
Identity and Access Management Specialist
- Manila City, Metro Manila
- Permanent
- Full-time
- Managing user onboarding, termination, and role changes.
- Managing file share access provisioning and user access provisioning/de-provisioning.
- Administering user authentication using tools such as Multi-Factor Authentication (MFA).
- Managing access to software and systems based on Active Directory.
- Managing admin consent requests in Azure Active Directory.
- Handling manual onboarding, termination, and role changes for privileged accounts.
- Managing RBAC roles to ensure appropriate access control across systems and applications.
- Regularly review and update role assignments to align with organizational needs and security policies.
- Conducting regular account reviews, including those for expired, dormant, and late-terminated accounts.
- Managing access to shared and personal mailboxes, creating shared mailboxes, and handling the creation and administration of distribution lists (DLs).
- Working closely with IT teams and stakeholders to integrate IAM solutions with existing systems and applications
- Implement & Configure enterprise app integrations in Azure AD, ensuring secure authentication and provisioning.
- Translate & Action Designs – Work from approved architectural designs, ensuring secure and efficient implementation.
- Manage Change & Risk – Raise, document, and implement changes while mitigating security risks.
- Optimize & Troubleshoot – Identify and resolve authentication, provisioning, and authorization issues.
- Configure and enforce Conditional Access Policies (CAP) to secure authentication and reduce attack surface.
- Implement risk-based access controls, including MFA enforcement, device compliance, and session controls.
- At least 3 years of working experience in the related field is required for this position
- Has solid understanding of Group Policy and network architecture
- Knowledge and experience in the use of Service Management systems/tools (desirable)
- Experience in Microsoft Active Directory or CyberArk
- Has background with Azure Cloud Active Directory
- Experience in Azure Enterprise Applications, SAML, and SCIM integrations with deep knowledge of identity security best practices
- Expert understanding of Admin Consent workflows and User Delegated Permissions in OAuth/OpenID Connect
- Experience in reading and modifying scripts using PowerShell
- Experience with the concepts of user directories, identity lifecycle management, and identity attestation.
- Experience in Privileged Access Management
- Experience in Microsoft Office 365 platforms
- Experience with the concepts of authentication (e.g., Multi-Factor Authentication or MFA), authorization, Role-Based Access Control (RBAC), Single Sign-On (SSO)
- Proven experience in eliciting requirements and testing is a plus
- Familiar with ITIL v3/v4
- Experience in a global shared services organisation (desirable)