IT Security Specialist (Identity & AI)

Singapore Public ServiceOn-siteFull-timeMid level, 2–5 yearsListed 1 week ago

Apply now

About this role

[What the role is]
As an Identity & AI Security Specialist, you will strengthen HDB’s identity security capabilities and enable the secure adoption of Generative AI and agentic AI. Working with system owners, architects, operations teams, governance functions and partners, you will design, implement, administer and operate security controls and the supporting infrastructure for human identities, privileged accounts, service and workload identities, application credentials and AI agents across on-premises, cloud and AI-enabled environments. You will also help maintain the security, availability, performance and resilience of enterprise identity and AI security platforms and their underlying infrastructure.

[What you will be working on]

- Shape identity and AI security:   Review and improve policies, standards, reference   architectures   and control requirements in line with the threat landscape, regulatory   obligations   and industry practices.

- Assess and reduce risk:   Identify   gaps affecting human, privileged, machine and AI identities; conduct security   risk   assessments; and recommend practical remediation measures and security solutions.

- Engineer identity controls:   Design, implement and enhance IAM, IGA, PAM, PIM, MFA, SSO, Conditional Access, RBAC, just-in-time access and access-governance capabilities across hybrid environments.

- Govern the identity lifecycle:   Establish   controls for privileged accounts, service accounts, application identities, API credentials, workload   identities   and AI agents, including discovery, onboarding, recertification, credential   rotation   and decommissioning.

- Secure AI use cases:   Review Generative AI and agentic AI solutions and define controls for agent authentication and authorisation, tool and data access, secrets, prompt injection, excessive agency, data leakage, human approval,   logging   and auditability.

- Maintain identity and AI security infrastructure:   Administer,   operate   and maintain enterprise identity and AI security platforms and their underlying infrastructure. Monitor system health, capacity, availability, performance,   security   and integration dependencies; perform patching, upgrades, hardening,   backup   and recovery activities; troubleshoot technical issues; and coordinate maintenance and technology refreshes with internal teams and vendors.

- Deliver secure   and resilient   solutions:   Translate business , infrastructure   and security requirements into solution designs and implementation plans; coordinate configuration, integration, testing,   deployment   and   operational handover ;   and   manage   lifecycle upgrades , capacity needs,   resilience   and technology refresh activities .

- Automate and integrate:   Develop scripts, API   integrations   and workflows to improve identity discovery, provisioning, access reviews, credential management,   monitoring   and remediation.

- Operate and respond:   Monitor   the health, availability, performance and security posture of   identity and AI security   platforms and their supporting infrastructure. Investigate   alerts , service   disruptions   and security   incidents ; perform   root-cause analysis ;   and implement   timely   recovery,   containment ,   remediation   and preventive   measures.

- Support assurance:   Maintain   technical documentation, operating   procedures   and control evidence; support audits and assessments; and ensure excessive,   dormant   or unauthorised access is remediated promptly.

- Communicate outcomes:   Analyse risks, trends and control effectiveness, and present clear recommendations and management reports to technical and non-technical stakeholders.

[What we are looking for]

- Have a degree in cybersecurity, computer science, information systems, engineering or a related discipline, or equivalent relevant professional experience.

- Have at least 3 years of relevant experience in identity security, cybersecurity engineering , infrastructure   operations   or security architecture, including hands-on experience implementing ,   administering   or   supporting enterprise identity and AI security platforms and their underlying infrastructure .

- Have practical knowledge of enterprise infrastructure operations, including Windows Server or Linux administration, platform monitoring, system hardening, patching, backup and recovery, high availability, capacity management, change   management   and technical troubleshooting.

- Understand identity lifecycle management, authentication, authorisation, Zero Trust, least privilege, segregation of duties, privileged access, access   reviews   and identity-related threat scenarios.

- Have working knowledge of enterprise identity technologies and integration patterns, including Active Directory or Microsoft Entra ID, SAML 2.0, OAuth 2.0, OpenID Connect, SCIM, LDAP, Kerberos,   federation   and REST APIs.

- Can analyse complex security and operational issues, translate requirements into practical controls, and troubleshoot identity integrations and access-related incidents.

- Can work effectively with system owners, architects, operations teams,   auditors   and vendors, and communicate technical risks and recommendations clearly to different audiences.

- Are organised, outcome-focused and able to   maintain   clear technical documentation, operating   procedures   and implementation records.

Good to   have

- Experience with identity governance, privileged   access   and secrets-management platforms.

- Experience with cloud IAM, CIEM, identity threat detection and response, non-human identity governance, workload   identities   or hybrid identity environments.

- Experience conducting security architecture reviews, threat modelling or risk assessments for Generative AI, agentic   AI   or other emerging technologies.

- Proficiency   in PowerShell, Python or similar languages for security automation, API   integration   and orchestration; exposure to infrastructure as code or   DevSecOps   practices is an advantage.

- Relevant certifications such as CISSP, CISM, CCSP or equivalent.