoft Entra ID Governance
- SailPoint Identity Security Cloud / IdentityIQ
- Saviynt
- Okta
- One Identity Manager
- IBM Security Verify
- Ping Identity
- Oracle Identity Governance
Authentication and Federation
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Conditional Access
- Security Assertion Markup Language (SAML 2.0)
- OAuth 2.0
- OpenID Connect (OIDC)
- Lightweight Directory Access Protocol (LDAP)
- Kerberos authentication
- Identity federation and trust relationships
Identity Governance and Administration
- Identity lifecycle management
- Automated provisioning and deprovisioning
- Joiner, mover and leaver processes
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- Access certification and recertification
- Segregation of Duties (SoD)
- Identity governance workflows
- Access request and approval management
Privileged Access and Security
- Privileged Access Management (PAM) principles
- Privileged Identity Management (PIM)
- Least-privilege access controls
- Administrative and service account security
- Privileged access reviews
- Identity threat detection and response fundamentals
Cloud and Hybrid Identity
- Microsoft Azure identity services
- Microsoft Entra Connect
- Hybrid identity synchronisation
- AWS IAM fundamentals
- Cloud application identity integration
- Enterprise application access management
Automation and Integration
- PowerShell scripting
- REST APIs
- Microsoft Graph API
- SCIM provisioning
- Identity workflow automation
- Integration with HR systems and enterprise applications
Security Frameworks and Standards
- ISO/IEC 27001
- NIST Cybersecurity Framework
- NIST SP 800-63 Digital Identity Guidelines
- Zero Trust security principles
- POPIA and applicable data protection requirements
- Enterprise access control policies and standards
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- CompTIA Security+
- Certified Identity and Access Manager (CIAM)
- SailPoint IdentityIQ or Identity Security Cloud certifications
- Okta Certified Professional / Administrator
- Saviynt Identity Governance certifications
- CyberArk Certified Defender or equivalent PAM certifications
- Relevant Microsoft Azure, AWS or enterprise IAM certifications
Key Personal Attributes
- Strong analytical and technical problem-solving abilities.
- Excellent attention to detail and security awareness.
- Ability to troubleshoot complex identity and authentication issues.
- Strong understanding of access security and confidentiality requirements.
- Excellent communication and stakeholder engagement skills.
- Ability to collaborate effectively with cybersecurity, infrastructure and application teams.
- Proactive approach to identifying identity-related security risks.
- Ability to manage multiple IAM tasks, incidents and projects.
- Strong organisational and technical documentation skills.
- High levels of integrity, accountability and professional ethics.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their relevant identity and access management experience, together with copies of applicable academic qualifications and professional certifications.
Candidates should highlight:
- Enterprise IAM platforms they have implemented, administered or supported.
- Experience with Microsoft Entra ID, Active Directory, SailPoint, Saviynt, Okta or equivalent solutions.
- Practical experience implementing SSO, MFA and conditional access controls.
- Involvement in identity lifecycle management, access governance and automation.
- Experience securing identities across cloud, hybrid and on-premises environments.
- Relevant IAM projects, implementations and technical achievements.
- Professional certifications and specialised IAM training.
Please note: Specific project requirements, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.