Assistant Lead, Workforce & Identity Security
Singapore
Listed on 2026-05-30
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security
Company Description
Mediacorp is Singapore's largest content creator and national media network, operating a suite of TV channels, radio stations, and multiple digital platforms. Its mission is to engage, entertain, and enrich audiences by harnessing the power of creativity.
We are committed to creating an inclusive and diverse workplace where talent thrives. Our hiring decisions are made based on merit and fit-to-role. If you have a disability or special need which requires accommodation to participate in the recruitment process, please inform us when you submit your online application. We will be happy to support as necessary.
RESPONSIBILITIES Purpose of the roleYou are the person who ensures the right workforce has the right access to the right resources.
You own our Identity & Access Management (IAM), Privileged Access Management (PAM) and workforce security capabilities. You will drive an identity-first, Zero Trust model across on-prem, cloud and SaaS environments, and lead major IAM/PAM uplift projects that are central to our cyber‑resilience and CSA Cyber Trust Mark ambitions.
This role reports to the Lead, Cyber Defence & Resilience and is a critical counterpart to our Cyber Fusion, Exposure & Vulnerability Management and Digital Trust teams.
Scope of the roleIn this role, you will be responsible for the strategy, architecture, implementation and ongoing effectiveness of identity and workforce security across:
- Identities & Accounts - Employees, contractors, vendors, service accounts and application identities across multiple directories and HR systems
- Access Control - Role‑based access (RBAC), attribute‑based access (ABAC), segregation of duties (SoD), and entitlements for business and privileged users
- IAM Platforms - Enterprise IAM solutions (e.g. SailPoint, Saviynt, Oracle IAM, Azure AD / Entra , Okta or similar) covering identity lifecycle, SSO and federation
- PAM Platforms - Cyber Ark or equivalent vaulting and session‑monitoring solutions for privileged and sensitive accounts
- Processes & Governance - Joiner-mover‑leaver (JML), recertification, access reviews, break‑glass processes and exception handling
- Zero Trust & Workforce Security - MFA, adaptive authentication, conditional access, device and contextual signals that underpin an identity‑centric security model
You will work closely with:
- HR, IT Operations, Application Owners, Cloud Engineering and Enterprise Architecture
- Cyber Fusion / SOC (for identity‑related monitoring & response) and Exposure & Vulnerability Management
- Internal Audit, Risk & Compliance and external regulators in demonstrating effective access governance
- Define and maintain the Workforce & Identity Security strategy and roadmap, aligned with Cyber Defence & Resilience, Zero Trust and CSA Cyber Trust Mark requirements
- Design the target operating model for IAM & PAM: roles and responsibilities, RACI, processes, tooling and integration patterns
- Translate business and regulatory requirements into clear identity control objectives and practical implementation plans
- Own the end‑to‑end IAM & PAM architecture, including directories, identity stores, SSO, federation, MFA, just‑in‑time provisioning and password‑less / adaptive authentication
- Set architectural standards for integration of applications and systems into IAM/PAM platforms (e.g. connectors, APIs, SCIM, SAML/OIDC/OAuth, RADIUS)
- Lead design and deployment of role and attribute models (RBAC/ABAC) that support least privilege while remaining maintainable and understandable
- Ensure IAM/PAM designs support hybrid and multi‑cloud environments, remote work, and third‑party access scenarios
- Lead multi‑year IAM/PAM and identity‑first security uplift programmes, including re‑platforming or major expansion of IAM and PAM solutions
- Manage full lifecycle of these programmes: requirements, design, build, test, migration, stabilisation and handover to BAU, using Agile or hybrid methodologies
- Coordinate cross‑functional squads (security engineers, IAM developers, infra/AD teams, application owners, HR and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).